diff --git a/integrations/feed-taxii2/manifest.yaml b/integrations/feed-taxii2/manifest.yaml new file mode 100644 index 0000000..fa6950b --- /dev/null +++ b/integrations/feed-taxii2/manifest.yaml @@ -0,0 +1,64 @@ +id: feed_taxii2 +name: TAXII 2 Feed +version: 1.0.0 +description: "Generic TAXII 2.1 threat-intel feed connector — pull STIX 2.x indicators from any TAXII 2.1 server (OpenCTI, Anomali, MISP, CISA AIS, ...) and emit normalized IOCs (value + type) parsed from the STIX patterns, for import into the Threat Indicator Manager. Basic or bearer authentication; stdlib-only, no extra Python dependencies." +changelog: "1.0.0 — Initial release: list collections, fetch indicators from a TAXII 2.1 collection." +category: feed + +# Per-instance configuration. api_root_url is the TAXII 2.1 API root +# (e.g. https://server/taxii2/api1). auth_type selects none/basic/bearer. +config_schema: + properties: + api_root_url: + type: string + description: "TAXII 2.1 API root URL (e.g. https://server/taxii2/api1)" + collection_id: + type: string + description: "Default collection ID to fetch from" + auth_type: + type: string + description: "none, basic, or bearer (default basic)" + default: "basic" + username: + type: string + description: "Username (for basic auth)" + password: + type: string + description: "Password (basic) or token (bearer)" + x-soar-sensitive: true + insecure: + type: boolean + description: "Trust any TLS certificate (not secure)" + default: false + required: + - api_root_url + +commands: + - id: list_collections + name: feed-taxii2-list-collections + description: "List the collections available on the TAXII 2.1 API root." + risk: read + inputs_schema: + properties: {} + required: [] + outputs_schema: { properties: {} } + - id: fetch_indicators + name: feed-taxii2-fetch-indicators + description: "Fetch STIX indicators from a collection and return normalized IOCs." + risk: read + inputs_schema: + properties: + collection_id: { type: string, description: "Collection ID (defaults to the configured one)" } + added_after: { type: string, description: "Only objects added after this timestamp (ISO-8601)" } + limit: { type: number, description: "Max objects to request (default 500)" } + required: [] + outputs_schema: { properties: {} } + + - id: test_connection + name: feed-taxii2-test-connection + description: "Verify the TAXII server and credentials (used by the Test button)." + risk: read + inputs_schema: + properties: {} + required: [] + outputs_schema: { properties: {} } diff --git a/integrations/feed-taxii2/scripts/fetch_indicators.py b/integrations/feed-taxii2/scripts/fetch_indicators.py new file mode 100644 index 0000000..69b3154 --- /dev/null +++ b/integrations/feed-taxii2/scripts/fetch_indicators.py @@ -0,0 +1,117 @@ +import json, os, sys, re, ssl, base64, urllib.parse, urllib.request, urllib.error + + +def _cfg(): + return json.loads(os.environ.get("INTEGRATION_SECRETS", "{}")) + + +def _inputs(): + return json.loads(os.environ.get("INTEGRATION_INPUTS", "{}")) + + +def _ctx(cfg): + if cfg.get("insecure"): + c = ssl.create_default_context() + c.check_hostname = False + c.verify_mode = ssl.CERT_NONE + return c + return None + + +def _root(cfg): + return str(cfg.get("api_root_url", "")).rstrip("/") + + +def _headers(cfg): + h = {"Accept": "application/taxii+json;version=2.1", "User-Agent": "Riposte-SOAR"} + at = str(cfg.get("auth_type") or "basic").lower() + if at == "basic": + raw = str(cfg.get("username", "")) + ":" + str(cfg.get("password", "")) + h["Authorization"] = "Basic " + base64.b64encode(raw.encode("utf-8")).decode("ascii") + elif at == "bearer": + h["Authorization"] = "Bearer " + str(cfg.get("password", "")) + return h + + +def request(path, cfg, params=None): + url = _root(cfg) + path + if params: + clean = {k: v for k, v in params.items() if v not in (None, "")} + if clean: + url += "?" + urllib.parse.urlencode(clean) + req = urllib.request.Request(url, headers=_headers(cfg), method="GET") + with urllib.request.urlopen(req, timeout=120, context=_ctx(cfg)) as r: + raw = r.read() + return json.loads(raw) if raw else {} + + +# STIX pattern parsing: extract stix object type + value from an indicator pattern +# e.g. [ipv4-addr:value = '1.2.3.4'] , [domain-name:value = 'bad.com'] , +# [file:hashes.'SHA-256' = 'abc...'] , [url:value = 'http://x'] +_PAT = re.compile(r"(\w[\w-]*):(?:value|hashes\.'?[\w:-]+'?)\s*=\s*'([^']+)'") + +_STIX_TYPE = { + "ipv4-addr": "ip", "ipv6-addr": "ip", + "domain-name": "domain", + "url": "url", + "email-addr": "email", "email-message": "email", + "file": "hash", + "user-account": "user", +} + + +def parse_pattern(pattern): + out = [] + for m in _PAT.finditer(pattern or ""): + stix_type, value = m.group(1), m.group(2) + t = _STIX_TYPE.get(stix_type) + if t: + out.append({"value": value, "type": t}) + return out + + +def _run(fn): + try: + print(json.dumps(fn(_cfg(), _inputs()))) + except urllib.error.HTTPError as e: + print(json.dumps({"error": "HTTP " + str(e.code), "detail": e.read().decode("utf-8", "replace")})) + sys.exit(1) + except Exception as e: + print(json.dumps({"error": str(e)})) + sys.exit(1) + + +q = lambda v: urllib.parse.quote(str(v), safe="") + + +def main(cfg, inputs): + cid = inputs.get("collection_id") or cfg.get("collection_id") + if not cid: + raise Exception("collection_id is required") + + added_after = inputs.get("added_after") + limit = inputs.get("limit") + + resp = request( + "/collections/" + q(cid) + "/objects/", + cfg, + params={"added_after": added_after, "limit": int(limit or 500)}, + ) + + indicators = [] + for obj in resp.get("objects", []): + if obj.get("type") == "indicator": + for parsed in parse_pattern(obj.get("pattern")): + parsed["stix_id"] = obj.get("id") + parsed["labels"] = obj.get("labels") + indicators.append(parsed) + + return { + "collection_id": cid, + "count": len(indicators), + "indicators": indicators, + "more": resp.get("more", False), + } + + +_run(main) diff --git a/integrations/feed-taxii2/scripts/list_collections.py b/integrations/feed-taxii2/scripts/list_collections.py new file mode 100644 index 0000000..37c477b --- /dev/null +++ b/integrations/feed-taxii2/scripts/list_collections.py @@ -0,0 +1,88 @@ +import json, os, sys, re, ssl, base64, urllib.parse, urllib.request, urllib.error + + +def _cfg(): + return json.loads(os.environ.get("INTEGRATION_SECRETS", "{}")) + + +def _inputs(): + return json.loads(os.environ.get("INTEGRATION_INPUTS", "{}")) + + +def _ctx(cfg): + if cfg.get("insecure"): + c = ssl.create_default_context() + c.check_hostname = False + c.verify_mode = ssl.CERT_NONE + return c + return None + + +def _root(cfg): + return str(cfg.get("api_root_url", "")).rstrip("/") + + +def _headers(cfg): + h = {"Accept": "application/taxii+json;version=2.1", "User-Agent": "Riposte-SOAR"} + at = str(cfg.get("auth_type") or "basic").lower() + if at == "basic": + raw = str(cfg.get("username", "")) + ":" + str(cfg.get("password", "")) + h["Authorization"] = "Basic " + base64.b64encode(raw.encode("utf-8")).decode("ascii") + elif at == "bearer": + h["Authorization"] = "Bearer " + str(cfg.get("password", "")) + return h + + +def request(path, cfg, params=None): + url = _root(cfg) + path + if params: + clean = {k: v for k, v in params.items() if v not in (None, "")} + if clean: + url += "?" + urllib.parse.urlencode(clean) + req = urllib.request.Request(url, headers=_headers(cfg), method="GET") + with urllib.request.urlopen(req, timeout=120, context=_ctx(cfg)) as r: + raw = r.read() + return json.loads(raw) if raw else {} + + +# STIX pattern parsing: extract stix object type + value from an indicator pattern +# e.g. [ipv4-addr:value = '1.2.3.4'] , [domain-name:value = 'bad.com'] , +# [file:hashes.'SHA-256' = 'abc...'] , [url:value = 'http://x'] +_PAT = re.compile(r"(\w[\w-]*):(?:value|hashes\.'?[\w:-]+'?)\s*=\s*'([^']+)'") + +_STIX_TYPE = { + "ipv4-addr": "ip", "ipv6-addr": "ip", + "domain-name": "domain", + "url": "url", + "email-addr": "email", "email-message": "email", + "file": "hash", + "user-account": "user", +} + + +def parse_pattern(pattern): + out = [] + for m in _PAT.finditer(pattern or ""): + stix_type, value = m.group(1), m.group(2) + t = _STIX_TYPE.get(stix_type) + if t: + out.append({"value": value, "type": t}) + return out + + +def _run(fn): + try: + print(json.dumps(fn(_cfg(), _inputs()))) + except urllib.error.HTTPError as e: + print(json.dumps({"error": "HTTP " + str(e.code), "detail": e.read().decode("utf-8", "replace")})) + sys.exit(1) + except Exception as e: + print(json.dumps({"error": str(e)})) + sys.exit(1) + + +def main(cfg, inputs): + return request("/collections/", cfg) + + +_run(main) diff --git a/integrations/feed-taxii2/scripts/test_connection.py b/integrations/feed-taxii2/scripts/test_connection.py new file mode 100644 index 0000000..93e2897 --- /dev/null +++ b/integrations/feed-taxii2/scripts/test_connection.py @@ -0,0 +1,89 @@ +import json, os, sys, re, ssl, base64, urllib.parse, urllib.request, urllib.error + + +def _cfg(): + return json.loads(os.environ.get("INTEGRATION_SECRETS", "{}")) + + +def _inputs(): + return json.loads(os.environ.get("INTEGRATION_INPUTS", "{}")) + + +def _ctx(cfg): + if cfg.get("insecure"): + c = ssl.create_default_context() + c.check_hostname = False + c.verify_mode = ssl.CERT_NONE + return c + return None + + +def _root(cfg): + return str(cfg.get("api_root_url", "")).rstrip("/") + + +def _headers(cfg): + h = {"Accept": "application/taxii+json;version=2.1", "User-Agent": "Riposte-SOAR"} + at = str(cfg.get("auth_type") or "basic").lower() + if at == "basic": + raw = str(cfg.get("username", "")) + ":" + str(cfg.get("password", "")) + h["Authorization"] = "Basic " + base64.b64encode(raw.encode("utf-8")).decode("ascii") + elif at == "bearer": + h["Authorization"] = "Bearer " + str(cfg.get("password", "")) + return h + + +def request(path, cfg, params=None): + url = _root(cfg) + path + if params: + clean = {k: v for k, v in params.items() if v not in (None, "")} + if clean: + url += "?" + urllib.parse.urlencode(clean) + req = urllib.request.Request(url, headers=_headers(cfg), method="GET") + with urllib.request.urlopen(req, timeout=120, context=_ctx(cfg)) as r: + raw = r.read() + return json.loads(raw) if raw else {} + + +# STIX pattern parsing: extract stix object type + value from an indicator pattern +# e.g. [ipv4-addr:value = '1.2.3.4'] , [domain-name:value = 'bad.com'] , +# [file:hashes.'SHA-256' = 'abc...'] , [url:value = 'http://x'] +_PAT = re.compile(r"(\w[\w-]*):(?:value|hashes\.'?[\w:-]+'?)\s*=\s*'([^']+)'") + +_STIX_TYPE = { + "ipv4-addr": "ip", "ipv6-addr": "ip", + "domain-name": "domain", + "url": "url", + "email-addr": "email", "email-message": "email", + "file": "hash", + "user-account": "user", +} + + +def parse_pattern(pattern): + out = [] + for m in _PAT.finditer(pattern or ""): + stix_type, value = m.group(1), m.group(2) + t = _STIX_TYPE.get(stix_type) + if t: + out.append({"value": value, "type": t}) + return out + + +def _run(fn): + try: + print(json.dumps(fn(_cfg(), _inputs()))) + except urllib.error.HTTPError as e: + print(json.dumps({"error": "HTTP " + str(e.code), "detail": e.read().decode("utf-8", "replace")})) + sys.exit(1) + except Exception as e: + print(json.dumps({"error": str(e)})) + sys.exit(1) + + +def main(cfg, inputs): + request("/collections/", cfg) + return {"ok": True} + + +_run(main)