Skip to content

Commit c0123c9

Browse files
committed
threat_intelligence.py: dont format the flow ts before setting evidence
1 parent 90761ca commit c0123c9

File tree

1 file changed

+11
-11
lines changed

1 file changed

+11
-11
lines changed

modules/threat_intelligence/threat_intelligence.py

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -216,7 +216,7 @@ def set_evidence_malicious_asn(
216216
profile=ProfileID(ip=saddr),
217217
timewindow=TimeWindow(number=twid_int),
218218
uid=[uid],
219-
timestamp=utils.convert_ts_format(timestamp, utils.alerts_format),
219+
timestamp=timestamp,
220220
)
221221

222222
self.db.set_evidence(evidence)
@@ -236,7 +236,7 @@ def set_evidence_malicious_asn(
236236
profile=ProfileID(ip=daddr),
237237
timewindow=TimeWindow(number=twid_int),
238238
uid=[uid],
239-
timestamp=utils.convert_ts_format(timestamp, utils.alerts_format),
239+
timestamp=timestamp,
240240
)
241241

242242
self.db.set_evidence(evidence)
@@ -314,7 +314,7 @@ def set_evidence_malicious_ip_in_dns_response(
314314
profile=ProfileID(ip=ip),
315315
timewindow=TimeWindow(number=twid_int),
316316
uid=[uid],
317-
timestamp=utils.convert_ts_format(timestamp, utils.alerts_format),
317+
timestamp=timestamp,
318318
)
319319

320320
self.db.set_evidence(evidence)
@@ -337,7 +337,7 @@ def set_evidence_malicious_ip_in_dns_response(
337337
profile=ProfileID(ip=saddr),
338338
timewindow=TimeWindow(number=twid_int),
339339
uid=[uid],
340-
timestamp=utils.convert_ts_format(timestamp, utils.alerts_format),
340+
timestamp=timestamp,
341341
)
342342

343343
self.db.set_evidence(evidence)
@@ -407,7 +407,7 @@ def set_evidence_conn_from_malicious_ip(
407407
profile=ProfileID(ip=saddr),
408408
timewindow=TimeWindow(number=twid_int),
409409
uid=[uid],
410-
timestamp=utils.convert_ts_format(timestamp, utils.alerts_format),
410+
timestamp=timestamp,
411411
)
412412
self.db.set_evidence(evidence)
413413
# mark this ip as malicious in our database
@@ -457,7 +457,7 @@ def set_evidence_conn_to_malicious_ip(
457457
profile=ProfileID(ip=daddr),
458458
timewindow=TimeWindow(number=twid_int),
459459
uid=[uid],
460-
timestamp=utils.convert_ts_format(timestamp, utils.alerts_format),
460+
timestamp=timestamp,
461461
)
462462
self.db.set_evidence(evidence)
463463

@@ -477,7 +477,7 @@ def set_evidence_conn_to_malicious_ip(
477477
profile=ProfileID(ip=saddr),
478478
timewindow=TimeWindow(number=twid_int),
479479
uid=[uid],
480-
timestamp=utils.convert_ts_format(timestamp, utils.alerts_format),
480+
timestamp=timestamp,
481481
)
482482
self.db.set_evidence(evidence)
483483
# mark this ip as malicious in our database
@@ -571,7 +571,7 @@ def set_evidence_malicious_domain(
571571
profile=ProfileID(ip=srcip),
572572
timewindow=TimeWindow(number=twid_number),
573573
uid=[uid],
574-
timestamp=utils.convert_ts_format(timestamp, utils.alerts_format),
574+
timestamp=timestamp,
575575
)
576576

577577
self.db.set_evidence(evidence)
@@ -1589,7 +1589,7 @@ def set_evidence_malicious_cname_in_dns_response(
15891589
profile=ProfileID(ip=srcip),
15901590
timewindow=TimeWindow(number=int(twid.replace("timewindow", ""))),
15911591
uid=[uid],
1592-
timestamp=utils.convert_ts_format(timestamp, utils.alerts_format),
1592+
timestamp=timestamp,
15931593
)
15941594

15951595
self.db.set_evidence(evidence)
@@ -1868,7 +1868,7 @@ def is_dns_answer_of_a_malicious_query(
18681868
profile=ProfileID(ip=answer),
18691869
timewindow=TimeWindow(number=int(twid.replace("timewindow", ""))),
18701870
uid=[uid],
1871-
timestamp=utils.convert_ts_format(timestamp, utils.alerts_format),
1871+
timestamp=timestamp,
18721872
)
18731873

18741874
self.db.set_evidence(evidence)
@@ -1884,7 +1884,7 @@ def is_dns_answer_of_a_malicious_query(
18841884
profile=ProfileID(ip=srcip),
18851885
timewindow=TimeWindow(number=int(twid.replace("timewindow", ""))),
18861886
uid=[uid],
1887-
timestamp=utils.convert_ts_format(timestamp, utils.alerts_format),
1887+
timestamp=timestamp,
18881888
)
18891889
self.db.set_evidence(evidence)
18901890

0 commit comments

Comments
 (0)