Skip to content

sodejm/threat-intelligence-enrichment

v0.1.0PolyForm-Noncommercial-1.0.0

Read-only source-specific threat intelligence lookups with explicit privacy approval and bounded requests.

COPS Threat Intelligence Enrichment

Issue #29. This read-only library validates analyst-selected IPs, domains, URLs, SHA-256 hashes, certificate SHA-256 fingerprints, email addresses, and Azure application IDs. Each outbound request requires an Approval for the exact source and indicator digest. Paths and queries in URLs, email addresses, and application IDs also require allow_sensitive=True.

The current adapters query MISP attributes, TAXII 2.1 collection objects, and Microsoft Defender Threat Intelligence hosts for IPs and domains, and Microsoft Graph service principals for Azure application IDs. The service principal claim means only that the app ID was found in the tenant; it is not a threat verdict. The Graph read requires Application.Read.All, while Defender Threat Intelligence hosts require ThreatIntelligence.Read.All and the relevant Defender Threat Intelligence licenses. TAXII matches only exact simple STIX indicator patterns, including IPv6 addresses and certificate SHA-256 hashes, and marks a paginated response partial. MISP responses at the 1,000-row cap are partial. Claims retain source provenance and supplied confidence; a Microsoft host record is not a verdict.

The library imports the repository's cops.connectors SDK. Install from this repository or package that SDK explicitly with the plugin before standalone distribution. Configure MISP/TAXII origins from trusted operator settings; configuration is not accepted from analyzed data. Credentials are caller-provided and never written to results. Requests are TLS only, fixed route, no redirect, 10 seconds and 1 MiB per attempt, with at most three attempts. Positive cache defaults to one hour; negative cache defaults to five minutes. Cache entries are in memory and stale values are returned only for an explicit cache-only read.

Offline tests: PYTHONPATH=.:plugins/detection-hunting/threat-intelligence-enrichment python3 -m unittest discover -s plugins/detection-hunting/threat-intelligence-enrichment/tests. Live source permissions, licenses, retention, schema variants, and provider response semantics are unverified; use an authorized test tenant before relying on operational coverage.