MalwareBazaar Response Integration via API

Purpose

This guide explains how to configure the MalwareBazaar (abuse.ch) Response integration in Logsign USO, so that an analyst (or an action rule) can look up malware sample information by hash, tag, or signature/family directly from a Logsign Incident. This is a read-only threat-intelligence lookup integration; it does not block or change state anywhere.

Prerequisites

  • An abuse.ch account with a MalwareBazaar Auth-Key. As of recent abuse.ch policy, an Auth-Key is required for API access even though MalwareBazaar's data itself is free to use; register at abuse.ch to obtain one.

Step 1: Obtain Your Auth-Key

  1. Register for (or log in to) an abuse.ch account.
  2. Generate an Auth-Key for API access from your abuse.ch account settings.

Step 2: Configure the Integration in Logsign USO

In Logsign USO, go to Settings > Integrations > Responses, search for MalwareBazaar, click Configure then +Device, and fill in:

FieldRequiredDescription
Device NameYesFree-text label identifying this MalwareBazaar device in Logsign.
Auth KeyYesYour abuse.ch Auth-Key from Step 1. Stored encrypted at rest.

Click Create to save the device.

Available Methods

  • query_malware — looks up a sample by hash. Arg: hash (required).
  • query_tag — looks up samples by tag. Arg: tag (required).
  • query_signature — looks up samples by malware signature/family name. Arg: signature (required).

Troubleshooting

SymptomLikely causeWhat to check
401/403 errorWrong or missing Auth Key.Confirm your abuse.ch Auth-Key is entered exactly and is still valid.
429 Too Many Requestsabuse.ch enforces rate limits on the Auth-Key tier.Reduce the frequency of automated lookups.
No results for a known-bad hashThe sample was not submitted to/indexed by MalwareBazaar (it only covers samples submitted to it, not a universal malware database).Cross-check against another threat-intel source; MalwareBazaar's coverage depends on community submissions.

Notes and Limits

  • This integration is read-only threat intelligence; it never blocks or changes state anywhere.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.