intelmq.bots.experts.tuency package¶
Submodules¶
intelmq.bots.experts.tuency.expert module¶
© 2021 Sebastian Wagner <wagner@cert.at>
SPDX-License-Identifier: AGPL-3.0-or-later
https://gitlab.com/intevation/tuency/tuency/-/blob/master/backend/docs/IntelMQ-API.md
Example query: > curl -s -H “Authorization: Bearer XXX” ‘https://tuency-demo1.example.com/intelmq/lookup?classification_taxonomy=availability&classification_type=backdoor &feed_provider=Team+Cymru&feed_name=FTP&feed_status=production&ip=123.123.123.23’
same for domain= a query can contain both ip address and domain
Example response: {“ip”:{“destinations”:[{“source”:”portal”,”name”:”Thurner”,”contacts”:[{“email”:”test@example.com”}]}]},”suppress”:true,”interval”:{“unit”:”days”,”length”:1}} {“ip”:{“destinations”:[{“source”:”portal”,”name”:”Thurner”,”contacts”:[{“email”:”test@example.vom”}]}]},”domain”:{“destinations”:[{“source”:”portal”,”name”:”Thurner”,”contacts”:[{“email”:”abuse@example.at”}]}]},”suppress”:true,”interval”:{“unit”:”immediate”,”length”:1}}
-
intelmq.bots.experts.tuency.expert.
BOT
¶
-
class
intelmq.bots.experts.tuency.expert.
TuencyExpertBot
(bot_id: str, start: bool = False, sighup_event=None, disable_multithreading: bool = None)¶ Bases:
intelmq.lib.bot.Bot
-
init
()¶
-
overwrite
= True¶
-
process
()¶
-