Skip to content

[Filebeat] Malware Bazaar Dataset for Threat Intel Module #24569

@peasead

Description

@peasead

Modules

Describe the enhancement:
Currently, the threat intel module for Filebeat did not have the data provided by Malware Bazaar.

Malware Bazaar provides rich file metadata about malware that can assist cyber intelligence analysts, threat hunters, and incident responders during incident response and ongoing security operations.

Describe a specific use case for the enhancement or feature:
Threat hunting, security operations, and intelligence analysis.

Filebeat module

  • Test log files exist for the grok patterns
  • Generated output for at least 1 log file exists

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions