
InQuest Labs APIと対話するためのPythonらしいインターフェースとコマンドラインツール。
InQuest Labs API と対話するための Pythonic なインターフェースおよびコマンドラインツールです。この API との対話に API キーは不要であることに注意してください。API キーがあれば、ルックバック期間を延長し、レート制限を解除し、利用可能なサンプルをダウンロードできます。ユーザーは OAuth を介してサインインして API キーを生成できます。サインインは無料です。認証は LinkedIn、Twitter、Google、Github に対応しています。
検索可能な API ドキュメント(多言語スニペット付き): https://labs.inquest.net/docs/
OpenAPI (Swagger) 仕様: https://app.swaggerhub.com/apis-docs/InQuest.net/InQuestLabs/1.0
InQuest Labs API CLI をインストールするには、pipx を使用することをお勧めします。これにより、パッケージとすべての依存関係が分離された仮想環境にインストールされ、簡単に呼び出せます。
pipx install inquestlabs
または、inquestlabs をライブラリとして使用したい場合は、pip を使用してインストールできます。
pip install inquestlabs
利用可能なコマンドラインツールとオプションを確認するには、inquestlabs --help の出力を参照してください。次のようになります。
InQuest Labs Command Line Driver
Usage:
inquestlabs [options] dfi list
inquestlabs [options] dfi details <sha256> [--attributes]
inquestlabs [options] dfi download <sha256> <path> [--encrypt]
inquestlabs [options] dfi attributes <sha256> [--filter=<filter>]
inquestlabs [options] dfi search (code|context|metadata|ocr) <keyword>
inquestlabs [options] dfi search (md5|sha1|sha256|sha512) <hash>
inquestlabs [options] dfi search (domain|email|filename|filepath|ip|registry|url|xmpid) <ioc>
inquestlabs [options] dfi sources
inquestlabs [options] dfi upload <path>
inquestlabs [options] iocdb list
inquestlabs [options] iocdb search <keyword>
inquestlabs [options] iocdb sources
inquestlabs [options] repdb list
inquestlabs [options] repdb search <keyword>
inquestlabs [options] repdb sources
inquestlabs [options] yara (b64re|base64re) <regex> [(--big-endian|--little-endian)]
inquestlabs [options] yara hexcase <instring>
inquestlabs [options] yara uint <instring> [--offset=<offset>] [--hex]
inquestlabs [options] yara widere <regex> [(--big-endian|--little-endian)]
inquestlabs [options] yara cidr <ipv4>
inquestlabs [options] lookup ip <ioc>
inquestlabs [options] lookup domain <ioc>
inquestlabs [options] report <ioc>
inquestlabs [options] stats
inquestlabs [options] setup <apikey>
inquestlabs [options] trystero list-days
inquestlabs [options] trystero list-samples <yyyy-mm-dd>
Options:
--attributes Include attributes with DFI record.
--api=<apikey> Specify an API key.
--big-endian Toggle big endian.
--config=<config> Configuration file with API key [default: ~/.iqlabskey].
--debug Docopt debugging.
--encrypt Zip sample with password 'infected' before downloading.
--filter=<filter> Filter by attributes type (domain, email, filename, filepath, ip, registry, url, xmpid)
-h --help Show this screen.
--hex Treat <instring> as hex bytes.
-l --limits Show remaining API credits and limit reset window.
--little-endian Toggle little endian.
--offset=<offset> Specify an offset other than 0 for the trigger.
--proxy=<proxy> Intermediate proxy
--timeout=<timeout> Maximum amount of time to wait for IOC report.
--verbose=<level> Verbosity level, outputs to stderr [default: 0].
--version Show version.
以下のサードパーティプロジェクトが InQuest Labs と統合されています。
ご自身のプロジェクトを掲載したい場合は、ご連絡いただくか、プルリクエストを送信してください。
攻撃の大部分(90%以上)は電子メールを介して発生します。「Trystero Project」は、Google と Microsoft という2大メールプロバイダーの、実際に発生しつつある新興マルウェアに対するセキュリティ効果を測定するために、私たちが積極的に実施している実験のコードネームです。基本的なアイデアは次のとおりです...日々の実際の脅威を取得し、それを最も人気のある2つのクラウドメールプロバイダー、Google と Microsoft にループさせます。どのサンプルが受信トレイに到達するかを監視し、時間の経過とともに結果を比較します。詳細の閲覧、グラフの表示、データの探索、結果の比較は InQuest Labs: Trystero Project で行えます。テストコーパスをさらに詳しく調べたい場合は、次の2つのコマンドラインオプションを参照してください。
Trystero Project を実施した日付と、各日に収集されたサンプル数の一覧です。first_record は最も古い記録(2020-08-09)を示すことに注意してください。