New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Sending out x-arf emails #2
Comments
Some examples can be found from http://www.x-arf.org/schemata.html Overall the x-arf community seems to have stalled in the last 2-3 years, indicators:
|
Analysing the two existing python implementation I've found: http://x-arfreporting.sourceforge.net/
=> not helping much, could more easily be reimplemented in python3 https://pypi.python.org/pypi/pyxarf
python: 1004 (98.92%) => useful as basis for a base library that could parse, validate and write xarf. |
Further design thoughts:
|
https://bitbucket.org/abusix/pyxarf.git did not enable tickets so I've send an email to info@abusix.com |
Talked to @dmth : We will try the "integrate what we need directly in intelmq first" approach. Rationale: We find out faster, what we actually need in terms of interface and python3 functions. And we provide first value faster. Later we can see how active the pyxarf community is to extend pyxarf to that use case. We also know our technical requirements better at that point, having it tried out. If pyxarfcan we developed in that direction, we can refactor to use the updated library later. |
pyxarf does not need a lot of changes to run on python3. |
Current status in branch xarf is that you can see the example mapping for malware and multiple ones get written out into the text body part for debugging purposes. Mail creation needs to be refactored. |
#7 of branch xarf provides basic xarf writing support |
The basic xarf support from the branch has been merged to master, |
Meanwhile the rudimentary experimental xarf sending support was removed 23b07eb My next step: Finding example data testing the mapping. |
An small update: This issue is more specifically about implementing writing with intelmq-mailgen, which has a dependency on the currently by @bernhard-herzog developed new way of configuring how events are distributed. |
@dmth what is the status of this? |
https://github.com/Intevation/intelmq-mailgen/blob/master/example_scripts/20xarf.py contains an implementation of the newly developed schema. But it can only send X-ARF "simple", "bulk" is not supported yet. The Script is user-maintainable and can be extended with own or official schemata.
|
Should be able to send out x-arf emails.
Specification available from http://www.x-arf.org,
the question is: which version v0.2 or v0.3 draft.
TODO: List x-arf sender and receivers. Look for example emails.
The text was updated successfully, but these errors were encountered: