{"repo":"muchdogesec/obstracts","free":true,"listed":false,"github":"https://github.com/muchdogesec/obstracts","clone":"git clone https://github.com/muchdogesec/obstracts.git","description":"Turn any blog into structured threat intelligence.","language":"Python","stars":60,"topics":["atom","blog","rss","threat-hunting","threat-intel","threat-intelligence"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Obstracts Before you begin... We offer a fully hosted web version of Obstracts which includes many additional features over those in this codebase. You can find out more about the web version here. Overview Obstracts takes a blog ATOM or RSS feed and converts into structured threat intelligence. Organisations subscribe to lots of blogs for security information. These blogs contain interesting indicators of malicious activity (e.g. malicious URL). To help automate the extraction of this information, Obstracts automatically downloads blog articles and extracts indicators for viewing to a user. It works at a high level like so: 1. A feed is added to Obstracts by user (selecting profile to be used) 2. Obstracts uses history4feed as a microservice to handle the download and storage of posts. 3. The HTML from history4feed for each blog post is converted to markdown using file2txt in html mode 4. The markdown is run through txt2stix where txt2stix pattern extractions/whitelists/aliases are run based on staff defined profile 5. STIX bundles are generated for each post of the blog, and stored in an ArangoDB database called obstracts database and Collections names matching the blog 6. A user can access the bundle data or specific objects in the bundle via the API 7. As new posts are added to remote blogs, user makes request to update blog and these are requested by history4feed Install Download and configure Pre-requisites IMPORTANT : ArangoDB and Postgres must be running. These are no","default_branch":null,"files":null,"tree":[],"storefront":"/r/muchdogesec","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/muchdogesec/obstracts/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}