A plugin to enable indicators to be submitted to CIFv3 in real-time
Project description
Threat Bus CIFv3 Plugin
A Threat Bus plugin that enables communication to Collective Intelligence Framework v3.
Installation
pip install threatbus-cif3
Configuration
The plugin uses the cifsdk python client to submit indicators received on the threatbus into a CIF instance.
...
plugins:
cif3:
api:
host: http://cif.host.tld:5000
ssl: false
token: CIF_TOKEN
group: everyone
confidence: 7.5
tlp: amber
tags:
- test
- malicious
...
Development Setup
The following guides describe how to set up local, dockerized instances of MISP.
Dockerized CIFv3
Use dockerized CIFv3 to set up a local CIFv3 environment:
Setup a CIFv3 docker container
git clone https://github.com/sfinlon/cif-docker.git
cd cif-docker
docker-compose build
Edit the docker-compose.yml
vim docker-compose.yml
Find the section cif
in the configuration and edit the following as appropriate:
cif:
...
ports:
- "5000:5000"
...
Start the container
docker-compose up -d
# get an interactive shell
docker-compose exec cif /bin/bash
# become the cif user
su cif
# check to see if access tokens were successfully created
cif-tokens
# ping the router to ensure connectivity
cif --ping
License
Threat Bus comes with a 3-clause BSD license.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Close
Hashes for threatbus-cif3-2020.11.26.tar.gz
Algorithm | Hash digest | |
---|---|---|
SHA256 | af1e2d14b0904dea78951e286b23586ac08354bce4ef04dfc8c883a062b79175 |
|
MD5 | 3823504dd01b81aeba33d8adb6e13ef1 |
|
BLAKE2b-256 | 1d507bf22bff8f0b5dadccb79658ac17a08070d33b8e8348af4e6d9c24f69688 |
Close
Hashes for threatbus_cif3-2020.11.26-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 42f451e0225a700d61452fb6fa6be73abc9fab3556604065d46fb80cb8f6de69 |
|
MD5 | 2cc97a7add75eb9f0bb1d9e67d47edf7 |
|
BLAKE2b-256 | a0b6ec9508a390da27ba8fd5f497051e7f35b54cea9799661425884d4cd0b71e |