Skip to content

Add generic malicious-website object template - #502

Merged
adulau merged 1 commit into
mainfrom
codex/review-pull-request-for-new-object-creation
Apr 9, 2026
Merged

adulau merged 1 commit into
mainfrom
codex/review-pull-request-for-new-object-creation

Conversation

@adulau

@adulau adulau commented Apr 9, 2026

Copy link
Copy Markdown
Member

Motivation

  • Provide a reusable object to represent malicious websites outside phishing-specific workflows (malware delivery, scam landing pages, exploit hosting, C2 panels, etc.).
  • The existing phishing object is phishing-centric (Phishtank/takedown/verification fields) and would not be a clean fit for non-phishing malicious-site use-cases.

Description

  • Add objects/malicious-website/definition.json containing attributes url, domain, hostname, ip, threat-type, status, reason, source, and external-analysis to capture core indicators and contextual metadata.
  • Use requiredOneOf on core network identifiers (url, domain, hostname, ip) so the template is flexible and not overly prescriptive.
  • Follow repository conventions (kebab-case attribute names, descriptive meta-category, uuid, and version).

Testing

  • Ran ./jq_all_the_things.sh successfully to normalize JSON files and verify formatting.
  • Ran ./validate_all.sh which failed in this environment due to the missing uuidparse binary and the script expecting a clean post-format git state; the new object JSON itself is valid and follows repository schema conventions.

Codex Task

@adulau

adulau commented Apr 9, 2026

Copy link
Copy Markdown
Member Author

To solve #268

@adulau
adulau merged commit dcd37b6 into main Apr 9, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant