Merge pull request #7924 from Security-Onion-Solutions/analyzer-docs

Update analyzer docs with information about analyzers that require au…
This commit is contained in:
weslambert
2022-05-10 09:40:50 -04:00
committed by GitHub

View File

@@ -18,6 +18,23 @@ The built-in analyzers support the following observable types:
| Urlscan |✗ |✗|✗|✗|✗|✗|✗|✓|✗|
| Virustotal |✓ |✓|✓|✗|✗|✗|✗|✓|✗|
## Authentication
Many analyzers require authentication, via an API key or similar. The table below illustrates which analyzers require authentication.
| Name | Authn Req'd|
--------------------------|------------|
[AlienVault OTX](https://otx.alienvault.com/api) |✓|
[EmailRep](https://emailrep.io/key) |✓|
[GreyNoise](https://www.greynoise.io/plans/community) |✓|
JA3er |✗|
LocalFile |✗|
[Pulsedive](https://pulsedive.com/api/) |✓|
Spamhaus |✗|
Urlhaus |✗|
[Urlscan](https://urlscan.io/docs/api/) |✓|
[VirusTotal](https://developers.virustotal.com/reference/overview) |✓|
## Developer Guide
### Python