Best practices in threat intelligence
☆50Nov 6, 2022Updated 3 years ago
Alternatives and similar repositories for best-practices-in-threat-intelligence
Users that are interested in best-practices-in-threat-intelligence are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Azure function to insert MISP data in to Azure Sentinel☆33Oct 19, 2022Updated 3 years ago
- Telsy CTI Research Team☆57Dec 15, 2020Updated 5 years ago
- The Intelligent Process Lifecycle of Active Cyber Defenders☆34Jan 1, 2023Updated 3 years ago
- Splunk Add-on for PowerShell provides field extraction for PowerShell event logs.☆17Feb 1, 2021Updated 5 years ago
- An OpenTAXII Configuration for MISP☆88Sep 29, 2022Updated 3 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- A Passive DNS backend and collector☆33Jul 16, 2022Updated 4 years ago
- Set of Maltego transforms to inferface with a MISP Threat Sharing instance, and also to explore the whole MITRE ATT&CK dataset.☆186Jun 23, 2024Updated 2 years ago
- This repository is a curated list of pro bono incident response entities.☆21Jun 21, 2023Updated 3 years ago
- Build Automated Machine Images for MISP☆29Jun 9, 2023Updated 3 years ago
- Connect your mail client/infrastructure to MISP in order to create events based on the information contained within mails.☆70Nov 11, 2023Updated 2 years ago
- The Infosec Community Definitive Guide to Jupyter Notebooks☆134Oct 17, 2020Updated 5 years ago
- A completely unsupported set of scripts used in SANS FOR572, Advanced Network Forensics and Analysis☆30Aug 6, 2025Updated last year
- Specifications used in the MISP project including MISP core format☆55Aug 6, 2026Updated 3 weeks ago
- A simple ReST server to lookup threat actors (by name, synonym or UUID) and returning the corresponding MISP galaxy information about the…☆52Aug 30, 2025Updated 11 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Automated Docker MISP container - Malware Information Sharing Platform and Threat Sharing☆103Dec 29, 2023Updated 2 years ago
- Defanged Indicator of Compromise (IOC) Extractor.☆584Aug 28, 2024Updated 2 years ago
- Validate IOC from MISP ; Export results and iocs to SIEM and sensors using syslog and CEF format☆14Sep 13, 2016Updated 9 years ago
- Object-oriented programming language for writing smart contracts on all platforms. Built to work alongside BenchChain distributed virtua…☆11Apr 17, 2018Updated 8 years ago
- TAXII server implementation in Python from EclecticIQ☆214Mar 12, 2026Updated 5 months ago
- CIF v3 -- the fastest way to consume threat intelligence☆189Apr 20, 2023Updated 3 years ago
- a modified version base on Tracecorn☆20Oct 29, 2019Updated 6 years ago
- Threat hunting tool for scraping latest scrapes from Pastebin☆36Feb 17, 2021Updated 5 years ago
- Example configuration for tethering Adafruit FONA with Linux's PPP daemon.☆13Jun 7, 2016Updated 10 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- BlackBerry Threat Research & Intelligence☆100Oct 20, 2023Updated 2 years ago
- Static malware analysis using python☆12Jun 22, 2018Updated 8 years ago
- A collection of hunting and blue team scripts. Mostly others, some my own.☆38Jan 8, 2023Updated 3 years ago
- YETI (Your Everyday Threat Intelligence) Integration to Elastic Stack☆16Jan 6, 2021Updated 5 years ago
- Baseline organizational policies and practices☆10Apr 17, 2017Updated 9 years ago
- Golang-based subdomain miner leveraging certificate transparency logs☆74Aug 8, 2023Updated 3 years ago
- Collection of scripts for different malware analysis tasks☆77Jul 15, 2019Updated 7 years ago
- The Suspicious Email Submitter is a discontinued browser extension (Chrome, Chromium, Firefox) for the easy submission of suspicious emai…☆15Mar 6, 2023Updated 3 years ago
- A collection of scripts to look various things up in VERIS data such as VCDB.☆14Apr 27, 2017Updated 9 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- This repository contains all public indicators identified by 401trg during the course of our investigations. It also includes relevant ya…☆120Apr 14, 2021Updated 5 years ago
- go-atomicredteam is a Golang application to execute tests as defined in the atomics folder of Red Canary's Atomic Red Team project (https…☆48Mar 7, 2023Updated 3 years ago
- This repository provides tools to fight against Emotet malware. You can protect your system using these tools☆24Jan 24, 2020Updated 6 years ago
- Term concordances for each course in the SANS DFIR curriculum. Used for automated index generation.☆70Aug 7, 2020Updated 6 years ago
- Utilities that we use to make life easier☆12Jul 12, 2022Updated 4 years ago
- Automate bug bounty recon using bash alias☆15Aug 6, 2024Updated 2 years ago
- A python script to turn Ubuntu Desktop in a one stop security platform. The InfoSec Fortress installs the packages,tools, and resources t…☆53Jan 3, 2022Updated 4 years ago