def createIOC(md5, config_dict): items = [ ("contains", "Network", "Network/DNS", "string", config_dict["Domain"]), ("is", "PortItem", "PortItem/remotePort", "string", config_dict["Port"]), ("is", "ProcessItem", "ProcessItem/name", "string", config_dict["StartUp Name"]), ("is", "RegistryItem", "RegistryItem/Value", "string", config_dict["Registry Key"]), ] IOC = ioc.main(items) database.insertIOC(md5, IOC)
def createIOC(md5, dict): items = [] domain = dict["Domain"] items.append(("contains", "Network", "Network/DNS", "string", domain)) items.append( ("is", "PortItem", "PortItem/remotePort", "string", dict["Port"])) install = [("is", "ProcessItem", "ProcessItem/name", "string", dict["StartUp Name"]), ("is", "RegistryItem", "RegistryItem/Value", "string", dict["Registry Key"])] for x in install: items.append(x) IOC = ioc.main(items) database.insertIOC(md5, IOC)
def createIOC(md5, dict): items = [] domain = dict["Domain"] items.append(("contains", "Network", "Network/DNS", "string", domain)) items.append(("is", "PortItem", "PortItem/remotePort", "string", dict["Port"])) install = [ ("is", "ProcessItem", "ProcessItem/name", "string", dict["StartUp Name"]), ("is", "RegistryItem", "RegistryItem/Value", "string", dict["Registry Key"]) ] for x in install: items.append(x) IOC = ioc.main(items) database.insertIOC(md5, IOC)