OTX pulse enrichment helpers and indicator-match rule - #2043
Conversation
- Avoid literal "None" strings in FirstSeen/LastSeen alert context fields - Pass lut_name through factory functions and helpers to avoid redundant _find_greynoise_v3_lut_name calls per event Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add _GreyNoiseV3Base with shared ip_address/url methods and common __init__ logic, removing duplication between ScannerIntelligence and BusinessService classes. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
PR SummaryMedium Risk Overview Introduces a new standard rule Refactors severity comparison into Reviewed by Cursor Bugbot for commit 1f8da89. Bugbot is set up for automated code reviews on this repo. Configure here. |
| for match_data in enrichment.get(lut_name, {}).values(): | ||
| if hasattr(match_data, "get") and match_data.get("indicator_type"): | ||
| return lut_name | ||
| return None |
There was a problem hiding this comment.
LUT detection fails when all indicators have multiple matches
Medium Severity
_find_otx_lut_name only recognizes single-match enrichment entries (dicts) via hasattr(match_data, "get"). When an indicator appears in multiple OTX pulses, the enrichment stores a list of dicts for that indicator. Lists lack a get method, so the check silently skips them. If every indicator in the event has multiple pulse matches, the function returns None, causing get_otx_object to return None and the rule to miss the threat entirely. The rest of the code (_lookup, otx_severity zip logic) explicitly handles multi-match lists, confirming this scenario is intended to work.
Reviewed by Cursor Bugbot for commit a6b62c3. Configure here.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
There are 2 total unresolved issues (including 1 from previous review).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 0ffb30a. Configure here.


Summary
panther_otx_helpersglobal helper exposing the fullOTX.Pulsesschema (pulse metadata, indicator metadata, severity derivation, alert context).Standard.OTX.MaliciousIndicatorrule that matches enriched IOCs across IPs, domains, file hashes (MD5/SHA1/SHA256), and emails against the*_otxlookup table, with severity escalated when the matching pulse names an adversary or known malware family.queries/otx_queries/that group the per-indicator OTX pulse rows back into per-pulse rollups:Query.OTX.PulsesSummary— recent pulses with indicator-type breakdown (IP / domain / hash / URL / email / CVE).Query.OTX.HighImpactPulses— pulses with a named adversary or malware family, scored CRITICAL / HIGH.Testing
make test
THREAT-589 THREAT-590