This is a fork of InfoSharing with an interactive menu to create, push and poll your IoC.
These instructions will explain you hot to make this project up and running on your local machine.
At first you need to solve all dependencies:
# cabby
sudo pip install cabby
# python-cybox
git clone https://github.com/CybOXProject/python-cybox.git
cd python-cybox/
sudo python setup.py install
# python-stix
git clone https://github.com/STIXProject/python-stix.git
cd python-stix
sudo python setup.py install
# stix
sudo pip install stix #already installed with cabby. But in case of issue.....
sudo pip install stix2
# validators
sudo pip install validators
Once dowloaded this package you have just to run the script as showed here below:
sh# python infosharing.py
An interactive menu will be displayed:
Welcome to Cyber Saiyan Info-Sharing
Please choose the option you want to run:
1. Add new IoC
2. Push IoC Stix 1.2
3. Push IoC Stix 2
4. Poll InfoSharing Server
0. Quit
The first option, that will run the main script CS_build_stix requires you to single out main details as title, description author and source file of your IoC. Here below what will be displayed:
Insert Title Ioc:Title Example
Insert Decription:Test Script
Insert User Identity:usertest
Add IoC Source File:../test.txt
Stix File generation in progress....
Writing STIX 1.2 package: package.stix
Writing STIX 2 package: package.stix2
>>
The script will generate two new file that contain your IoC according Stix 1.2 and Stix 2 taxonomy
Writing STIX 1.2 package: package.stix
Writing STIX 2 package: package.stix2
Here an example:
- package.stix - File Stix 1.2 (XML)
- package.stix2 - File Stix 2 (JSON)
The option 2 and 3 allow to push your IoC according the taxonomy you prefer. Both option will run a shell script:
- Stix 1.2 - Script to push Ioc according Stix 1.2 Taxonomy
- Stix 2 - Script to push Ioc according Stix 2 Taxonomy
IMPORTANT: Modify both scripts changing the password used to authenticate the session
The option 3 polls the InfoSharing server to check if your IoC have been uploaded correctly. Wait for about 5 minutes before polling.
- Poll - Script to poll the InfoSharing web server to check if your IoC have been uploaded
This option doesn't require any authentication and should be runned ten minutes after pushing the IoC packages.