<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using new MineMeld file hash indicators? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/127553#M99171</link>
    <description>&lt;P&gt;I see that new indicator types for&amp;nbsp;file hashes (&lt;SPAN&gt;MD5, SHA256, SHA1, SSDEEP)&lt;/SPAN&gt; were&amp;nbsp;added in MineMeld 0.9.26 this is awesome, but should those indicator types be selectable from the (&amp;nbsp;NODES&amp;nbsp;&amp;gt; ADD INDICATOR &amp;gt; TYPE ) drop down menu? &amp;nbsp;I don't see them listed so I'm just trying to figure out how to employ the use of these new indicator types. &amp;nbsp;I'm still very new to MineMeld so still getting familiar and testing it out so my apologies if this is off-base...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, does anyone know if we will be able to export AutoFocus file hashes into export lists to leverage them in MineMeld?&lt;/P&gt;</description>
    <pubDate>Fri, 18 Nov 2016 22:33:21 GMT</pubDate>
    <dc:creator>DrewDixon</dc:creator>
    <dc:date>2016-11-18T22:33:21Z</dc:date>
    <item>
      <title>Using new MineMeld file hash indicators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/127553#M99171</link>
      <description>&lt;P&gt;I see that new indicator types for&amp;nbsp;file hashes (&lt;SPAN&gt;MD5, SHA256, SHA1, SSDEEP)&lt;/SPAN&gt; were&amp;nbsp;added in MineMeld 0.9.26 this is awesome, but should those indicator types be selectable from the (&amp;nbsp;NODES&amp;nbsp;&amp;gt; ADD INDICATOR &amp;gt; TYPE ) drop down menu? &amp;nbsp;I don't see them listed so I'm just trying to figure out how to employ the use of these new indicator types. &amp;nbsp;I'm still very new to MineMeld so still getting familiar and testing it out so my apologies if this is off-base...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, does anyone know if we will be able to export AutoFocus file hashes into export lists to leverage them in MineMeld?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 22:33:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/127553#M99171</guid>
      <dc:creator>DrewDixon</dc:creator>
      <dc:date>2016-11-18T22:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Using new MineMeld file hash indicators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/127632#M99172</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45263"&gt;@DrewDixon﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;currently the only Miner producing hashes is the VirusTotal retrohunt Miner.&lt;/P&gt;
&lt;P&gt;Next release (0.9.30) will have better coverage for hashes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have suggestions for new feeds of hashes we should cover ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Sat, 19 Nov 2016 12:59:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/127632#M99172</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-11-19T12:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Using new MineMeld file hash indicators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/127833#M99173</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First I just wanted to say thanks for all the great work creating MineMeld and for your part in making it open source!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would you perhaps have any more info on the VirusTotal retrohunt Miner? &amp;nbsp;Does this pull *all* of the malicious file hashes from VirusTotal or some or how does that work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for asking on suggestions, I absolutely have a few:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.)&amp;nbsp;Team Cymru Malware hash registry would be a great one to have a miner available, it looks like they want open source uses/implementations to&amp;nbsp;reach out to them first like&amp;nbsp;they state here in this page (&lt;A href="http://www.team-cymru.org/MHR.html" target="_blank"&gt;http://www.team-cymru.org/MHR.html&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.) It would be *Phenomenal* if an update for AutoFocus subscribers (those of us that have an AutoFocus license) could export file hashes from AutoFocus into export lists to be used with MineMeld (in bulk, if possible, currently we can't add file hashes to export lists it seems..), I'm not sure how/if&amp;nbsp;Palo Alto Networks might feel about that but it certianly would be probably the most&amp;nbsp;epic known malware file hash feed! &amp;nbsp;Do you think this might be possible?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thoughts?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Drew&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2016 15:32:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/127833#M99173</guid>
      <dc:creator>DrewDixon</dc:creator>
      <dc:date>2016-11-21T15:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Using new MineMeld file hash indicators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/128231#M99174</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45263"&gt;@DrewDixon﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;VirusTotal retro hunt is a subscription based feature of VT where you can define Yara rules and be notified every time a new sample uploaded to VT matches one of those rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) I will look into this, thanks !&lt;/P&gt;
&lt;P&gt;2) about AutoFocus, a feed containing all the billions of hashes known to AF wouldn't be super useful. But&amp;nbsp;I see your point.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and please let us&amp;nbsp;know any suggestion you have,&lt;/P&gt;
&lt;P&gt;luigi&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 17:36:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/128231#M99174</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-11-22T17:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: Using new MineMeld file hash indicators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/171272#M99175</link>
      <description>&lt;P&gt;Luigi, i am on&amp;nbsp;&lt;SPAN&gt;VERSION: 0.9.40 (AF)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) is hashes includeded in the export miner ?&lt;/P&gt;
&lt;P&gt;2) is there a miner that i can use to add hashes from nodes-&amp;gt;add indicator.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i can only see a miner for virus total. please let me know .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2017 14:16:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/171272#M99175</guid>
      <dc:creator>Jerin</dc:creator>
      <dc:date>2017-08-11T14:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: Using new MineMeld file hash indicators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/171415#M99176</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50717"&gt;@Jerin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;1) hashes are exported by output nodes, which Miner are you using ? The autofocus.samplesMiner support hashes&lt;/P&gt;
&lt;P&gt;2) you will be able to do it in the next release (0.9.42)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2017 09:43:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/171415#M99176</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-08-14T09:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Using new MineMeld file hash indicators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/171506#M99177</link>
      <description>&lt;P&gt;Thanks Luigi .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;i am able to get hash from autofocus.samplesminer. wondering if "Export List Miner" support hash too?&lt;/P&gt;
&lt;P&gt;i see only &amp;nbsp;IPv4, URL, and domain indicators.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Jerin&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2017 17:00:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/171506#M99177</guid>
      <dc:creator>Jerin</dc:creator>
      <dc:date>2017-08-14T17:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: Using new MineMeld file hash indicators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/172828#M99178</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50717"&gt;@Jerin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;you can't add hashes to export list. Please, could you provide more details about your use case ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 12:48:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-new-minemeld-file-hash-indicators/m-p/172828#M99178</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-08-23T12:48:00Z</dc:date>
    </item>
  </channel>
</rss>

