conpot icon indicating copy to clipboard operation
conpot copied to clipboard

Add option to include databus dump in stix report

Open johnnykv opened this issue 10 years ago • 4 comments

johnnykv avatar Aug 05 '14 17:08 johnnykv

I assume as an artifact?

glaslos avatar Aug 05 '14 17:08 glaslos

guess so, not sure

johnnykv avatar Aug 05 '14 17:08 johnnykv

Hi! I would like to work on this issue. Can you tell me what exactly is databus dump and what all has to be included in it? Thanks.

shrave avatar Feb 06 '17 16:02 shrave

Hi @shrave I removed the uncomplicated label as this probably isn't true anymore. First step would be to verify that the stix reporter is still working. I assume this would also include an upgrade of the stix library currently used. Then you would need to find a way how to add a databus snapshot (https://github.com/mushorg/conpot/blob/master/conpot/core/databus.py#L102) to the STIX report.

glaslos avatar Feb 06 '17 16:02 glaslos