techservicesillinois / secops-splunk-null-router

null router app for Splunk SOAR
Other
3 stars 0 forks source link

Is not able to handle IPv6 IP addresses. #29

Closed livn46 closed 1 year ago

livn46 commented 1 year ago

Whenever an IPv6 address is passed to the BHR app, it fails. SOAR containers that can be viewed as examples are 68923 or 68924.

Tasks

edthedev commented 1 year ago

Re-opening this to add a regression test with an IPv6 address.

tzturner commented 1 year ago

We created a test SOAR playbook and hardcoded in the IPv6 address from event 68923 (2405:201:11:d046:adaa:55c5:dcfa:9b80). It ran successfully. We checked the BHR site for that IPv6 address and found the following.

image

Blocking of IPv6 addresses appears to be working.