e83017121a
This is a POC of usage of shuffle webhook as entry for a responder for thehive. I am going to add extra layer to it later but this may help others to create some quick responders. I see for example an use in things like EDR not yet supported by cortex but included in Shuffle.
Functions
The point of this folder is to make GCP Cloud functions able to run default WALKOFF apps.
How it works:
- Subsequent info is based on the appname in main
- stitcher.go deploys the config to the app part of the website
- stitcher.go deploys the cloud function based on baseline.py
- stitcher.go SHOULD deploy the app to dockerhub for onpremise usecases
How to fix an appfile (done in stitcher.go)
- Remove walkoff_app_sdk.app_base import
- Remove anything with name == "main" (runner)
Stitching order:
- Base imports
- Authorization
- class AppBase
- class
- Runner
Update may 2020:
Moved static_baseline to ./onprem/app_sdk because of license.