How do you integrate the Sandbox IOC feed into the MetaDefender Cloud Reputation service?

Introduction

It is important to mention the 2-way integration between MetaDefender Sandbox and the MetaDefender Reputation service in the Cloud:

  1. Sandbox uses the Cloud Reputation API to perform OSINT Lookups for supported IOC types (hashes, IPs, domains and URLs). This represents Layer 1 of the full analysis pipeline, and the reputation checks greatly improve the efficacy of the overall analysis.
  2. Sandbox generates an IOC feed based on the public samples submitted to the filescan.io and metadefender.com Community sites. This IOC feed is continuously ingested into the internal database of the MetaDefender Reputation service to enrich the results of the Reputation API.

Processing Pipeline

The IOC processing pipeline includes the following steps:

  1. Filescan.io aggregates scan reports and calculates individual verdicts for the IOCs included in these scan reports. Note that filescan.io might also ingest Sandbox scan results from metadefender.com (public scan reports are shared between the two Community sites).
  2. The filescan.io backend creates a continuous IOC feed based on the summary of scan reports: https://www.filescan.io/feed/reports
  3. The MetaDefender Reputation service periodically ingests the IOC feed data from filescan.io. All IOCs with a valid verdict are saved to the Reputation database with all metadata that is included in the IOC feed. Each IOC is indexed separately in the database to allow efficient lookup operations.

Example API Responses

Hash lookup API response example including scan results from MetaDefender Sandbox:

Hash lookup
Copy

URL lookup API response example including MetaDefender Sandbox as a reputation provider:

JSON
Copy
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard