<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using Minemeld for URL EDL in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-for-url-edl/m-p/234290#M97289</link>
    <description>&lt;P&gt;Dear MM comunity,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;I am trying to use MM for parsing a URL list to populate a PA NGFW which lacks Url filtering license.&lt;/P&gt;
&lt;P&gt;I have found that predefined miner&amp;nbsp; urlhaus.URL which seems very well done. It is based on&amp;nbsp;&lt;A href="https://urlhaus.abuse.ch/" target="_blank"&gt;https://urlhaus.abuse.ch/&lt;/A&gt;&amp;nbsp;, which is free of charge.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have cloned it, then cloned a URL aggregator and a URL Output.&lt;/P&gt;
&lt;P&gt;I used the following aggregator&lt;/P&gt;
&lt;TABLE class="table table-condensed nodedetail-info-table"&gt;
&lt;TBODY&gt;
&lt;TR class=""&gt;
&lt;TD&gt;PROTOTYPE&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://wdoria-rg1-mm.westeurope.cloudapp.azure.com/#/prototypes/stdlib/aggregatorURL" target="_blank"&gt;stdlib.aggregatorURL&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;and the following URL output&lt;/P&gt;
&lt;TABLE class="table table-condensed nodedetail-info-table"&gt;
&lt;TBODY&gt;
&lt;TR class=""&gt;
&lt;TD&gt;PROTOTYPE&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://wdoria-rg1-mm.westeurope.cloudapp.azure.com/#/prototypes/stdlib/feedHCWithValue" target="_blank"&gt;stdlib.feedHCWithValue&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, I obtained an output, but seems it is not useful for NGFW (running 8.1 version) , probably because of http:// in front of every URL&lt;/P&gt;
&lt;P&gt;that is the output&amp;nbsp; (BE CAREFUL DON'T CLICK THEM)&lt;/P&gt;
&lt;P&gt;[...]&lt;/P&gt;
&lt;PRE&gt;http://0-day.us/img/exe/7.exe
http://0-day.us/img/exe/8.ex&lt;BR /&gt;http://0-day.us/img/puttsy.vbs &lt;BR /&gt;http://00294949493yur93.space/1ishuwuycywgeacqylyik.exe&lt;BR /&gt;http://01.azrj-phone.zuliyego.cn/wenbenchakanqi_yxdown.com.apk&lt;/PRE&gt;
&lt;P&gt;[...]&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think I need to strip the http:// in order to be used by Panos..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For reference the queue reference the complete output is that:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://wdoria-rg1-mm.westeurope.cloudapp.azure.com/feeds/ABUSE-feedHCWithValue" target="_blank"&gt;https://wdoria-rg1-mm.westeurope.cloudapp.azure.com/feeds/ABUSE-feedHCWithValue&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any tips is appreciated.&lt;/P&gt;
&lt;P&gt;Walter Doria&lt;/P&gt;</description>
    <pubDate>Sun, 07 Oct 2018 08:41:21 GMT</pubDate>
    <dc:creator>wdoria</dc:creator>
    <dc:date>2018-10-07T08:41:21Z</dc:date>
    <item>
      <title>Using Minemeld for URL EDL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-for-url-edl/m-p/234290#M97289</link>
      <description>&lt;P&gt;Dear MM comunity,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;I am trying to use MM for parsing a URL list to populate a PA NGFW which lacks Url filtering license.&lt;/P&gt;
&lt;P&gt;I have found that predefined miner&amp;nbsp; urlhaus.URL which seems very well done. It is based on&amp;nbsp;&lt;A href="https://urlhaus.abuse.ch/" target="_blank"&gt;https://urlhaus.abuse.ch/&lt;/A&gt;&amp;nbsp;, which is free of charge.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have cloned it, then cloned a URL aggregator and a URL Output.&lt;/P&gt;
&lt;P&gt;I used the following aggregator&lt;/P&gt;
&lt;TABLE class="table table-condensed nodedetail-info-table"&gt;
&lt;TBODY&gt;
&lt;TR class=""&gt;
&lt;TD&gt;PROTOTYPE&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://wdoria-rg1-mm.westeurope.cloudapp.azure.com/#/prototypes/stdlib/aggregatorURL" target="_blank"&gt;stdlib.aggregatorURL&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;and the following URL output&lt;/P&gt;
&lt;TABLE class="table table-condensed nodedetail-info-table"&gt;
&lt;TBODY&gt;
&lt;TR class=""&gt;
&lt;TD&gt;PROTOTYPE&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://wdoria-rg1-mm.westeurope.cloudapp.azure.com/#/prototypes/stdlib/feedHCWithValue" target="_blank"&gt;stdlib.feedHCWithValue&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, I obtained an output, but seems it is not useful for NGFW (running 8.1 version) , probably because of http:// in front of every URL&lt;/P&gt;
&lt;P&gt;that is the output&amp;nbsp; (BE CAREFUL DON'T CLICK THEM)&lt;/P&gt;
&lt;P&gt;[...]&lt;/P&gt;
&lt;PRE&gt;http://0-day.us/img/exe/7.exe
http://0-day.us/img/exe/8.ex&lt;BR /&gt;http://0-day.us/img/puttsy.vbs &lt;BR /&gt;http://00294949493yur93.space/1ishuwuycywgeacqylyik.exe&lt;BR /&gt;http://01.azrj-phone.zuliyego.cn/wenbenchakanqi_yxdown.com.apk&lt;/PRE&gt;
&lt;P&gt;[...]&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think I need to strip the http:// in order to be used by Panos..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For reference the queue reference the complete output is that:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://wdoria-rg1-mm.westeurope.cloudapp.azure.com/feeds/ABUSE-feedHCWithValue" target="_blank"&gt;https://wdoria-rg1-mm.westeurope.cloudapp.azure.com/feeds/ABUSE-feedHCWithValue&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any tips is appreciated.&lt;/P&gt;
&lt;P&gt;Walter Doria&lt;/P&gt;</description>
      <pubDate>Sun, 07 Oct 2018 08:41:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-for-url-edl/m-p/234290#M97289</guid>
      <dc:creator>wdoria</dc:creator>
      <dc:date>2018-10-07T08:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Using Minemeld for URL EDL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-for-url-edl/m-p/234305#M97290</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42661"&gt;@wdoria&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;just add the "?v=panosurl" at the end of the output node url to get all these anonying prefixes being removed by MineMeld.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More details in &lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Parameters-for-the-output-feeds/ta-p/146170" target="_self"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Parameters-for-the-output-feeds/ta-p/146170&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Oct 2018 10:01:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-for-url-edl/m-p/234305#M97290</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-10-07T10:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Using Minemeld for URL EDL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-for-url-edl/m-p/243908#M97291</link>
      <description>&lt;P&gt;I would like to use the urlhaus list as well, but it currently has over 90,000 entries, while the PA-5000 and PA-7000 support a maximum of 50,000 URLs.&amp;nbsp; Is there a smarter way to trim this list other than just blindly dropping the oldest entries using the "?n=50000" parameter?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 19:46:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-for-url-edl/m-p/243908#M97291</guid>
      <dc:creator>dhenke</dc:creator>
      <dc:date>2018-12-19T19:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Using Minemeld for URL EDL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-for-url-edl/m-p/243986#M97292</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71691"&gt;@dhenke&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is there any "confidence-like" value attached to the indicators you could use as a input filter criteria?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 08:09:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-for-url-edl/m-p/243986#M97292</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-12-20T08:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Using Minemeld for URL EDL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-for-url-edl/m-p/244030#M97293</link>
      <description>&lt;P&gt;Unfortunately, no.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The predefined miner urlhaus.yml has a url of &lt;SPAN class="pl-s"&gt;&lt;A href="https://urlhaus.abuse.ch/downloads/text/" target="_blank"&gt;https://urlhaus.abuse.ch/downloads/text/&lt;/A&gt;, which is just a listing of malware URLs with no other values.&amp;nbsp; There is a different url at &lt;A href="https://urlhaus.abuse.ch/downloads/csv/" target="_blank"&gt;https://urlhaus.abuse.ch/downloads/csv/&lt;/A&gt; that has several fields (ID, Dateadded, URL, URL status,&amp;nbsp;Threat, Associated tags, and Link to URLhaus entry), but none with a confidence value.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="pl-s"&gt;I suppose one could re-write the miner to use the other URL and generate their own level of confidence from the "Dateadded" and "URL status" (excluding the oldest entries that have an "offline" status), but that's a little beyond my current level of proficiency.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 14:04:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-for-url-edl/m-p/244030#M97293</guid>
      <dc:creator>dhenke</dc:creator>
      <dc:date>2018-12-20T14:04:48Z</dc:date>
    </item>
  </channel>
</rss>

