OpenDXL

Posted on
Thu Sep 05, 2019 7:09 am
AndyVirus offline
Posts: 257
Joined: Mar 18, 2014
Location: Newport Pagnell, UK

OpenDXL

I know this is a niche request and if it is more effort than it is worth then forget it but.... Would it be possible to add OpenDXL to your MQTT connector plugin (or a variant of the plugin)?
OpenDXL is a version of MQTT that is designed and provide by McAfee, primarily for security products so that all vendors can integrate with each other.
I already use DXL extensively in my day job via McAfee products and the idea to be able to integrate with Indigo has always been something i have wanted.

For example, threat detected = sonos speak hostname and action taken, if not blocked flash red light etc. .... If Malware sandbox has found something malicious, send pushover to my moble. etc. Possibilities are endless with the plugins in Indigo.

Im thinking that by putting bells and whistles on events that make things happen in the real world, greater attention can be achieved instead of ignoring splunk or emails.

https://github.com/opendxl
https://github.com/opendxl/opendxl-client-python

OpenDXL is certificate based authentication per fabric (distributed cluster of brokers).

An OpenDXL broker is provided also that does not require McAfee ePO to manage the brokers unlike the virtual machine DXL broker which I am running.

Does this look possible to achieve in the MQTT plugin?

Posted on
Thu Sep 05, 2019 7:55 am
FlyingDiver online
User avatar
Posts: 7213
Joined: Jun 07, 2014
Location: Southwest Florida, USA

Re: OpenDXL

Please create an enhancement issue for this at https://github.com/FlyingDiver/Indigo-MQTT/issues

I'll need to dig into the API docs a little more, but I think it'll be possible to do a new broker type that allows subscribing to OpenDXL topics. Not sure about the sending requests part yet.

joe (aka FlyingDiver)
my plugins: http://forums.indigodomo.com/viewforum.php?f=177

Posted on
Wed Sep 25, 2019 8:04 pm
FlyingDiver online
User avatar
Posts: 7213
Joined: Jun 07, 2014
Location: Southwest Florida, USA

Re: OpenDXL

For anyone interested in this technology, I've got a branch of the MQTT Connector plugin on GitHub that can connect to an OpenDXL broker (as well as MQTT). Need some real world testing before I release it.

joe (aka FlyingDiver)
my plugins: http://forums.indigodomo.com/viewforum.php?f=177

Page 1 of 1

Who is online

Users browsing this forum: No registered users and 6 guests