forked from xujun10110/es_email_intel
-
Notifications
You must be signed in to change notification settings - Fork 1
/
gen_wordcloud.py
128 lines (117 loc) · 1.56 KB
/
gen_wordcloud.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
from elasticsearch import Elasticsearch
from wordcloud import WordCloud, STOPWORDS
import common_functions
keywords = '''APT 28
APT 30
RAT
SEA
Zeus
Adobe
Angler
anonopsaudix2
APT 12
Axiom
Backoff
Badur
BlackPOS
brute force
Bugat
codoso
Cool EK
Cridex
cross team
cryptowall
CVE-2015-1635
Cyber Berkut
DD4BC
DDoS
Deep Panda
Dexter
DPRK
Dridex
Driveby
Duqu
Dyre
Equation Group
Feodor
Fiesta
FIN4
FlashPack
FlimKit
Gamarue
GhostSec
Heartbleed
ISIL
ISIS
LastPass
Lotus Blossom
Magnitude
Malum
MalumPOS
MS15-034
Neutrino
Newscaster
Nitlove
Nuclear
obfuscat
Ocean Lotus
OPM
password guess
Phishing
Poodle
PoS
Poweliks
Ransomware
Sakula
Sakura
Sandworm
Shell Crew
ShellShock
SQLi
SQLMap
Styx
Sweet Orange
Syrian Electronic Army
TESLACYRPT
Titan Rain
Upatre
vawtrak
vSkimmer
'''
keywords_list = keywords.split('\n')
es_server = '192.168.3.208'
es = Elasticsearch([{'host': es_server, 'port': 9200}])
es_collection_name = 'mail2json'
def gen_wordcloud():
then = common_functions.queryrange(1)
body = '''{
"size" : 10000,
"query": {
"constant_score": {
"filter": {
"range": {
"epoch": {
"from": '''+then+'''
}
}
}
}
}
}'''
text = common_functions.pull_mailtext_24hrs(es, es_collection_name, body, keywords_list).lower()
print text
print
wc = WordCloud(background_color="white", max_words=40)
fileloc = "/home/pierre/es_email_intel/wordcloud.png"
try:
wc.generate(text)
wc.to_file(fileloc)
print 'Finished!'
return
except:
target = open(fileloc, 'w')
target.truncate()
target.close()
print 'Except!'
return
gen_wordcloud()