MISP API
- Watcher.common.misp.create_misp_tags(misp_api)
Create and verify MISP tags.
- Args:
misp_api: PyMISP API instance
- Returns:
list: Created/verified tags
- Watcher.common.misp.create_objects(obj, existing_values=None)
Create MISP Objects for any domain object (Site or DnsTwisted).
- Args:
obj: Domain object (Site or DnsTwisted) containing domain data existing_values: Optional set of (type, value) tuples to check for duplicates
- Returns:
list: MISP objects ready to be added/updated
- Watcher.common.misp.create_or_update_objects(misp_api, event, site, dry_run=False)
Create or update MISP objects for a given domain-bearing object (Site, LegitimateDomain, or DnsTwisted - including dangling-detection rows).
- Args:
misp_api: PyMISP API instance event: MISP Event object site: Domain-bearing object (identified via _get_domain_identifier) dry_run: If True, simulate the operation without making changes
- Returns:
tuple: (success, message)
- Watcher.common.misp.create_takeover_objects(dns_twisted, existing_values=None)
Create a MISP object for a subdomain-takeover (dangling DNS) finding. Kept separate from create_objects() (Site/LegitimateDomain) since a dangling-detection DnsTwisted row carries a different attribute set (CNAME target, provider, HTTP status).
- Args:
dns_twisted: DnsTwisted instance with a subdomain_takeover Alert existing_values: Optional set of (type, value) tuples to check for duplicates
- Returns:
list: MISP objects ready to be added/updated
- Watcher.common.misp.find_domain_object(misp_api, event, domain_name)
Find a domain object in a MISP event.
- Args:
misp_api: PyMISP API instance event: MISP Event object domain_name: Domain name to search for
- Returns:
tuple: (object_found, existing_object)