Sha256: 32d8eb6f179d05a685b464878673bd93158f992dc57b348228d484f1212807f9

Contents?: true

Size: 1.05 KB

Versions: 6

Compression:

Stored size: 1.05 KB

Contents

# frozen_string_literal: true

module Mihari
  module Analyzers
    class Crtsh < Base
      # @return [Boolean]
      attr_reader :exclude_expired

      #
      # @param [String] query
      # @param [Hash, nil] options
      # @param [Bool] exclude_expired
      #
      def initialize(query, options: nil, exclude_expired: true)
        super(query, options: options)

        @exclude_expired = exclude_expired
      end

      def artifacts
        results = search
        results.map do |result|
          values = result["name_value"].to_s.lines.map(&:chomp)
          values.map do |value|
            Artifact.new(data: value, source: source, metadata: result)
          end
        end.flatten
      end

      private

      #
      # @return [Mihari::Clients::Crtsh]
      #
      def client
        @client ||= Mihari::Clients::Crtsh.new
      end

      #
      # Search
      #
      # @return [Array<Hash>]
      #
      def search
        exclude = exclude_expired ? "expired" : nil
        client.search(query, exclude: exclude)
      end
    end
  end
end

Version data entries

6 entries across 6 versions & 1 rubygems

Version Path
mihari-5.4.2 lib/mihari/analyzers/crtsh.rb
mihari-5.4.1 lib/mihari/analyzers/crtsh.rb
mihari-5.4.0 lib/mihari/analyzers/crtsh.rb
mihari-5.3.2 lib/mihari/analyzers/crtsh.rb
mihari-5.3.1 lib/mihari/analyzers/crtsh.rb
mihari-5.3.0 lib/mihari/analyzers/crtsh.rb