certsocietegenerale/FIR

Artifacts are not loading Automatically.

Obad94 opened this issue · 4 comments

I have been working with artifacts, earlier it was running perfectly and all the artifacts were loading automatically from the related files. but now after a few weeks, it's not loading automatically. I can only see the hashes of the uploaded files but no contents such as IP, URL, or email addresses are shown.
I have tried pdf, HTML, CSV, txt, and xlsx but nothing works.

Hi,

I may be wrong, but from my understanding uploaded files are not (and have never been) scanned for artifacts in them. Their hashes are calculated and added as artifact, but their content is not analyzed.

IP/URL/emails artifacts are calculated from the ticket description, comments or nuggets only.

Could you please check on the "earlier" tickets if the artifacts have been loaded because of some comment on the ticket ?

Ohh Yeah, Sorry for the inconvenience. I totally forgot the process flow. well, by the way, is there any possibility to add a new feature to analyze files that can help to extract information (IP, hashes, Emails, URLs) from the uploaded files?

Thank you for the quick response you are a savior.

Hummm ...to be honnest I am not sure this feature would be desirable : attached files are not supposed to contain evidence (Evidence should be added as comment or nugget instead). There is a risk of adding misleading/wrong artifacts.

Also, this feature would be very complex to implement, given the high number of files to support (from .msg/.eml to office & HTML documents...)

Got your point. Thank you for the information.