New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Disable malwaredomains threat intel feed #642
Comments
|
hey , can I work on this issue |
|
@san-coding thank you, we welcome help. You can reference this past PR for an example of removing MalwareDomains from rita-bl. I believe it just involves deleting two files.
Since the actual changes are fairly straightforward we'd ask that you test them as well. I think the following tests plus anything else you think of:
If you need some sample Zeek logs let us know. |
|
Thanks, I do need some sample week logs |
This feed is no longer available and the default config should be changed to disable it until it is fully removed from rita-bl.
rita/etc/rita.yaml
Line 111 in 4a4b639
rita/config/static.go
Line 78 in 4a4b639
activecm/rita-bl#10
The text was updated successfully, but these errors were encountered: