evebox
evebox copied to clipboard
Lookup sources
Hi,
Thanks for your nice job, evebox is efficient and useful for us. Would you think it possible to add, as it exist in Snorby, a lookup source feature. You already have an "ip report" link in the drop down menu near an ip address, you might add a customizable field to point to any site one prefer to have info about an ip address, like https://www.robtex.com/?dns=${ip}.
Thanks !
Yes, so this is planned, at least mentally. Right now we just use the DNS info that Suricata was able to pull off the wire, but this is often not a enough.
I was thinking of the equivalant of "dig -x {ip}" and "whois {ip}" perhaps with some links to external tools, or a preferred external tool.
The lookups would be done by the EveBox server, so would originate there, but probably have to be enabled server side as well, as doing DNS lookups on alerting traffic is a potential information leakage.
Any more thoughts on this while I plan it out?
What i like with the possibility to choose an external site to make lookup is that you can get a bit more context, like ip reputation and the fact that the request don't originate from our network., plus, you can choose the one you prefer.
Closing. Will consider on per source bases, and there is a way to add your own custom hooks now.