forked from mandiant/ioc_writer
-
Notifications
You must be signed in to change notification settings - Fork 0
/
README
84 lines (65 loc) · 2.87 KB
/
README
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
ioc_writer
===============================================================================
The source code in this package is made available under the terms of the
Apache License , Version 2.0. See the "LICENSE " file for more information.
===============================================================================
Author:
William Gibb
william.gibb at mandiant dot com
===============================================================================
Purpose:
Provide a python library that allows for basic creation and editing of OpenIOC
objects. It supports a basic CRUD (Create, Read, Update, Delete) for various
items:
item Create Read Update Delete
IOC name Yes No Yes Yes
IOC description Yes No Yes Yes
created date Yes No Yes N/A
last modified date Yes No Yes N/A
published date Yes No Yes N/A
link metadata Yes No Yes Yes
IndicatorItem nodes Yes No NotYet Yes
Indicator nodes Yes No NotYet Yes
Parameters Yes No Yes Yes
Items do not have built in Read operations, since all items can be accesed
with built in ElementTree syntax or the use of XPATH to select portions
of the IOC.
No decision has been made about whether or not to support changing of
existing Indicator/IndicatorItem nodes.
See the Docs in the Docs\ directory, and the examples directory for examples of
working with the library. The user code should only be calling functionality
provided in ioc_api or ioc_common.
===============================================================================
Requirements:
The python "lxml" library must be installed. This can be obtained from one of
following locations.
https://pypi.python.org/pypi/lxml/3.2.1
http://lxml.de/
============================================================================
Installation:
See the file named "INSTALL" for instructions on installing this library
locally.
============================================================================
Manifest:
README
this file
INSTALL
instructions for installing the library
setup.py
installation script
ioc_writer/
actual library containing the code to build & manipulate the iocs
docs/
Generated HTML documentation for the ioc_writer library
examples/
Example code
examples/11_to_10_downgrade
Script to downgrade OpenIOC 1.1 to OpenIOC 1.1.
examples/openioc_to_yara
Scripts that support encapsulating YARA signatures in OpenIOC 1.1 format.
examples/simple_ioc_writer
Script that consumes a csv of data to build an IOC. this csv contains the
content, context, et cetera. An example CSV is provided.
===============================================================================
Bug reports / questions / feedback / feature requests:
william.gibb at mandiant dot com