It seems to me like a case for classification vulnerable.potentially-unwanted-accessible - or do I understand something wrong in the Mikrotik world?
Best regards
// Kamil Mańkowski mankowski@cert.at - T: +43 676 898 298 7204 // CERT Austria - https://www.cert.at/ // CERT.at GmbH, FB-Nr. 561772k, HG Wien
On 9/10/26 22:56, elsif via IntelMQ-dev wrote:
Hello,
Below is the draft mapping for a new report. Please see the attached pdf for details as our web hosting provider is still having issues with the report pages.
Please let me know if you have any comments or suggestions.
Regards,
Jason
{ "constant_fields" : { "classification.identifier" : "open-mikrotik-service", "classification.taxonomy" : "other", "classification.type" : "other", "protocol.application" : "Mikrotik Service" }, "feed_name" : "Accessible-MikroTik", "file_name" : "scan_mikrotik_service", "optional_fields" : [ [ "severity", "severity", "validate_to_none" ], [ "protocol.transport", "protocol" ], [ "source.reverse_dns", "hostname" ], [ "extra.", "tag", "validate_to_none" ], [ "source.asn", "asn", "invalidate_zero" ], [ "source.geolocation.cc", "geo" ], [ "source.geolocation.region", "region" ], [ "source.geolocation.city", "city" ], [ "extra.source.naics", "naics", "invalidate_zero" ], [ "extra.", "hostname_source", "validate_to_none" ], [ "extra.source.sector", "sector", "validate_to_none" ], [ "extra.", "version", "validate_to_none" ], [ "extra.", "data_2000", "validate_to_none" ], [ "extra.", "data_winbox", "validate_to_none" ], [ "product.vulnerabilities", "tag", "extract_cve_from_tag" ] ], "required_fields" : [ [ "time.source", "timestamp", "add_UTC_to_timestamp" ], [ "source.ip", "ip", "validate_ip" ], [ "source.port", "port", "convert_int" ] ], "url" : "https://www.shadowserver.org/what-we-do/network-reporting/ accessible-mikrotik-service-report/" }
IntelMQ-dev mailing list -- intelmq-dev@lists.cert.at To unsubscribe send an email to intelmq-dev-leave@lists.cert.at