Minemeld List or Miner for a static list of IPs/URLs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Minemeld List or Miner for a static list of IPs/URLs

L2 Linker

Creating this post based on another thread. In a previous post's comment section, @spssspss asked "Is it possible to create a white list from an IPs address file?" and Luigi requested a new post be created for this functionality.. 

 

Can a list of IPs or URLs be hosted on MineMeld without the content actually being pulled from an external source?

 

Thanks!

-Chris

 

 

1 accepted solution

Accepted Solutions

L5 Sessionator

Hi @chmotley,

 

Yes. MineMeld can host indicators in a local database. The first approach was documented in Uploading list of indicators to MineMeld and supported by yaml files. Newer approach is based in a sqlite db, with an embeded aging engine and exposed via API. Implementation details in Using MineMeld as an Incident Response Platform

 

In summary, you need to add a "localDB" miner and upload the indicators to it using the script at https://gist.github.com/jtschichold/95f3906566b18b50cf2e3e1a44f1e785

View solution in original post

2 REPLIES 2

L5 Sessionator

Hi @chmotley,

 

Yes. MineMeld can host indicators in a local database. The first approach was documented in Uploading list of indicators to MineMeld and supported by yaml files. Newer approach is based in a sqlite db, with an embeded aging engine and exposed via API. Implementation details in Using MineMeld as an Incident Response Platform

 

In summary, you need to add a "localDB" miner and upload the indicators to it using the script at https://gist.github.com/jtschichold/95f3906566b18b50cf2e3e1a44f1e785

Thanks, Xavi!

 

I've added an FR (8269) to enable text-list functionality inside of MineMeld without the scripting requirements. Please feel free to review and vote!

  • 1 accepted solution
  • 7135 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!