How do you integrate the Sandbox IOC feed into the MetaDefender Cloud Reputation Service?

Introduction

It is important to mention the 2-way integration between MetaDefender Aether and the MetaDefender Reputation service in the Cloud:

  1. MetaDefender Aether uses the Cloud Reputation API to perform OSINT Lookups for supported IOC types (hashes, IPs, domains and URLs). This represents Layer 1 of the full analysis pipeline, and the reputation checks greatly improve the efficacy of the overall analysis.
  2. MetaDefender Aether generates an IOC feed based on the public samples submitted to the filescan.io and metadefender.com Community sites. This IOC feed is continuously ingested into the internal database of the MetaDefender Reputation service to enrich the results of the Reputation API.

Processing Pipeline

The IOC processing pipeline includes the following steps:

  1. Filescan.io aggregates scan reports and calculates individual verdicts for the IOCs included in these scan reports. Note that filescan.io might also ingest Sandbox scan results from metadefender.com (public scan reports are shared between the two Community sites).
  2. The filescan.io backend creates a continuous IOC feed based on the summary of scan reports: https://www.filescan.io/feed/reports
  3. The MetaDefender Reputation service periodically ingests the IOC feed data from filescan.io. All IOCs with a valid verdict are saved to the Reputation database with all metadata that is included in the IOC feed. Each IOC is indexed separately in the database to allow efficient lookup operations.

Example API Responses

Hash lookup API response example including scan results from MetaDefender Aether:

Hash lookup
Copy

URL lookup API response example including MetaDefender Aether as a reputation provider:

JSON
Copy
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard