Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Describe the change
This PR introduces a new scanner
ScanIqy
to target and extract network addresses from IQY (Internet Query) files which are used by Microsoft Excel. This scanner was developed as IQY files have been used to contact suspicious domains to download content. The following has been added to Strelka:ScanIqy
scanner, which attempts to extract URLs within IQY files.test_scan_iqy
, which is used to validate the IQY and Strelka IOC pipeline.In addition, bug fixes were implemented in this PR to fix preexisting issues with:
poetry
failed to install dependencies (unknown reason)ScanPcap
tests failed to verify (zeek
update)Describe testing procedures
Sample output
ScanIqy
output will look like the following:Checklist