Skip to content

OTX pulse enrichment helpers and indicator-match rule - #2043

Merged
arielkr256 merged 16 commits into
developfrom
otx-enrichment-helpers
May 1, 2026
Merged

arielkr256 merged 16 commits into
developfrom
otx-enrichment-helpers

Conversation

@arielkr256

@arielkr256 arielkr256 commented May 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add panther_otx_helpers global helper exposing the full OTX.Pulses schema (pulse metadata, indicator metadata, severity derivation, alert context).
  • Add Standard.OTX.MaliciousIndicator rule that matches enriched IOCs across IPs, domains, file hashes (MD5/SHA1/SHA256), and emails against the *_otx lookup table, with severity escalated when the matching pulse names an adversary or known malware family.
  • Add two saved queries under queries/otx_queries/ that group the per-indicator OTX pulse rows back into per-pulse rollups:
    • Query.OTX.PulsesSummary — recent pulses with indicator-type breakdown (IP / domain / hash / URL / email / CVE).
    • Query.OTX.HighImpactPulses — pulses with a named adversary or malware family, scored CRITICAL / HIGH.

Testing

make test

THREAT-589 THREAT-590

arielkr256 and others added 12 commits March 9, 2026 11:34
- Avoid literal "None" strings in FirstSeen/LastSeen alert context fields
- Pass lut_name through factory functions and helpers to avoid redundant
  _find_greynoise_v3_lut_name calls per event

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add _GreyNoiseV3Base with shared ip_address/url methods and common
__init__ logic, removing duplication between ScannerIntelligence and
BusinessService classes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@arielkr256
arielkr256 requested a review from a team as a code owner May 1, 2026 14:49
@cursor

cursor Bot commented May 1, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Adds a new cross-logtype detection rule driven by OTX lookup-table enrichment and changes shared severity-comparison logic, which can impact alerting behavior and severity calculation across rules.

Overview
Adds AlienVault OTX pulse enrichment support via new panther_otx_helpers, including LUT auto-detection, parsed pulse/indicator accessors, severity derivation (otx_severity*), and alert-context builders.

Introduces a new standard rule Standard.OTX.MaliciousIndicator that matches enriched IOCs (IPs/domains/hashes/emails) in p_any_* fields and sets alert severity based on pulse metadata; adds two saved queries to summarize/highlight high-impact OTX pulses.

Refactors severity comparison into panther_base_helpers.severity_greater_than (re-exported from GreyNoise/OTX helpers for compatibility) and tweaks GreyNoise rule severity selection to handle None initial state; updates detection-coverage/index docs to include the new OTX rule.

Reviewed by Cursor Bugbot for commit 1f8da89. Bugbot is set up for automated code reviews on this repo. Configure here.

Comment thread rules/standard_rules/greynoise_malicious_ip.py
Comment thread global_helpers/panther_otx_helpers.py Outdated
for match_data in enrichment.get(lut_name, {}).values():
if hasattr(match_data, "get") and match_data.get("indicator_type"):
return lut_name
return None

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LUT detection fails when all indicators have multiple matches

Medium Severity

_find_otx_lut_name only recognizes single-match enrichment entries (dicts) via hasattr(match_data, "get"). When an indicator appears in multiple OTX pulses, the enrichment stores a list of dicts for that indicator. Lists lack a get method, so the check silently skips them. If every indicator in the event has multiple pulse matches, the function returns None, causing get_otx_object to return None and the rule to miss the threat entirely. The rest of the code (_lookup, otx_severity zip logic) explicitly handles multi-match lists, confirming this scenario is intended to work.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit a6b62c3. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 2 total unresolved issues (including 1 from previous review).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0ffb30a. Configure here.

Comment thread rules/standard_rules/otx_malicious_indicator.py
@arielkr256
arielkr256 added this pull request to the merge queue May 1, 2026
@arielkr256 arielkr256 added enhancement New feature or request rules Real-time log data detections queries Stored Queries that help to quickly investigate lookup_table LookUpTables provide enrichment for Rules labels May 1, 2026
Merged via the queue into develop with commit e59cf03 May 1, 2026
18 of 19 checks passed
@arielkr256
arielkr256 deleted the otx-enrichment-helpers branch May 1, 2026 16:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request lookup_table LookUpTables provide enrichment for Rules queries Stored Queries that help to quickly investigate rules Real-time log data detections

3 participants