OpenCTI-Platform / opencti

Open Cyber Threat Intelligence Platform
https://opencti.io
Other
6.11k stars 906 forks source link

[MalwareBazaar Recent Additions] unsafe Download option #2601

Open R3dHash opened 1 year ago

R3dHash commented 1 year ago

Use case

Our Opencti platform in production environment is shared by several profiles including non technical ones that could by a misclick download a malicious payload from that feed. We think that it would be safer to restrict that option to a specific group of persons. Moreover unless there's is a constraint that we did not have identified we think it would be safer to NOT unzip the password-protected archive downloaded from Abuse. From a storage capacity perspective, we would reduce the overall size of stored payloads.

Current Workaround

We found no workaround unless deactivating the connector.

Proposed Solution

Additional Information

image

If the feature request is approved, would you be willing to submit a PR?

Yes

SamuelHassine commented 1 year ago

Related to #1580.