Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VirusTotal as source #273

Open
ater49 opened this issue Oct 18, 2018 · 4 comments
Open

VirusTotal as source #273

ater49 opened this issue Oct 18, 2018 · 4 comments

Comments

@ater49
Copy link

ater49 commented Oct 18, 2018

Hi,

If you have a VirusTotal Intelligence, you can push some Yara Rules in order to monitor some leak/threats about specific targeting. Is it possible to add results of these searches as source of AIL ?

Here's the process:
YARA Rules into VT Intelligence > Results are sent to AIL > AIL use VT private API to download files > AIL do the same treatment of files as do for pasties

@deadbits
Copy link

deadbits commented Nov 9, 2018

I'd also love this. I do a lot of my leak hunting in VTI, and I know of several others others that do the same.

This would need to parse the json notifications feed for user defined YARA rules names and download the matching results

@deadbits
Copy link

deadbits commented Jan 9, 2019

I use VTI to monitor for data leaks just as much as Paste sites, personally. If the AIL primary devs/maintainers think this is OK to create, I can add this as a module myself to include in master? Cc: @adulau

@Terrtia
Copy link
Member

Terrtia commented Jan 11, 2019

hey @deadbits !

All pull requests are welcome :)

The VT key are located in configs/keys/virusTotalKEYS.py.

Let me know if you need help

@adulau
Copy link
Member

adulau commented Jan 11, 2019

@deadbits It sounds like a great idea. Don't hesitate to PR even a beta version. We would be glad to review it and integrate it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants