mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Add information for MHR and WhoisLookup, and other minor updates
This commit is contained in:
@@ -12,11 +12,13 @@ The built-in analyzers support the following observable types:
|
|||||||
| Greynoise |✗ |✗|✓|✗|✗|✗|✗|✗|✗|
|
| Greynoise |✗ |✗|✓|✗|✗|✗|✗|✗|✗|
|
||||||
| JA3er |✗ |✗|✗|✓|✗|✗|✗|✗|✗|
|
| JA3er |✗ |✗|✗|✓|✗|✗|✗|✗|✗|
|
||||||
| LocalFile |✓ |✓|✓|✓|✗|✓|✗|✓|✗|
|
| LocalFile |✓ |✓|✓|✓|✗|✓|✗|✓|✗|
|
||||||
|
| Malware Hash Registry |✗ |✓|✗|✗|✗|✗|✗|✓|✗|
|
||||||
| Pulsedive |✓ |✓|✓|✗|✗|✗|✓|✓|✓|
|
| Pulsedive |✓ |✓|✓|✗|✗|✗|✓|✓|✓|
|
||||||
| Spamhaus |✗ |✗|✓|✗|✗|✗|✗|✗|✗|
|
| Spamhaus |✗ |✗|✓|✗|✗|✗|✗|✗|✗|
|
||||||
| Urlhaus |✗ |✗|✗|✗|✗|✗|✗|✓|✗|
|
| Urlhaus |✗ |✗|✗|✗|✗|✗|✗|✓|✗|
|
||||||
| Urlscan |✗ |✗|✗|✗|✗|✗|✗|✓|✗|
|
| Urlscan |✗ |✗|✗|✗|✗|✗|✗|✓|✗|
|
||||||
| Virustotal |✓ |✓|✓|✗|✗|✗|✗|✓|✗|
|
| Virustotal |✓ |✓|✓|✗|✗|✗|✗|✓|✗|
|
||||||
|
| WhoisLookup |✓ |✗|✗|✗|✗|✗|✓|✗|✗|
|
||||||
|
|
||||||
## Authentication
|
## Authentication
|
||||||
Many analyzers require authentication, via an API key or similar. The table below illustrates which analyzers require authentication.
|
Many analyzers require authentication, via an API key or similar. The table below illustrates which analyzers require authentication.
|
||||||
@@ -26,13 +28,15 @@ Many analyzers require authentication, via an API key or similar. The table belo
|
|||||||
[AlienVault OTX](https://otx.alienvault.com/api) |✓|
|
[AlienVault OTX](https://otx.alienvault.com/api) |✓|
|
||||||
[EmailRep](https://emailrep.io/key) |✓|
|
[EmailRep](https://emailrep.io/key) |✓|
|
||||||
[GreyNoise](https://www.greynoise.io/plans/community) |✓|
|
[GreyNoise](https://www.greynoise.io/plans/community) |✓|
|
||||||
JA3er |✗|
|
[JA3er](https://ja3er.com/) |✗|
|
||||||
LocalFile |✗|
|
LocalFile |✗|
|
||||||
|
[Malware Hash Registry](https://hash.cymru.com/docs_whois) |✗|
|
||||||
[Pulsedive](https://pulsedive.com/api/) |✓|
|
[Pulsedive](https://pulsedive.com/api/) |✓|
|
||||||
Spamhaus |✗|
|
[Spamhaus](https://www.spamhaus.org/dbl/) |✗|
|
||||||
Urlhaus |✗|
|
[Urlhaus](https://urlhaus.abuse.ch/) |✗|
|
||||||
[Urlscan](https://urlscan.io/docs/api/) |✓|
|
[Urlscan](https://urlscan.io/docs/api/) |✓|
|
||||||
[VirusTotal](https://developers.virustotal.com/reference/overview) |✓|
|
[VirusTotal](https://developers.virustotal.com/reference/overview) |✓|
|
||||||
|
[WhoisLookup](https://github.com/meeb/whoisit) |✗|
|
||||||
|
|
||||||
|
|
||||||
## Developer Guide
|
## Developer Guide
|
||||||
|
|||||||
Reference in New Issue
Block a user