Skip to main content

Threat Bus CIFv3 Plugin

PyPI Status Build Status License

A Threat Bus plugin to push indicators from Threat Bus to Collective Intelligence Framework v3.

The plugin uses the cifsdk (v3.x) Python client to submit indicators received from Threat Bus into a CIFv3 instance.

The plugin breaks with the pub/sub architecture of Threat Bus, because CIF does not subscribe itself to the bus. Instead, the plugin actively contacts a CIF endpoint.

Installation

pip install threatbus-cif3

Configuration

Configure this plugin by adding a section to Threat Bus' config.yaml file, as follows:

...
plugins:
  cif3:
    api:
      host: http://cif.host.tld:5000
      ssl: false
      token: CIF_TOKEN
    group: everyone
    confidence: 7.5
    tlp: amber
    tags:
      - test
      - malicious
...

Development Setup

The following guides describe how to set up local, dockerized instances of CIF.

Dockerized CIFv3

Use dockerized CIFv3 to set up a local CIFv3 environment:

Setup a CIFv3 docker container

git clone https://github.com/sfinlon/cif-docker.git
cd cif-docker
docker-compose build

Edit the docker-compose.yml

vim docker-compose.yml

Find the section cif in the configuration and edit the following as appropriate to bind port 5000 to your localhost:

cif:
    ...
    ports:
      - "5000:5000"
    ...

Start the container

docker-compose up -d
# Get an interactive shell in the container:
docker-compose exec cif /bin/bash
# Become the cif user:
su cif
# check to see if access tokens were successfully created. Copy the `admin`
# token to the CIF config section:
cif-tokens
# Ping the router to ensure connectivity:
cif --ping

License

Threat Bus comes with a 3-clause BSD license.

Metadata

Release files for threatbus-cif3 2022.5.16

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for threatbus-cif3 2022.5.16
File Size Uploaded
threatbus-cif3-2022.5.16.tar.gz 5.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for threatbus-cif3 2022.5.16
File Interpreter ABI Platform
threatbus_cif3-2022.5.16-py3-none-any.whl Python 3 none any Details

Total release size: 10.8 kB

Release files / threatbus-cif3-2022.5.16.tar.gz

Download URL threatbus-cif3-2022.5.16.tar.gz
Size 5.3 kB
Tags Source
SHA-256 checksum
How to use checksums
e1c6386899812860b5350214c94cc514df7a183c0461024f503e40e2d1ad7274
BLAKE2b-256 checksum
How to use checksums
bf573dece0608fc2c7ca5faf031528cca0ce3b2e5ff1764c1711a93848b6c9af
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.0 CPython/3.8.12

Release files / threatbus_cif3-2022.5.16-py3-none-any.whl

Download URL threatbus_cif3-2022.5.16-py3-none-any.whl
Size 5.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ec5c6393ded523b9ee6da2a51bfbd545c9d9a26ad1db76590799e24d185368ed
BLAKE2b-256 checksum
How to use checksums
aac4fe56b5d108ec568a3ba609f1ea3f790c092c43f6ee7f4297f19ee4f04471
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.0 CPython/3.8.12
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page