You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Since extracting file observables from reports was implemented in TheHive-Project/TheHive#982 (i still can't wrap my head around how I'm supposed build the report that TheHive picks the file due to lack of knowledge and documentation) it would be extremely useful, if the FileInfo Analyzer would this, especially in the Outlook submodule.
Example workflow after Improvement
upload any malspam.msg which includes a malicious .doc and analyze with FileInfo
import malicious .doc attachment provided in the report as file observable
scan attachment to gain more insight real quick
If you could point me to the right direction, for example how a report has to look like to trigger TheHive to pick up file observables, I'd try to implement this improvement by myself and create a pull request.
The text was updated successfully, but these errors were encountered:
Request Type
Feature / Improvement
Description
Since extracting file observables from reports was implemented in TheHive-Project/TheHive#982 (i still can't wrap my head around how I'm supposed build the report that TheHive picks the file due to lack of knowledge and documentation) it would be extremely useful, if the FileInfo Analyzer would this, especially in the Outlook submodule.
Example workflow after Improvement
If you could point me to the right direction, for example how a report has to look like to trigger TheHive to pick up file observables, I'd try to implement this improvement by myself and create a pull request.
The text was updated successfully, but these errors were encountered: