
用于与 InQuest Labs API 交互的 Pythonic 接口和命令行工具。
一个用于与 InQuest Labs API 交互的 Pythonic 接口和命令行工具。请注意,与该 API 交互无需 API 密钥。但 API 密钥确实能提供延长回溯时间、解除速率限制以及下载可用样本的能力。用户可以通过 OAuth 登录来生成 API 密钥。登录完全免费。支持通过 LinkedIn、Twitter、Google 和 Github 进行身份验证。
可搜索的 API 文档,内含多语言代码片段:https://labs.inquest.net/docs/
OpenAPI (Swagger) 规范:https://app.swaggerhub.com/apis-docs/InQuest.net/InQuestLabs/1.0
安装 InQuest Labs API CLI 的推荐方式是使用 pipx。这会将包及其所有依赖安装到一个可轻松调用的隔离虚拟环境中。
pipx install inquestlabs
另一种方式,或者当你希望将 inquestlabs 作为库使用时,可以使用 pip 安装。
pip install inquestlabs
要查看可用的命令行工具和选项,请参阅 inquestlabs --help 的输出。输出大致如下:
InQuest Labs Command Line Driver
Usage:
inquestlabs [options] dfi list
inquestlabs [options] dfi details <sha256> [--attributes]
inquestlabs [options] dfi download <sha256> <path> [--encrypt]
inquestlabs [options] dfi attributes <sha256> [--filter=<filter>]
inquestlabs [options] dfi search (code|context|metadata|ocr) <keyword>
inquestlabs [options] dfi search (md5|sha1|sha256|sha512) <hash>
inquestlabs [options] dfi search (domain|email|filename|filepath|ip|registry|url|xmpid) <ioc>
inquestlabs [options] dfi sources
inquestlabs [options] dfi upload <path>
inquestlabs [options] iocdb list
inquestlabs [options] iocdb search <keyword>
inquestlabs [options] iocdb sources
inquestlabs [options] repdb list
inquestlabs [options] repdb search <keyword>
inquestlabs [options] repdb sources
inquestlabs [options] yara (b64re|base64re) <regex> [(--big-endian|--little-endian)]
inquestlabs [options] yara hexcase <instring>
inquestlabs [options] yara uint <instring> [--offset=<offset>] [--hex]
inquestlabs [options] yara widere <regex> [(--big-endian|--little-endian)]
inquestlabs [options] yara cidr <ipv4>
inquestlabs [options] lookup ip <ioc>
inquestlabs [options] lookup domain <ioc>
inquestlabs [options] report <ioc>
inquestlabs [options] stats
inquestlabs [options] setup <apikey>
inquestlabs [options] trystero list-days
inquestlabs [options] trystero list-samples <yyyy-mm-dd>
Options:
--attributes Include attributes with DFI record.
--api=<apikey> Specify an API key.
--big-endian Toggle big endian.
--config=<config> Configuration file with API key [default: ~/.iqlabskey].
--debug Docopt debugging.
--encrypt Zip sample with password 'infected' before downloading.
--filter=<filter> Filter by attributes type (domain, email, filename, filepath, ip, registry, url, xmpid)
-h --help Show this screen.
--hex Treat <instring> as hex bytes.
-l --limits Show remaining API credits and limit reset window.
--little-endian Toggle little endian.
--offset=<offset> Specify an offset other than 0 for the trigger.
--proxy=<proxy> Intermediate proxy
--timeout=<timeout> Maximum amount of time to wait for IOC report.
--verbose=<level> Verbosity level, outputs to stderr [default: 0].
--version Show version.
以下第三方项目与 InQuest Labs 集成:
欢迎联系我们或提交拉取请求,将你的项目列入其中。
绝大多数攻击(>90%)都是通过电子邮件传播的。“Trystero Project”是我们正在积极进行的一项实验的代号,旨在衡量两大邮件提供商 Google 和 Microsoft 针对真实世界新兴恶意软件的安全有效性。基本思路是这样的……我们每天获取真实世界威胁样本,并将其循环发送到两个最流行的云邮件提供商 Google 和 Microsoft。我们会监控哪些样本能进入收件箱,并随时间比较结果。你可以在 InQuest Labs: Trystero Project 阅读更多内容、查看图表、探索数据并比较结果。如果你想进一步探索测试语料库,请参阅以下两个命令行选项:
此命令列出我们运行 Trystero 项目的日期,以及每天收集的样本数量。请注意,first_record 表示最早的记录(2020-08-09)。