From b71a38aed3104e412977ca5d952b34f3c4bf08fd Mon Sep 17 00:00:00 2001 From: Elijah Gibson <82835625+semphorin@users.noreply.github.com> Date: Wed, 13 Dec 2023 14:28:48 -0500 Subject: [PATCH] Add ThreatFox, Echotrail, MalwareBazaar, Elasticsearch --- cases.rst | 40 ++++++++++++++++++++++++---------------- 1 file changed, 24 insertions(+), 16 deletions(-) diff --git a/cases.rst b/cases.rst index c9520e2c..3e09c559 100644 --- a/cases.rst +++ b/cases.rst @@ -162,22 +162,26 @@ Supported Analyzers and Data Types The following is a summary of the built-in analyzers and their supported data types: -======================= ======= === ==== == ==== ===== === === ========== - Name Domain EML Hash IP Mail Other URI URL User Agent -======================= ======= === ==== == ==== ===== === === ========== -Alienvault OTX ✓ ✓ ✓ -EmailRep ✓ -Greynoise ✓ -LocalFile ✓ ✓ ✓ ✓ ✓ -Malware Hash Registry ✓ -Pulsedive ✓ ✓ ✓ ✓ ✓ ✓ -Spamhaus ✓ -Sublime Platform ✓ -Urlhaus ✓ -Urlscan ✓ -Virustotal ✓ ✓ ✓ ✓ -WhoisLookup ✓ -======================= ======= === ==== == ==== ===== === === ========== +======================= ======= === ======== ==== == ==== ===== === === ========== ======== ==== + Name Domain EML Gimphash Hash IP Mail Other URI URL User Agent Telfhash Tlsh +======================= ======= === ======== ==== == ==== ===== === === ========== ======== ==== +Alienvault OTX ✓ ✓ ✓ +Echotrail ✓ +Elasticsearch ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ +EmailRep ✓ +Greynoise ✓ +LocalFile ✓ ✓ ✓ ✓ ✓ +Malwarebazaar ✓ ✓ ✓ ✓ +Malware Hash Registry ✓ +Pulsedive ✓ ✓ ✓ ✓ ✓ ✓ +Spamhaus ✓ +Sublime Platform ✓ +Threatfox ✓ ✓ ✓ +Urlhaus ✓ +Urlscan ✓ +Virustotal ✓ ✓ ✓ ✓ +WhoisLookup ✓ +======================= ======= === ======== ==== == ==== ===== === === ========== ======== ==== @@ -223,10 +227,14 @@ Some analyzers require authentication or other details to be configured before u The following analyzers require users to configure authentication or other parameters in order for the analyzer to work correctly: - AlienVault OTX +- Echotrail +- Elasticsearch - EmailRep - GreyNoise - LocalFile +- Malwarebazaar - Pulsedive +- Threatfox - Urlscan - VirusTotal