Add initial supported observable matrix/table

This commit is contained in:
weslambert
2022-04-27 08:58:34 -04:00
committed by GitHub
parent 76f183b112
commit 4edd729596

View File

@@ -2,6 +2,18 @@
Security Onion provides a means for performing data analysis on varying inputs. This data can be any data of interest sourced from event logs. Examples include hostnames, IP addresses, file hashes, URLs, etc. The analysis is conducted by one or more analyzers that understand that type of input. Analyzers come with the default installation of Security Onion. However, it is also possible to add additional analyzers to extend the analysis across additional areas or data types.
## Supported Observable Types
The built-in analyzers support the following observable types:
| Name | Domain | Hash | IP | JA3 | URL |
| ------------------------|--------|-------|-------|-------|-------|
| Alienvault OTX |✓ |✓|✓|✗|✓|
| Greynoise |✗ |✗|✓|✗|✗|
| JA3er |✗ |✗|✗|✓|✗|
| LocalFile |✓ |✓|✓|✓|✓|
| Spamhaus |✗ |✗|✓|✗|✗|
| Urlhaus |✗ |✗|✗|✗|✓|
| Virustotal |✓ |✓|✓|✗|✓|
## Developer Guide