- Notifications
You must be signed in to change notification settings - Fork 519
ti_abusech: add ja3_fingerprints and sslblacklist data streams #14703
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
b771d1a to d76fade Compare 🚀 Benchmarks reportPackage |
| Data stream | Previous EPS | New EPS | Diff (%) | Result |
|---|---|---|---|---|
sslblacklist | 0 | 23255.81 | 23255.81 ( - %) | 👍 |
threatfox | 0 | 19230.77 | 19230.77 ( - %) | 👍 |
url | 0 | 15384.62 | 15384.62 ( - %) | 👍 |
ja3_fingerprints | 0 | 6688.96 | 6688.96 ( - %) | 👍 |
malware | 0 | 11325.03 | 11325.03 ( - %) | 👍 |
malwarebazaar | 0 | 11534.03 | 11534.03 ( - %) | 👍 |
sslblacklist | 0 | 19157.09 | 19157.09 ( - %) | 👍 |
threatfox | 0 | 10822.51 | 10822.51 ( - %) | 👍 |
url | 0 | 8347.25 | 8347.25 ( - %) | 👍 |
ja3_fingerprints | 0 | 15384.62 | 15384.62 ( - %) | 👍 |
malware | 0 | 17543.86 | 17543.86 ( - %) | 👍 |
malwarebazaar | 0 | 14705.88 | 14705.88 ( - %) | 👍 |
| Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
8d1042a to bc53e9c Compare e47427e to a965ff1 Compare Bump to kibana.version is required to pick up transformMapEntry CEL macro. Test samples obtained from the relevant API endpoints.
| /test benchmark fullreport |
kcreddy left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just some nits and clarification. LGTM overall.
| - name: threat.feed.name | ||
| type: constant_keyword | ||
| description: Display friendly feed name | ||
| value: AbuseCH URL |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| value: AbuseCH URL | |
| value: AbuseCH JA3 Fingerprint Blacklist |
| required: true | ||
| show_user: true | ||
| default: 1h | ||
| description: Interval for polling indicators from AbuseCH data dump. As data dump is generated every 5 minutes, it should be greater than 5 minutes. Default `1h`. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| description: Interval for polling indicators from AbuseCH data dump. As data dump is generated every 5 minutes, it should be greater than 5 minutes. Default `1h`. | |
| description: Interval for polling threat indicators from AbuseCH data dump. As data dump is generated every 5 minutes, it should be greater than 5 minutes. Default `1h`. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
snap!
| - name: threat.feed.name | ||
| type: constant_keyword | ||
| description: Display friendly feed name | ||
| value: AbuseCH URL |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| value: AbuseCH URL | |
| value: AbuseCH SSL Certificate Blacklist |
| required: true | ||
| show_user: true | ||
| default: 1h | ||
| description: Interval for polling indicators from AbuseCH data dump. As data dump is generated every 5 minutes, it should be greater than 5 minutes. Default `1h`. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| description: Interval for polling indicators from AbuseCH data dump. As data dump is generated every 5 minutes, it should be greater than 5 minutes. Default `1h`. | |
| description: Interval for polling threat indicators from AbuseCH data dump. As data dump is generated every 5 minutes, it should be greater than 5 minutes. Default `1h`. |
| - event.dataset | ||
| - threat.indicator.name | ||
| sort: "@timestamp" | ||
| description: Latest Abuse CH URL data. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| description: Latest Abuse CH URL data. | |
| description: Latest Abuse CH SSL Certificate Blacklist data. |
| - event.dataset | ||
| - threat.indicator.name | ||
| sort: "@timestamp" | ||
| description: Latest Abuse CH URL data. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| description: Latest Abuse CH URL data. | |
| description: Latest Abuse CH JA3 Fingerprint Blacklist data. |
| conditions: | ||
| kibana: | ||
| version: "^8.18.0 || ^9.0.0" | ||
| version: "^8.19.0 || ^9.1.0" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is this for using two var comprehensions?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes.
💚 Build Succeeded
History
cc @efd6 |
|
| Package ti_abusech - 3.2.0 containing this change is available at https://epr.elastic.co/package/ti_abusech/3.2.0/ |
…ic#14703) Bump to kibana.version is required to pick up transformMapEntry CEL macro. Test samples obtained from the relevant API endpoints.


Proposed commit message
Checklist
changelog.ymlfile.Author's Checklist
How to test this PR locally
Related issues
Screenshots