Skip to content

Feature Request: Payload UI for the GreedyBear web interface #1510

Description

@opbot-xd

Problem / What it aims to solve

At the moment, analysts can only interact with quarantined payloads (searching, filtering, and downloading) by querying the REST API directly. This creates friction for users who prefer interacting via a graphical interface.

Suggested approach

Add a dedicated payload browser to GreedyBear's existing web frontend. The UI should allow analysts to:

  • Search and filter payloads by hash, MIME type, source honeypot, etc.
  • View payload metadata.
  • Download the .vir quarantined samples directly from the browser (respecting the existing RBAC / threat_researcher group permissions).

Additional context

Note: Implementing this feature may require changes across multiple codebases (e.g., both GreedyBear and tpot-payload-server).

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions