Tools to support sighting from various sources (e.g. network pcap) to sight attributes in MISP instances
Switch branches/tags
Nothing to show
Clone or download
adulau add: debug mode added (-d/--debug)
The debug output gives an output about the processing:

python3 pcapreader.py -r test.cap   --debug
{'discarded': 0, 'sighted': 8, 'non-sighted': 4}

- discarded means skipped line (not processed)
- sighted means IP addresses sighted in MISP successfully
- non-sighted mean IP addresses not-sighted (usually meaning the IP addresses are not in MISP)
Latest commit a4e2190 Feb 24, 2017
Permalink
Failed to load latest commit information.
bin add: debug mode added (-d/--debug) Feb 24, 2017
LICENSE Initial commit Feb 20, 2017
README.md Initial commit Feb 20, 2017

README.md

misp-sighting-tools

Tools to support sighting from various sources (e.g. network pcap) to sight attributes in MISP instances