TheresAFewConors / Sooty

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.
GNU General Public License v3.0
1.31k stars 205 forks source link

PhishTank Capability #18

Closed Gurulhu closed 4 years ago

Gurulhu commented 5 years ago

Fixes #8

Gurulhu commented 5 years ago

Does this work with URL's as well as IP addresses as is? If so, I can approve straight off - if not can that be added?

Actually, PhishTank only works for URLs, it doesn't classify IPs. Maybe we should treat IPs and URLs separately.

TheresAFewConors commented 4 years ago

Apologies for the delay on responding here. Feature looks good, I think it would make sense to do a DNS lookup for IP's, and submit those domains if a URL is not submitted. That way the majority of submissions can be checked in one go, rather than having to individually search for URL / IP. There is already a function for DNS lookups if you want to utilise that to get the domains.

Besides that looks good to me. I'll approve once we get this part worked out. Thanks again.

TheresAFewConors commented 4 years ago

closing due to inactivity