tenzir / threatbus

🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.
https://docs.tenzir.com/threatbus
BSD 3-Clause "New" or "Revised" License
258 stars 16 forks source link

Plugin development #193

Closed tim-acki closed 2 years ago

tim-acki commented 2 years ago

Hello,

i would like to develop an own Plugin for threatbus. In the description are links to a guide on how to write a plugin (https://docs.tenzir.com/threatbus/plugins/plugin-development) and different plugin types (https://docs.tenzir.com/threatbus/plugins/overview). Unfortunately both links are redirected to the main page of vast.io, where i am not able to find the guides. Are the guides now located anywhere else and I am unable to find them? If not would it be possible to still get access to the guides?

Thanks in advance

Kind regards

mavam commented 2 years ago

Hi @tim-acki, thanks for reaching out! I'm sorry that the information is not very easily to put together. We are amidst a rewrite of Threat Bus, which itself is in maintenance mode.

The core functionality, pub-sub via STIX, was limited to Indicator SDOs and Sighting SROs in Threat Bus. We're opening up the fabric for a more flexible form of interconnection that also involve more complex objects, e.g., entire STIX bundles coming from MISP, or to contextualized alerts and then relay them to TheHive.

We are still in an alpha stage with this effort, but depending on your use case, this might actually be a good time to chime in and describe your use case. You can do that here or also interactively in our community Slack at http://slack.tenzir.com. Looking forward to hearing from you!

dominiklohmann commented 2 years ago

If not would it be possible to still get access to the guides?

The Threat Bus docs moved to vast.io/docs/use-vast/integrate/threatbus. All the information is still present.