Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC Internet Storm Center


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Latest Diaries

Now supporting OpenIOC via our API!

Published: 2014-08-21
Last Updated: 2014-08-21 18:52:34 UTC
by Alex Stanford (Version: 1)
0 comment(s)
The SANS Internet Storm Center is proud to announce the release of our first OpenIOC format API call. We have been hard at work writing a method that serves our firewall logs as OpenIOC XML content dynamically from a RESTful HTTP request. This is a critical step in expanding our service offerings to you, our readers, members and contributors.
 
You can use tools that ISC handler Russ McRee mentioned in a previous diary to convert output from this new method into STIX format. This is just the beginning however; the development roadmap includes the addition of another API method with the same data served in STIX format!
 
Ready to get started? View the documentation here: https://isc.sans.edu/api/#openiocsources
 
Please share your your feedback as well as use cases and success stories as they unfold in the comments below.
 
A big thanks to Russ McRee for his assistance with testing and the writing of this announcement!

-- 
Alex Stanford - GIAC GWEB & GSEC
Research Operations Manager,
SANS Internet Storm Center

Keywords:
0 comment(s)
ISC StormCast for Thursday, August 21st 2014 http://isc.sans.edu/podcastdetail.html?id=4115

If you have more information or corrections regarding our diary, please share.

Recent Diaries

Social Engineering Alive and Well
published 1 day ago by Kevin Shortt (1 comment)

Part 2: Is your home network unwittingly contributing to NTP DDOS attacks?
published 2 days ago by Rick (1 comment)

Web Server Attack Investigation - Installing a Bot and Reverse Shell via a PHP Vulnerability
published 3 days ago by Lenny (0 comments)

Part 1: Is your home network unwittingly contributing to NTP DDOS attacks?
published 4 days ago by Rick (2 comments)

Issues with Microsoft Updates
published 5 days ago by Manuel Humberto Santander Pelaacuteez (6 comments)

AppLocker Event Logs with OSSEC 2.8
published 6 days ago by Tom (1 comment)

PHP 5.3.29 is available, PHP 5.3 reaching end of life
published 1 week ago by Basil (0 comments)

Threats to virtual environments
published 1 week ago by Basil (0 comments)

View All Diaries →

Latest Discussions

recommender system for network intrusion detection
created 1 week ago by Anonymous (0 replies)

Stale prefixes associated with our AS
created 2 weeks ago by cj (0 replies)

DSHIELD with fail2ban
created 1 month ago by Ernest (0 replies)

Router Upgrade
created 1 month ago by ICI2Eye (2 replies)

ENDPOINT SERVICE DEFINITIONS (TCP/UDP)
created 1 month ago by Ratatosk (1 reply)

View All Forums →

Latest News

View All News →