Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Analyzer] WAD #814

Open
0ssigeno opened this issue Dec 24, 2021 · 3 comments
Open

[Analyzer] WAD #814

0ssigeno opened this issue Dec 24, 2021 · 3 comments

Comments

@0ssigeno
Copy link
Contributor

We can retrieve more information about the infrastructure behind a domain using WAD.

Since it is actually contacting the domain, we should add the leak_info flag in the configuration.

@mlodic
Copy link
Member

mlodic commented Dec 24, 2021

Good catch but we do not usually integrate tools that actively scan a target in IntelOwl.

This is because IntelOwl is not a tool that should be used for perfroming reconnaissance of a target. There are plenty of other projects that do that better and this has never been its main goal. I have already closed other similar issues.

However I understand that the framework completely supports these use cases and could integrate several similar tools/services. The point is that we should categorize them differently. We cannot just add them as normal analyzers.

I guess that a little customization for the "reconnaissance tools/services" can be thought and done once we will start working on the playbooks (#628). The playbooks will allow to group some analyzers together, to better separate use cases from one another. So I think we could keep this issue as a reminder.

But right now, considering the almost all the IntelOwl users just run "all the analyzers", I think we should avoid this.

@mlodic mlodic changed the title New analyzer: WAD [New Scanner] WAD Jan 4, 2023
@mlodic
Copy link
Member

mlodic commented Jan 4, 2023

from 2021 to 2023, now it could be time to start thinking about this.

We have implemented Playbooks and we have IntelOwl v4.
The framework can now support active scanners too in an easier way.

@mlodic mlodic changed the title [New Scanner] WAD [Analyzer] WAD Mar 29, 2024
@mlodic
Copy link
Member

mlodic commented Mar 29, 2024

this could be implemented like a normal analyzer

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants