Skip to content
This repository has been archived by the owner on Apr 26, 2021. It is now read-only.

Json+Syslog [cef-formatted] integration for analysis results #659

Open
jpsenior opened this issue Oct 16, 2015 · 3 comments
Open

Json+Syslog [cef-formatted] integration for analysis results #659

jpsenior opened this issue Oct 16, 2015 · 3 comments

Comments

@jpsenior
Copy link
Contributor

Build out a small system to add in syslog output for high level signature findings including criticality:
e.g. "Detects VirtualBox through the presence of a Device".

This capability will be added to the reporting modules.

@jpsenior
Copy link
Contributor Author

Note: Intention of this ticket is for vendor-agnostic SIEM integration

@botherder
Copy link
Member

It's an interesting idea, but we should discuss it. That's something that perhaps @jekil could work on.

@KillerInstinct
Copy link
Contributor

Yeah this one is kinda complex -- especially for custom rigs. I made a syslog reporting module a while back, that the user had to customize to fit their needs by modifying the module itself. Not ideal, but for parsing out IOCs from signatures, its kind of required.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

4 participants
@botherder @jpsenior @KillerInstinct and others