mirror of
https://github.com/mvt-project/mvt.git
synced 2026-10-02 22:16:58 +02:00
Test w-prefixed subdomain indicator matching
Add test for URL matching with prefixed subdomain.
This commit is contained in:
1 parent
3bb652f2d2
commit
df3b130ca8
1 file changed
+28
@@ -311,3 +311,31 @@ class TestIndicators:
|
||||
ind = Indicators(log=logging)
|
||||
ind.load_indicators_files([], load_default=False)
|
||||
assert ind.total_ioc_count == 9
|
||||
|
||||
def test_check_url_matches_w_prefixed_subdomain(self, tmp_path):
|
||||
import json
|
||||
|
||||
stix_file = tmp_path / "w-domain.stix2"
|
||||
stix_file.write_text(
|
||||
json.dumps(
|
||||
{
|
||||
"objects": [
|
||||
{
|
||||
"type": "indicator",
|
||||
"pattern": "[domain-name:value = 'web.evil.com']",
|
||||
}
|
||||
]
|
||||
}
|
||||
),
|
||||
encoding="utf-8",
|
||||
)
|
||||
ind = Indicators(log=logging)
|
||||
ind.load_indicators_files([str(stix_file)], load_default=False)
|
||||
|
||||
for url in (
|
||||
"https://web.evil.com/path",
|
||||
"https://www.web.evil.com/path",
|
||||
):
|
||||
match = ind.check_url(url)
|
||||
assert match is not None
|
||||
assert match.ioc.value == "web.evil.com"
|
||||
Reference in new issue
Block a user