Threat Bus CIFv3 Plugin
A Threat Bus plugin to push indicators from Threat Bus to Collective Intelligence Framework v3.
The plugin uses the cifsdk (v3.x) Python client to submit indicators received from Threat Bus into a CIFv3 instance.
The plugin breaks with the pub/sub architecture of Threat Bus, because CIF does not subscribe itself to the bus. Instead, the plugin actively contacts a CIF endpoint.
Installation
pip install threatbus-cif3
Configuration
Configure this plugin by adding a section to Threat Bus' config.yaml file, as
follows:
...
plugins:
cif3:
api:
host: http://cif.host.tld:5000
ssl: false
token: CIF_TOKEN
group: everyone
confidence: 7.5
tlp: amber
tags:
- test
- malicious
...
Development Setup
The following guides describe how to set up local, dockerized instances of CIF.
Dockerized CIFv3
Use dockerized CIFv3 to set up a local CIFv3 environment:
Setup a CIFv3 docker container
git clone https://github.com/sfinlon/cif-docker.git
cd cif-docker
docker-compose build
Edit the docker-compose.yml
vim docker-compose.yml
Find the section cif in the configuration and edit the following as
appropriate to bind port 5000 to your localhost:
cif:
...
ports:
- "5000:5000"
...
Start the container
docker-compose up -d
# Get an interactive shell in the container:
docker-compose exec cif /bin/bash
# Become the cif user:
su cif
# check to see if access tokens were successfully created. Copy the `admin`
# token to the CIF config section:
cif-tokens
# Ping the router to ensure connectivity:
cif --ping
License
Threat Bus comes with a 3-clause BSD license.
Metadata
Release files for threatbus-cif3 2022.5.16
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| threatbus-cif3-2022.5.16.tar.gz | 5.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| threatbus_cif3-2022.5.16-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 10.8 kB
Release files / threatbus-cif3-2022.5.16.tar.gz
| Download URL | threatbus-cif3-2022.5.16.tar.gz |
|---|---|
| Size | 5.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e1c6386899812860b5350214c94cc514df7a183c0461024f503e40e2d1ad7274
|
|
BLAKE2b-256 checksum How to use checksums |
bf573dece0608fc2c7ca5faf031528cca0ce3b2e5ff1764c1711a93848b6c9af
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.0 CPython/3.8.12
|
Release files / threatbus_cif3-2022.5.16-py3-none-any.whl
| Download URL | threatbus_cif3-2022.5.16-py3-none-any.whl |
|---|---|
| Size | 5.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ec5c6393ded523b9ee6da2a51bfbd545c9d9a26ad1db76590799e24d185368ed
|
|
BLAKE2b-256 checksum How to use checksums |
aac4fe56b5d108ec568a3ba609f1ea3f790c092c43f6ee7f4297f19ee4f04471
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.0 CPython/3.8.12
|