elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
24 stars 436 forks source link

Add Shodan integration #5342

Open colin-stubbs opened 1 year ago

colin-stubbs commented 1 year ago

Integration release checklist

Shodan provides data about hosts scanned/observed on the public Internet. This is a useful data source to Security Operations Centres, and any teams responsible for monitoring infrastructure, as well as security researchers.

Alerting from Shodan is provided by the Shodan Monitor service, which can be used to obtain push style alerts via webhook, which provides notification of new exposed services on monitored hosts and hosts related to DNS names, as well as vulnerabilities discovered on those hosts.

All changes

New Package

Dashboards changes

Log dataset changes

elasticmachine commented 1 year ago

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

colin-stubbs commented 1 year ago

PR inbound tomorrow :-)

colin-stubbs commented 1 year ago

@jamiehynds it's a monster, but it had to be to do battle with Shodan's data...