stix2gen is a simple utility to generate STIX2 indicators file from a list of provided indicators.
You can install stix2gen with the following command:
$ pip3 install stix2gen
Generate a STIX2 by automatically detecting the indicators types:
$ cat domains.txt emails.txt | stix2gen --malware-name NewMalware
You can also optionally provide a description using --malware-desc
.
Pipe the output to save to a file:
$ cat domains.txt emails.txt | stix2gen --malware-name NewMalware > newmalware.stix2
Please note: certain types of indicators might be misclassified when run through stix2gen's automatic detection. This is for example the case with app IDs (such as Android package names), which will be otherwise automatically detected as a domain name. In order to process app IDs you should explicitly specify a separate file including those indicators:
$ cat domains.txt emails.txt | stix2gen --malware-name NewMalware --app-ids-file package_names.txt > newmalware.stix2