Migrate enrich.py to modular system#117
Conversation
|
@MarcOverIP @xychix could you already have a look at the proposed approach? Regarding the iplist, I would get rid of the iplist config files from |
As discussed, we'll keep the following iplist config files in sync with the related ES index:
|
5fe1d8a to
ac43410
Compare
a59288a to
901401a
Compare
Fetch LOGLEVEL from config.json for alarms.py
Signed-off-by: fastlorenzo <git@bernardi.be>
@lorenzo please do check if alarms.py matches with ones in your open PR. Further these are minor additions
e03dcef to
a31c5d6
Compare
Fetch LOGLEVEL from config.json for alarms.py
Signed-off-by: fastlorenzo <git@bernardi.be>
@lorenzo please do check if alarms.py matches with ones in your open PR. Further these are minor additions
Signed-off-by: fastlorenzo <git@bernardi.be>
Signed-off-by: fastlorenzo <git@bernardi.be>
Signed-off-by: fastlorenzo <git@bernardi.be>
Signed-off-by: fastlorenzo <git@bernardi.be>
Signed-off-by: fastlorenzo <git@bernardi.be>
Signed-off-by: fastlorenzo <git@bernardi.be>
Signed-off-by: fastlorenzo <git@bernardi.be>
Signed-off-by: fastlorenzo <git@bernardi.be>
Signed-off-by: fastlorenzo <git@bernardi.be>
Signed-off-by: fastlorenzo <git@bernardi.be>
|
@MarcOverIP @xychix should be ready to be merged in master \o/ |
Signed-off-by: fastlorenzo <git@bernardi.be>
Signed-off-by: fastlorenzo <git@bernardi.be>
Signed-off-by: fastlorenzo <git@bernardi.be>
Enrich CS beacon dataEnrich redirector traffic with greynoiseEnrich redirector traffic with tor exit nodesEnrich redirector traffic with IP list (iplist_unknown.conf)Enrich redirector traffic with IP list (iplist_redteam.conf)Enrich redirector traffic with IP list (iplist_customer.conf)Enrich redirector traffic with IP list (iplist_alarmed.conf)Enrichment to replace=> To be done in another PRroguedomains.confTest enrich CS beacon dataTest enrich redirector traffic with greynoiseTest enrich redirector traffic with tor exit nodesTest enrich redirector traffic with IP list (iplist_unknown.conf)Test enrich redirector traffic with IP list (iplist_redteam.conf)Test enrich redirector traffic with IP list (iplist_customer.conf)Test enrich redirector traffic with IP list (iplist_alarmed.conf)=> To be done in another PRredteamdomains.conf=> still to decide how to use itRemove enrichment forknown_testsystems.confandknown_sandboxes.confAdd possibility to enable/disable enrichment modules (via config file)Add possibility to configure run interval for enrichment and alarm modules (via config file)Fix small errors in installer fordevrun (don't run certbot in dev)Fixes #108