From e6a2e49d37eb9b4ac7feb921e3a582b586f8c162 Mon Sep 17 00:00:00 2001 From: weslambert Date: Wed, 6 Dec 2023 12:57:59 -0500 Subject: [PATCH] Add Sublime Platform --- salt/sensoroni/files/analyzers/README.md | 28 +++++++++++++----------- 1 file changed, 15 insertions(+), 13 deletions(-) diff --git a/salt/sensoroni/files/analyzers/README.md b/salt/sensoroni/files/analyzers/README.md index 19335a545..2af8cf240 100644 --- a/salt/sensoroni/files/analyzers/README.md +++ b/salt/sensoroni/files/analyzers/README.md @@ -6,19 +6,20 @@ Security Onion provides a means for performing data analysis on varying inputs. The built-in analyzers support the following observable types: -| Name | Domain | Hash | IP | Mail | Other | URI | URL | User Agent | -| ------------------------|--------|-------|-------|-------|-------|-------|-------|-------| -| Alienvault OTX |✓ |✓|✓|✗|✗|✗|✓|✗| -| EmailRep |✗ |✗|✗|✓|✗|✗|✗|✗| -| Greynoise |✗ |✗|✓|✗|✗|✗|✗|✗| -| LocalFile |✓ |✓|✓|✗|✓|✗|✓|✗| -| Malware Hash Registry |✗ |✓|✗|✗|✗|✗|✓|✗| -| Pulsedive |✓ |✓|✓|✗|✗|✓|✓|✓| -| Spamhaus |✗ |✗|✓|✗|✗|✗|✗|✗| -| Urlhaus |✗ |✗|✗|✗|✗|✗|✓|✗| -| Urlscan |✗ |✗|✗|✗|✗|✗|✓|✗| -| Virustotal |✓ |✓|✓|✗|✗|✗|✓|✗| -| WhoisLookup |✓ |✗|✗|✗|✗|✓|✗|✗| +| Name | Domain | EML | Hash | IP | Mail | Other | URI | URL | User Agent | +| ------------------------|--------|-------|-------|-------|-------|-------|-------|-------|-------| +| Alienvault OTX |✓ |✗|✓|✓|✗|✗|✗|✓|✗| +| EmailRep |✗ |✗|✗|✗|✓|✗|✗|✗|✗| +| Greynoise |✗ |✗|✗|✓|✗|✗|✗|✗|✗| +| LocalFile |✓ |✗|✓|✓|✗|✓|✗|✓|✗| +| Malware Hash Registry |✗ |✗|✓|✗|✗|✗|✗|✓|✗| +| Pulsedive |✓ |✗|✓|✓|✗|✗|✓|✓|✓| +| Spamhaus |✗ |✗|✗|✓|✗|✗|✗|✗|✗| +| Sublime Platform |✗ |✓|✗|✗|✗|✗|✗|✗|✗| +| Urlhaus |✗ |✗|✗|✗|✗|✗|✗|✓|✗| +| Urlscan |✗ |✗|✗|✗|✗|✗|✗|✓|✗| +| Virustotal |✓ |✗|✓|✓|✗|✗|✗|✓|✗| +| WhoisLookup |✓ |✗|✗|✗|✗|✗|✓|✗|✗| ## Authentication @@ -33,6 +34,7 @@ LocalFile |✗| [Malware Hash Registry](https://hash.cymru.com/docs_whois) |✗| [Pulsedive](https://pulsedive.com/api/) |✓| [Spamhaus](https://www.spamhaus.org/dbl/) |✗| +[Sublime Platform](https://sublime.security) |✓| [Urlhaus](https://urlhaus.abuse.ch/) |✗| [Urlscan](https://urlscan.io/docs/api/) |✓| [VirusTotal](https://developers.virustotal.com/reference/overview) |✓|