CybercentreCanada / assemblyline

AssemblyLine 4: File triage and malware analysis
https://cybercentrecanada.github.io/assemblyline4_docs/
MIT License
249 stars 15 forks source link

Add campaign attribution to badlist updates #260

Closed kam193 closed 2 months ago

kam193 commented 2 months ago

Is your feature request related to a problem? Please describe. Currently, the badlist source update supports setting only two attribution tags: actor and malware family. They don't match my use case, where I'd like to set a campaign name.

Describe the solution you'd like Adding a campaign tag to attribution tags supported by badlist source update.

Describe alternatives you've considered Adding all attribution tags! :D

Additional context Would be great to add a JSON config field directly to the update source config, separating it from the service configuration ;)

I also don't think there is any standardisation across campaign names, so I wouldn't suggest adding a list of allowed names.