<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrate with MISP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/174491#M97626</link>
    <description>&lt;P&gt;Thanks&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71673"&gt;@vedd3r&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MineMeld is modular enough to accomodate 'enrichement'. For instance you could create an aggregator sort of node that checks IPv4 against your threat intel source (i.e. Wildfire / AutoFocus) to attach 'enrichement attributes' to that indicator.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm planning, for instance, on creating an enrichement node for MineMeld that will attach the PAN-DB URL category value as an attribute to all URL indicators received by that node. Each node in a MineMeld graph has the native capability of filtering (accept/discard) indicators based on attribute values. In my case the idea will be for the output node to discard all URL indicators received from this 'enriched graph' that are&amp;nbsp;classified as malware or phishing by PAN-DB because the URL-Filtering feature would be taking care of them already.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Sun, 03 Sep 2017 13:36:43 GMT</pubDate>
    <dc:creator>vedd3r</dc:creator>
    <dc:date>2017-09-03T13:36:43Z</dc:date>
    <item>
      <title>Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/143878#M97614</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you know something sample about integration with MISP (Malware Information share platform)???&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So another question is about scripts, can I launch a script into conifg a new prototype? If I've created a new prototype I set a url option...can I set the url option for script option????&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 17:02:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/143878#M97614</guid>
      <dc:creator>SantiBT</dc:creator>
      <dc:date>2017-02-20T17:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/144142#M97615</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56809"&gt;@SantiBT&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;about MISP integration, we are planning to add it in the short term. Would you be interested in a Miner for MISP or sending indicators to MISP ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 18:20:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/144142#M97615</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-02-21T18:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/144268#M97616</link>
      <description>&lt;P&gt;Hi Lmori!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, I'm interesting in a miner for MISP!!!! it will be a great idea!!!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you known that??????&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please, let me know if you need more info about this!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 08:26:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/144268#M97616</guid>
      <dc:creator>SantiBT</dc:creator>
      <dc:date>2017-02-22T08:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/144377#M97617</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56809"&gt;@SantiBT&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I am planning to start working on it in a couple of weeks, would you be interested in testing the beta ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 17:36:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/144377#M97617</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-02-22T17:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/144500#M97618</link>
      <description>&lt;P&gt;Of course! Tell me when and I'll check your mine!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2017 08:21:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/144500#M97618</guid>
      <dc:creator>SantiBT</dc:creator>
      <dc:date>2017-02-23T08:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/149616#M97619</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;maybe you already have some beta version for testing?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 09:37:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/149616#M97619</guid>
      <dc:creator>mateusz_o</dc:creator>
      <dc:date>2017-03-27T09:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/149627#M97620</link>
      <description>&lt;P&gt;Sorry, running late on this. First beta code should be available the week of April 10th (2017)&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 11:45:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/149627#M97620</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-03-27T11:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/172769#M97621</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I succeeded in using MISP extension in order to get data from a misp server...but now I cannot&amp;nbsp;&lt;/P&gt;&lt;P&gt;export data via output node.&lt;/P&gt;&lt;P&gt;My feed pass through a&amp;nbsp;&lt;A href="https://minemeld.be-secure.it/#/prototypes/stdlib/aggregatorDomain" target="_blank"&gt;stdlib.aggregatorDomain&lt;/A&gt;&amp;nbsp;and then I'm trying to have them available through a&amp;nbsp;&lt;A href="https://minemeld.be-secure.it/#/prototypes/stdlib/feedLCGreenWithValue" target="_blank"&gt;stdlib.feedLCGreenWithValue&lt;/A&gt;&amp;nbsp;output node.&lt;/P&gt;&lt;P&gt;No luck so far...on the output node I see non zero statistics&amp;nbsp;for&lt;/P&gt;&lt;P&gt;updated.queue, update.rx, withdraw.processed, withdraw.queued, withdraw.rx&lt;/P&gt;&lt;P&gt;while zero value for&lt;/P&gt;&lt;P&gt;checkpoint.* and removed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I try to connect to the&amp;nbsp;&lt;SPAN&gt;FEED BASE URL of the output node I get status 200 but a blank page.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm probably overlooking some important point...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sebastiano&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 07:51:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/172769#M97621</guid>
      <dc:creator>Sebastiano</dc:creator>
      <dc:date>2017-08-23T07:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/172855#M97622</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71589"&gt;@Sebastiano&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;could you check in the Miner LOGS which type of share level is applied to the indicators ?&lt;/P&gt;
&lt;P&gt;Go to the MISP Miner and click on LOGS, there you will see the extracted indicators. If you click on one of them you will see the full list of attributes assigned to the indicators and you will be able to check the share_level attribute.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 14:20:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/172855#M97622</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-08-23T14:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/173042#M97623</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&amp;nbsp;and thanks a lot for you answer.&lt;/P&gt;&lt;P&gt;I checked the log of the misp miner and I see share_level set to 'white' so I think those should be good 'candidates' for output.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;{&lt;BR /&gt;"_age_out": 4294967295000,&lt;BR /&gt;"confidence": 70,&lt;BR /&gt;"share_leve": "white",&lt;BR /&gt;"misp_event_tags": [&lt;/P&gt;&lt;P&gt;&amp;lt;snip&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using minemeld version 0.9.40&lt;/P&gt;&lt;P&gt;and minemeld-misp version 0.1b5&lt;/P&gt;&lt;P&gt;kind regars&lt;/P&gt;&lt;P&gt;Seba&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit....&lt;/P&gt;&lt;P&gt;Was a confidence problem...as my output node was a low confidence one... so confidence &amp;lt; 50...&lt;/P&gt;&lt;P&gt;Now it works like a charm...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 09:00:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/173042#M97623</guid>
      <dc:creator>Sebastiano</dc:creator>
      <dc:date>2017-08-24T09:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/173047#M97624</link>
      <description>&lt;P&gt;Is it possible to create one for sending indicators to MISP as well? Would be great if it can work both ways. Reason is that, MineMeld can take a lot of indicators from different sources, which some of them will create a lot of noise/false positives (IPv4 for example) and need to be 'curated' and 'enriched' before feeding it to other platforms such as SIEMs. So from my perspective MISP fits into that role of repository and enricher. Also, GOSINT from Cisco looks promising as well when it comes to data enricher.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 09:16:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/173047#M97624</guid>
      <dc:creator>vedd3r</dc:creator>
      <dc:date>2017-08-24T09:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/173069#M97625</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71673"&gt;@vedd3r&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MineMeld is modular enough to accomodate 'enrichement'. For instance you could create an aggregator sort of node that checks IPv4 against your threat intel source (i.e. Wildfire / AutoFocus) to attach 'enrichement attributes' to that indicator.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm planning, for instance, on creating an enrichement node for MineMeld that will attach the PAN-DB URL category value as an attribute to all URL indicators received by that node. Each node in a MineMeld graph has the native capability of filtering (accept/discard) indicators based on attribute values. In my case the idea will be for the output node to discard all URL indicators received from this 'enriched graph' that are&amp;nbsp;classified as malware or phishing by PAN-DB because the URL-Filtering feature would be taking care of them already.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 12:50:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/173069#M97625</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2017-08-24T12:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/174491#M97626</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71673"&gt;@vedd3r&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MineMeld is modular enough to accomodate 'enrichement'. For instance you could create an aggregator sort of node that checks IPv4 against your threat intel source (i.e. Wildfire / AutoFocus) to attach 'enrichement attributes' to that indicator.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm planning, for instance, on creating an enrichement node for MineMeld that will attach the PAN-DB URL category value as an attribute to all URL indicators received by that node. Each node in a MineMeld graph has the native capability of filtering (accept/discard) indicators based on attribute values. In my case the idea will be for the output node to discard all URL indicators received from this 'enriched graph' that are&amp;nbsp;classified as malware or phishing by PAN-DB because the URL-Filtering feature would be taking care of them already.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 03 Sep 2017 13:36:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/174491#M97626</guid>
      <dc:creator>vedd3r</dc:creator>
      <dc:date>2017-09-03T13:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/178923#M97627</link>
      <description>&lt;P&gt;I found error when activate "&lt;SPAN&gt;minemeld-misp&lt;/SPAN&gt;" extensions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please recommend me:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Collecting pymisp (from minemeld-misp==0.1b5)&lt;BR /&gt;/opt/minemeld/engine/0.9.42/local/lib/python2.7/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:318: SNIMissingWarning: An HTTPS request has been made, but the SNI (Subject Name Indication) extension to TLS is not available on this platform. This may cause the server to present an incorrect TLS certificate, which can cause validation failures. You can upgrade to a newer version of Python to solve this. For more information, see &lt;A href="https://urllib3.readthedocs.io/en/latest/security.html#snimissingwarning" target="_blank"&gt;https://urllib3.readthedocs.io/en/latest/security.html#snimissingwarning&lt;/A&gt;.&lt;BR /&gt; SNIMissingWarning&lt;BR /&gt;/opt/minemeld/engine/0.9.42/local/lib/python2.7/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:122: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. You can upgrade to a newer version of Python to solve this. For more information, see &lt;A href="https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning" target="_blank"&gt;https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning&lt;/A&gt;.&lt;BR /&gt; InsecurePlatformWarning&lt;BR /&gt; Retrying (Retry(total=4, connect=None, read=None, redirect=None)) after connection broken by 'ProtocolError('Connection aborted.', error(104, 'Connection reset by peer'))': /simple/pymisp/&lt;BR /&gt;/opt/minemeld/engine/0.9.42/local/lib/python2.7/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:122: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. You can upgrade to a newer version of Python to solve this. For more information, see &lt;A href="https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning" target="_blank"&gt;https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning&lt;/A&gt;.&lt;BR /&gt; InsecurePlatformWarning&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;see full log in attachments&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 10:10:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/178923#M97627</guid>
      <dc:creator>iThreatHunt</dc:creator>
      <dc:date>2017-09-27T10:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/185307#M97628</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;Do you have .yml file? My company block .git file from Server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/minemeld-misp" target="_blank"&gt;https://github.com/PaloAltoNetworks/minemeld-misp&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 10:05:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/185307#M97628</guid>
      <dc:creator>iThreatHunt</dc:creator>
      <dc:date>2017-11-03T10:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/186151#M97629</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67821"&gt;@iThreatHunt&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I have built a wheel file for it, you can download it and upload to MineMeld:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/minemeld-misp/releases/download/0.1b5/minemeld_misp-0.1b5-py2-none-any.whl" target="_blank"&gt;https://github.com/PaloAltoNetworks/minemeld-misp/releases/download/0.1b5/minemeld_misp-0.1b5-py2-none-any.whl&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 08:58:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/186151#M97629</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-11-09T08:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/186163#M97630</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you. But I activate API. I found message:&lt;/P&gt;
&lt;P&gt;Processing /opt/minemeld/local/library/minemeld_misp-0.1b5-py2-none-any.whl&lt;BR /&gt;Requirement already satisfied: minemeld-core==0.9.44 in /opt/minemeld/engine/0.9.44/lib/python2.7/site-packages (from -c /opt/minemeld/local/library/constraints.txt (line 31))&lt;BR /&gt;Collecting pymisp (from minemeld-misp==0.1b5)&lt;BR /&gt;/opt/minemeld/engine/0.9.44/local/lib/python2.7/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:318: SNIMissingWarning: An HTTPS request has been made, but the SNI (Subject Name Indication) extension to TLS is not available on this platform. This may cause the server to present an incorrect TLS certificate, which can cause validation failures. You can upgrade to a newer version of Python to solve this. For more information, see &lt;A href="https://urllib3.readthedocs.io/en/latest/security.html#snimissingwarning" target="_blank"&gt;https://urllib3.readthedocs.io/en/latest/security.html#snimissingwarning&lt;/A&gt;.&lt;BR /&gt; SNIMissingWarning&lt;BR /&gt;/opt/minemeld/engine/0.9.44/local/lib/python2.7/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:122: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. You can upgrade to a newer version of Python to solve this. For more information, see &lt;A href="https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning" target="_blank"&gt;https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning&lt;/A&gt;.&lt;BR /&gt; InsecurePlatformWarning&lt;BR /&gt; Retrying (Retry(total=4, connect=None, read=None, redirect=None)) after connection broken by 'ProtocolError('Connection aborted.', error(104, 'Connection reset by peer'))': /simple/pymisp/&lt;BR /&gt;/opt/minemeld/engine/0.9.44/local/lib/python2.7/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:122: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. You can upgrade to a newer version of Python to solve this. For more information, see &lt;A href="https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning" target="_blank"&gt;https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning&lt;/A&gt;.&lt;BR /&gt; InsecurePlatformWarning&lt;BR /&gt; Retrying (Retry(total=3, connect=None, read=None, redirect=None)) after connection broken by 'ProtocolError('Connection aborted.', error(104, 'Connection reset by peer'))': /simple/pymisp/&lt;BR /&gt;/opt/minemeld/engine/0.9.44/local/lib/python2.7/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:122: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. You can upgrade to a newer version of Python to solve this. For more information, see &lt;A href="https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning" target="_blank"&gt;https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning&lt;/A&gt;.&lt;BR /&gt; InsecurePlatformWarning&lt;BR /&gt; Retrying (Retry(total=2, connect=None, read=None, redirect=None)) after connection broken by 'ProtocolError('Connection aborted.', error(104, 'Connection reset by peer'))': /simple/pymisp/&lt;BR /&gt;/opt/minemeld/engine/0.9.44/local/lib/python2.7/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:122: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. You can upgrade to a newer version of Python to solve this. For more information, see &lt;A href="https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning" target="_blank"&gt;https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning&lt;/A&gt;.&lt;BR /&gt; InsecurePlatformWarning&lt;BR /&gt; Retrying (Retry(total=1, connect=None, read=None, redirect=None)) after connection broken by 'ProtocolError('Connection aborted.', error(104, 'Connection reset by peer'))': /simple/pymisp/&lt;BR /&gt;/opt/minemeld/engine/0.9.44/local/lib/python2.7/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:122: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. You can upgrade to a newer version of Python to solve this. For more information, see &lt;A href="https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning" target="_blank"&gt;https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning&lt;/A&gt;.&lt;BR /&gt; InsecurePlatformWarning&lt;BR /&gt; Retrying (Retry(total=0, connect=None, read=None, redirect=None)) after connection broken by 'ProtocolError('Connection aborted.', error(104, 'Connection reset by peer'))': /simple/pymisp/&lt;BR /&gt;/opt/minemeld/engine/0.9.44/local/lib/python2.7/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:122: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. You can upgrade to a newer version of Python to solve this. For more information, see &lt;A href="https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning" target="_blank"&gt;https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning&lt;/A&gt;.&lt;BR /&gt; InsecurePlatformWarning&lt;BR /&gt; Could not find a version that satisfies the requirement pymisp (from minemeld-misp==0.1b5) (from versions: )&lt;BR /&gt;No matching distribution found for pymisp (from minemeld-misp==0.1b5)&lt;BR /&gt;/opt/minemeld/engine/0.9.44/local/lib/python2.7/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:122: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. You can upgrade to a newer version of Python to solve this. For more information, see &lt;A href="https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning" target="_blank"&gt;https://urllib3.readthedocs.io/en/latest/security.html#insecureplatformwarning&lt;/A&gt;.&lt;BR /&gt; InsecurePlatformWarning&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 09:16:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/186163#M97630</guid>
      <dc:creator>iThreatHunt</dc:creator>
      <dc:date>2017-11-09T09:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/186823#M97631</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67821"&gt;@iThreatHunt&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;are you restricting access from the VM to Internet ? It seems that python pip library is not being to reach out to the package servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 05:28:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/186823#M97631</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-11-14T05:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/186827#M97632</link>
      <description>&lt;P&gt;Yes, I allow access to Internet by a URL for MM Server. Could you recommend me for URL list that must allow it?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 07:02:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/186827#M97632</guid>
      <dc:creator>iThreatHunt</dc:creator>
      <dc:date>2017-11-14T07:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: Integrate with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/195461#M97633</link>
      <description>&lt;H2&gt;SSL Warnings&lt;/H2&gt;
&lt;P&gt;urllib3 will issue several different warnings based on the level of certificate verification support. These warning indicate particular situations and can resolved in different ways.&lt;/P&gt;
&lt;UL class="simple"&gt;
&lt;LI&gt;
&lt;DL class="first docutils"&gt;
&lt;DT&gt;&lt;A class="reference internal" title="urllib3.exceptions.InsecureRequestWarning" href="https://urllib3.readthedocs.io/en/latest/reference/index.html#urllib3.exceptions.InsecureRequestWarning" target="_blank"&gt;&lt;CODE class="xref py py-class docutils literal"&gt;&lt;SPAN class="pre"&gt;InsecureRequestWarning&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/A&gt;&lt;/DT&gt;
&lt;DD&gt;This happens when an request is made to an HTTPS URL without certificate verification enabled. Follow the &lt;A class="reference internal" href="https://urllib3.readthedocs.io/en/latest/user-guide.html#ssl" target="_blank"&gt;&lt;SPAN class="std std-ref"&gt;certificate verification&lt;/SPAN&gt;&lt;/A&gt; guide to resolve this warning.&lt;/DD&gt;
&lt;/DL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DL class="first docutils"&gt;
&lt;DT&gt;&lt;A class="reference internal" title="urllib3.exceptions.InsecurePlatformWarning" href="https://urllib3.readthedocs.io/en/latest/reference/index.html#urllib3.exceptions.InsecurePlatformWarning" target="_blank"&gt;&lt;CODE class="xref py py-class docutils literal"&gt;&lt;SPAN class="pre"&gt;InsecurePlatformWarning&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/A&gt;&lt;/DT&gt;
&lt;DD&gt;This happens on Python 2 platforms that have an outdated &lt;A class="reference external" title="(in Python v3.5)" href="https://docs.python.org/3.5/library/ssl.html#module-ssl" target="_blank"&gt;&lt;CODE class="xref py py-mod docutils literal"&gt;&lt;SPAN class="pre"&gt;ssl&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/A&gt; module. These older &lt;A class="reference external" title="(in Python v3.5)" href="https://docs.python.org/3.5/library/ssl.html#module-ssl" target="_blank"&gt;&lt;CODE class="xref py py-mod docutils literal"&gt;&lt;SPAN class="pre"&gt;ssl&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/A&gt; modules can cause some insecure requests to succeed where they should fail and secure requests to fail where they should succeed. Follow the &lt;A class="reference internal" href="https://urllib3.readthedocs.io/en/latest/user-guide.html#ssl-py2" target="_blank"&gt;&lt;SPAN class="std std-ref"&gt;pyOpenSSL&lt;/SPAN&gt;&lt;/A&gt; guide to resolve this warning.&lt;/DD&gt;
&lt;/DL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL id="sni-warning" class="simple"&gt;
&lt;LI&gt;
&lt;DL class="first docutils"&gt;
&lt;DT&gt;&lt;A class="reference internal" title="urllib3.exceptions.SNIMissingWarning" href="https://urllib3.readthedocs.io/en/latest/reference/index.html#urllib3.exceptions.SNIMissingWarning" target="_blank"&gt;&lt;CODE class="xref py py-class docutils literal"&gt;&lt;SPAN class="pre"&gt;SNIMissingWarning&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/A&gt;&lt;/DT&gt;
&lt;DD&gt;This happens on Python 2 versions older than 2.7.9. These older versions lack &lt;A class="reference external" href="https://en.wikipedia.org/wiki/Server_Name_Indication" target="_blank"&gt;SNI&lt;/A&gt; support. This can cause servers to present a certificate that the client thinks is invalid. Follow the &lt;A class="reference internal" href="https://urllib3.readthedocs.io/en/latest/user-guide.html#ssl-py2" target="_blank"&gt;&lt;SPAN class="std std-ref"&gt;pyOpenSSL&lt;/SPAN&gt;&lt;/A&gt; guide to resolve this warning.&lt;/DD&gt;
&lt;/DL&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 17 Jan 2018 08:45:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrate-with-misp/m-p/195461#M97633</guid>
      <dc:creator>iThreatHunt</dc:creator>
      <dc:date>2018-01-17T08:45:50Z</dc:date>
    </item>
  </channel>
</rss>

