PaloAltoNetworks / minemeld
Main MineMeld documentation repo
☆378Updated 7 years ago
Alternatives and similar repositories for minemeld:
Users that are interested in minemeld are comparing it to the libraries listed below
- Engine of MineMeld☆141Updated 2 years ago
- Documentation of Cortex☆173Updated last year
- Documentation of TheHive☆395Updated last year
- ☆213Updated last year
- Prototypes for MineMeld nodes☆39Updated 3 years ago
- Automated deployment scripts for the RockNSM network hunting distribution.☆450Updated last year
- Python API Client for TheHive☆220Updated last week
- A threat hunting / data analysis environment based on Python, Pandas, PySpark and Jupyter Notebook.☆241Updated 3 years ago
- CrowdStrike Falcon Orchestrator provides automated workflow and response capabilities☆186Updated last year
- Threat Feed Aggregation, Made Easy☆167Updated 4 years ago
- Samples code that uses QRadar API's☆200Updated 4 years ago
- The Phishing Intelligence Engine - An Active Defense PowerShell Framework for Phishing Defense with Office 365☆180Updated 4 years ago
- TAXII server implementation in Python from EclecticIQ☆194Updated 10 months ago
- Mark Baggett's (@MarkBaggett - GSE #15, SANS SEC573 Author) tool for detecting randomness using NLP techniques rather than pure entropy c…☆125Updated 2 years ago
- Modules for expansion services, enrichment, import and export in MISP and other tools.☆353Updated this week
- MISP Docker (XME edition)☆283Updated last year
- Phantom Community Playbooks☆490Updated last month
- Cortex Analyzers Repository☆448Updated this week
- CIF v3 -- the fastest way to consume threat intelligence☆183Updated last year
- Automated Docker MISP container - Malware Information Sharing Platform and Threat Sharing☆175Updated 3 years ago
- File Scanning Framework☆291Updated 3 years ago
- Contains Logstash related content including tons of Logstash configurations☆253Updated 3 years ago
- CASCADE Server☆266Updated 2 years ago
- DEPRECATED - USE v3 (bearded-avenger)☆228Updated 7 years ago
- Graylog Processing Pipeline functions to enrich log messages with IoC information from threat intelligence databases☆153Updated last year
- Carbon Black API - Python language bindings☆145Updated 6 months ago
- User guide of MISP☆266Updated 2 months ago
- Useful network monitoring, analysis, and active response tools used or mentioned in the SANS SEC503 course (https://www.sans.org/course/i…☆221Updated 2 months ago
- DPS' Lightweight Investigation Notebook☆427Updated last year
- A Python library for parsing, manipulating, and generating STIX content.☆243Updated 3 years ago