A plugin to enable indicators to be submitted to CIFv3 in real-time
Project description
Threat Bus CIFv3 Plugin
A Threat Bus plugin to push indicators from Threat Bus to Collective Intelligence Framework v3.
The plugin uses the cifsdk (v3.x) Python client to submit indicators received from Threat Bus into a CIFv3 instance.
The plugin breaks with the pub/sub architecture of Threat Bus, because CIF does not subscribe itself to the bus. Instead, the plugin actively contacts a CIF endpoint.
Installation
pip install threatbus-cif3
Configuration
Configure this plugin by adding a section to Threat Bus' config.yaml
file, as
follows:
...
plugins:
cif3:
api:
host: http://cif.host.tld:5000
ssl: false
token: CIF_TOKEN
group: everyone
confidence: 7.5
tlp: amber
tags:
- test
- malicious
...
Development Setup
The following guides describe how to set up local, dockerized instances of CIF.
Dockerized CIFv3
Use dockerized CIFv3 to set up a local CIFv3 environment:
Setup a CIFv3 docker container
git clone https://github.com/sfinlon/cif-docker.git
cd cif-docker
docker-compose build
Edit the docker-compose.yml
vim docker-compose.yml
Find the section cif
in the configuration and edit the following as
appropriate to bind port 5000 to your localhost:
cif:
...
ports:
- "5000:5000"
...
Start the container
docker-compose up -d
# Get an interactive shell in the container:
docker-compose exec cif /bin/bash
# Become the cif user:
su cif
# check to see if access tokens were successfully created. Copy the `admin`
# token to the CIF config section:
cif-tokens
# Ping the router to ensure connectivity:
cif --ping
License
Threat Bus comes with a 3-clause BSD license.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Hashes for threatbus-cif3-2021.11.22.tar.gz
Algorithm | Hash digest | |
---|---|---|
SHA256 | 9765ccffd072e35c2129480e09b09ce680449b84ef043e275a7cbc70e9f51500 |
|
MD5 | ca101cffca88847afdc2cf752fc9e1bc |
|
BLAKE2b-256 | 54ae0e4770f0b4211143ede01fdb4921d1396f53c0ba2e8b54954e6195141b16 |
Hashes for threatbus_cif3-2021.11.22-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | d5aa94f8fee3d91fd61bbcbcd7462510a2a067c1f7c8910121a025c91c4e7803 |
|
MD5 | 83f23ae35f15a4f5013455c05610b89f |
|
BLAKE2b-256 | 6d251734aa502095883d07891624972e42a550e5c68a76a42af04c4f5aa29bbf |