MISP / misp-galaxyLinks
Clusters and elements to attach to MISP events or attributes (like threat actors)
☆591Updated 3 weeks ago
Alternatives and similar repositories for misp-galaxy
Users that are interested in misp-galaxy are comparing it to the libraries listed below
Sorting:
- Indicators from Unit 42 Public Reports☆727Updated 3 months ago
- Extract and aggregate threat intelligence.☆885Updated last year
- Defanged Indicator of Compromise (IOC) Extractor.☆557Updated last year
- Python library using the MISP Rest API☆476Updated this week
- Repository of YARA rules made by Trellix ATR Team☆620Updated 8 months ago
- MISP trainings, threat intel and information sharing training materials with source code☆420Updated 6 months ago
- Tool to extract indicators of compromise from security reports in PDF format☆437Updated 2 years ago
- A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.☆385Updated 3 years ago
- Cortex Analyzers Repository☆470Updated 3 weeks ago
- A set of Zeek scripts to detect ATT&CK techniques.☆617Updated last year
- The Python SDK for AlienVault OTX☆392Updated last year
- Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups☆721Updated 2 years ago
- ReversingLabs YARA Rules☆879Updated last month
- YARA Rules I come across on the internet☆355Updated last year
- Threat Report ATT&CK™ Mapping (TRAM) is a tool to aid analyst in mapping finished reports to ATT&CK.☆353Updated 4 years ago
- Modules for expansion services, enrichment, import and export in MISP and other tools.☆361Updated last week
- Cyber Analytics Repository☆968Updated 6 months ago
- Online hash checker for Virustotal and other services☆837Updated 8 months ago
- OASIS TC Open Repository: Python APIs for STIX 2☆406Updated 7 months ago
- FireEye Publicly Shared Indicators of Compromise (IOCs)☆469Updated 6 years ago
- Python Script to access ATT&CK content available in STIX via a public TAXII server☆570Updated 11 months ago
- IOC from articles, tweets for archives☆319Updated last year
- DC3 Malware Configuration Parser (DC3-MWCP) is a framework for parsing configuration information from malware. The information extracted …☆339Updated 9 months ago
- User guide of MISP☆281Updated 11 months ago
- Actionable analytics designed to combat threats☆1,005Updated 3 years ago
- FAME Automates Malware Evaluation☆917Updated last month
- Sophos-originated indicators-of-compromise from published reports☆636Updated 3 months ago
- Yara Rule Analyzer and Statistics☆396Updated 2 years ago
- Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.☆290Updated 3 weeks ago
- Malware Configuration And Payload Extraction☆760Updated last year