Kaspersky Module
The Kaspersky module enables you to synchronize your DocIntel instance with your Kaspersky Threat Intelligence Feed. All the reports with their associated tags and structured data will be imported for you to use.
Please note that this module is not part of the open-source version and is installed as an external module. If you are interested in this module, please contact antoine@docintel.org.
Installation
To install the module, follow these steps:
- Copy the received public key to
$DOCINTEL_DATA/modules/public.pem
. - Download the archive and extract its contents.
- Copy the contents of the archive to
$DOCINTEL_DATA/modules/kaspersky
. - Copy the licence file to
$DOCINTEL_DATA/modules/kaspersky/licence.txt
. - Restart the application.
- Go to Ingestion > Collectors
- Click Install
- Select
kaspersky.apt-and-crimeware-intel-reports
orkaspersky.ics-intel-reports
in the collector dropdown. Refer to Collector for more information about how to configure a collector. - Click Install
- Enter your API username, password and path to the private certificate.
- Click save