{"id":13775741,"url":"https://github.com/ecrimelabs/securityonion-ecrimelabs","last_synced_at":"2025-05-11T08:33:12.993Z","repository":{"id":200722905,"uuid":"146977120","full_name":"eCrimeLabs/securityonion-ecrimelabs","owner":"eCrimeLabs","description":"Implementation of informaiton from MISP through the eCrimeLabs API and into SecurityOnion","archived":false,"fork":false,"pushed_at":"2018-09-11T18:05:51.000Z","size":23,"stargazers_count":7,"open_issues_count":0,"forks_count":2,"subscribers_count":4,"default_branch":"master","last_synced_at":"2024-11-17T10:40:16.200Z","etag":null,"topics":["ecrimelabs","misp","securityonion"],"latest_commit_sha":null,"homepage":null,"language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/eCrimeLabs.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2018-09-01T07:17:02.000Z","updated_at":"2023-12-22T19:43:19.000Z","dependencies_parsed_at":null,"dependency_job_id":"0b7ac478-f405-4528-ade1-ed79dae3d3fb","html_url":"https://github.com/eCrimeLabs/securityonion-ecrimelabs","commit_stats":null,"previous_names":["ecrimelabs/securityonion-ecrimelabs"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/eCrimeLabs%2Fsecurityonion-ecrimelabs","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/eCrimeLabs%2Fsecurityonion-ecrimelabs/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/eCrimeLabs%2Fsecurityonion-ecrimelabs/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/eCrimeLabs%2Fsecurityonion-ecrimelabs/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/eCrimeLabs","download_url":"https://codeload.github.com/eCrimeLabs/securityonion-ecrimelabs/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":253540257,"owners_count":21924519,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ecrimelabs","misp","securityonion"],"created_at":"2024-08-03T17:01:47.772Z","updated_at":"2025-05-11T08:33:12.717Z","avatar_url":"https://github.com/eCrimeLabs.png","language":"Shell","funding_links":[],"categories":["\u003ca id=\"6e80463404d46f0493cf6e84597e4b5c\"\u003e\u003c/a\u003e工具"],"sub_categories":["\u003ca id=\"e99ba5f3de02f68412b13ca718a0afb6\"\u003e\u003c/a\u003eTor\u0026\u0026\u0026Onion\u0026\u0026洋葱"],"readme":"# SecurityOnion-eCrimeLabs\nImplementation of information from MISP through the eCrimeLabs API and into SecurityOnion\n\n**Prerequisites:**\n\n- Security Onion (installed,configured)\n- eCrimeLabs Broker API access and API Key\n- Download and Configure (on Master or Standalone)\n\n**Clone the repo:**\n```\ngit clone https://github.com/eCrimeLabs/securityonion-ecrimelabs\n```\n\n**Run the setup script:**\n```\nsudo bash securityonion-ecrimelabs/setup-ecrimelabs\n```\n\n**Update rules (if desired):**\n```\n/usr/sbin/download-ecrimelabs\nsudo rule-update\n```\n\n**Confirm rules in place:**\n```\ncat /etc/nsm/rules/alert.ecrimelabs.rules\ncat /etc/nsm/rules/incident.ecrimelabs.rules\n```\n\n**Confirm Bro Intel in place:**\n```\ncat /opt/bro/share/bro/intel/ecrimelabs-intel.dat\n```\n\nA cron job will run every 2 hours to download new NIDS rules and Intel.\n\n------\n\nRemember to modify **ecrimelabscfg**\n\nThe setup will allways pull the incident feed, and here from it is up to the individual\nimplementation on what other feeds will be extracted.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fecrimelabs%2Fsecurityonion-ecrimelabs","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fecrimelabs%2Fsecurityonion-ecrimelabs","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fecrimelabs%2Fsecurityonion-ecrimelabs/lists"}