misp-modules
misp-modules copied to clipboard
Have the virustotal_public module use ip-src|port and ip-dst|port as input type
Current module only accepts ['hostname', 'domain', "ip-src", "ip-dst", "md5", "sha1", "sha256", "url"].
With ip-src|port or ip-dst|port: strip the port part, then query for IP with virustotal