From a43cf2f642e07575a719181d79ad74cf39206ad2 Mon Sep 17 00:00:00 2001 From: Javier Botella Date: Thu, 4 Jun 2020 20:12:19 +0200 Subject: [PATCH 1/2] PolySwarm Integration --- rules/0690-polyswarm_rules.xml | 35 ++++++++++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) create mode 100644 rules/0690-polyswarm_rules.xml diff --git a/rules/0690-polyswarm_rules.xml b/rules/0690-polyswarm_rules.xml new file mode 100644 index 000000000..3bafcfd51 --- /dev/null +++ b/rules/0690-polyswarm_rules.xml @@ -0,0 +1,35 @@ + + + json + custom-polyswarm + Polyswarm integration messages. + no_full_log + + + 101000 + 1 + PolySwarm: Error with Endpoint + gdpr_IV_35.7.d, + no_full_log + + + 101000 + 0 + PolySwarm: Alert - File not found in PolySwarm + no_full_log + + + 101000 + 1 + 0 + PolySwarm: Alert - $(polyswarm.source.file) - No positives found + no_full_log + + + 101000 + 1 + PolySwarm: Alert - $(polyswarm.source.file) - $(polyswarm.positives) engines detected this file + gdpr_IV_35.7.d, + no_full_log + + From 76920a340dfd9f4bcdcc50175693cf1a09a1e855 Mon Sep 17 00:00:00 2001 From: Javier Botella Date: Mon, 29 Jun 2020 13:29:45 +0200 Subject: [PATCH 2/2] updated rules id --- rules/0690-polyswarm_rules.xml | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/rules/0690-polyswarm_rules.xml b/rules/0690-polyswarm_rules.xml index 3bafcfd51..e999e4c9a 100644 --- a/rules/0690-polyswarm_rules.xml +++ b/rules/0690-polyswarm_rules.xml @@ -1,32 +1,32 @@ - + json custom-polyswarm Polyswarm integration messages. no_full_log - - 101000 + + 91000 1 PolySwarm: Error with Endpoint gdpr_IV_35.7.d, no_full_log - - 101000 + + 91000 0 PolySwarm: Alert - File not found in PolySwarm no_full_log - - 101000 + + 91000 1 0 PolySwarm: Alert - $(polyswarm.source.file) - No positives found no_full_log - - 101000 + + 91000 1 PolySwarm: Alert - $(polyswarm.source.file) - $(polyswarm.positives) engines detected this file gdpr_IV_35.7.d,