-
Notifications
You must be signed in to change notification settings - Fork 171
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Enrich DNS indicators #36
Comments
So, um. What do we want to do on this one? |
So here is the original spec of what I wanted to do for the tiq-test enrichment format. We would get something like this from the raw data:
And turn it into (getting some random IPs and enrichments to illustrate):
So in this "enrichment type", we are transforming the
Of course this is all moot if there is no DNSDB key. In that case, all |
What we currently lack is (3), I believe. We already do (1) and most of (2), though it needs a bit of extension to be complete. |
Let me know if I can help. |
In the final, enriched data, does the FQDN still have its own entry, or are we just using the IPv4 entry? In other words, does the original FQDN IOC map to 1️⃣ or 2️⃣ enriched IOCs? I think it should be two, myself. |
nvm I figured out where everything goes. 😊 |
LeaveNoIndicatorBehind
The text was updated successfully, but these errors were encountered: