import json, os, sys, ssl, urllib.request, urllib.error URL = "https://threatfox.abuse.ch/export/json/recent/" _TMAP = { "ip:port": "ip", "domain": "domain", "url": "url", "md5_hash": "hash", "sha1_hash": "hash", "sha256_hash": "hash", } def _cfg(): return json.loads(os.environ.get("INTEGRATION_SECRETS", "{}")) def _inputs(): return json.loads(os.environ.get("INTEGRATION_INPUTS", "{}")) def _ctx(cfg): if cfg.get("insecure"): c = ssl.create_default_context() c.check_hostname = False c.verify_mode = ssl.CERT_NONE return c return None def _headers(cfg): h = {"User-Agent": "Riposte-SOAR", "Accept": "application/json"} k = cfg.get("api_key") if k: h["Auth-Key"] = str(k) return h def _get(url, cfg): req = urllib.request.Request(url, headers=_headers(cfg)) with urllib.request.urlopen(req, timeout=120, context=_ctx(cfg)) as r: return r.read() def _run(fn): try: print(json.dumps(fn(_cfg(), _inputs()))) except urllib.error.HTTPError as e: print(json.dumps({"error": "HTTP " + str(e.code), "detail": e.read().decode("utf-8", "replace")})) sys.exit(1) except Exception as e: print(json.dumps({"error": str(e)})) sys.exit(1) def main(cfg, inputs): raw = _get(URL, cfg) data = json.loads(raw) if raw else {} maxn = int(inputs.get("max_indicators") or 0) out = [] items = data.items() if isinstance(data, dict) else [] for _id, arr in items: if not isinstance(arr, list): continue for e in arr: if not isinstance(e, dict): continue ioc = e.get("ioc") if not ioc: continue it = e.get("ioc_type") t = _TMAP.get(it, "other") val = ioc.split(":")[0] if it == "ip:port" else ioc out.append({ "value": val, "type": t, "ioc_type": it, "malware": e.get("malware_printable") or e.get("malware"), "threat_type": e.get("threat_type"), "confidence": e.get("confidence_level"), "first_seen": e.get("first_seen_utc"), }) if maxn and len(out) >= maxn: return {"source": "threatfox:recent", "count": len(out), "indicators": out} return {"source": "threatfox:recent", "count": len(out), "indicators": out} _run(main)