STIXProject / use-cases
☆13Updated 8 years ago
Alternatives and similar repositories for use-cases:
Users that are interested in use-cases are comparing it to the libraries listed below
- Presentation Slides and Video links☆32Updated 3 years ago
- Performs OCR on image files and scans them for matches to YARA rules☆40Updated 6 years ago
- Security Onion Elastic Stack☆46Updated 4 years ago
- Malware/IOC ingestion and processing engine☆104Updated 6 years ago
- A set of templates for documenting threat intelligence☆74Updated 11 years ago
- Expert Investigation Guides☆51Updated 3 years ago
- A python script to query the MITRE ATT&CK API for tactics, techniques, mitigations, & detection methods for specific threat groups.☆66Updated 6 years ago
- Generate ATT&CK Navigator layer file from PowerShell Empire agent logs☆49Updated 6 years ago
- A collection of typical false positive indicators☆55Updated 4 years ago
- Python tool and library to help analyze files during malware triage and analysis.☆78Updated 4 years ago
- SMTP server / sinkhole for collecting spam☆44Updated 6 years ago
- Sandbox feature upgrade with the help of wrapped samples☆76Updated 6 years ago
- Monitoring tool for PasteBin-alike sites written in Python. Inspired by pastemon http://github.com/xme/pastemon☆44Updated 4 years ago
- Some IR notes☆73Updated 8 years ago
- Python parser for Red Canary's Atomic Red Team Yamls☆27Updated 6 years ago
- Transforms for the AlienVault OTX service☆39Updated 8 years ago
- ☆50Updated 6 years ago
- Repository of yara rules☆59Updated 2 years ago
- Analysis of wifi probe request data☆11Updated 7 years ago
- threat-intelligence.eu website and repository of information about open standards, documents, methodologies and processes in threat intel…☆48Updated 2 years ago
- Modular tool to test exfiltration techniques.☆37Updated 7 years ago
- References for FIRST CTI 2019 Symposium presentation☆23Updated 5 years ago
- My personal experience in Threat Hunting and knowledge gained so far.☆19Updated 7 years ago
- Mitre Att&ck Technique Emulation☆82Updated 5 years ago
- A MITRE Caldera plugin written in Python 3 used to convert Red Canary Atomic Red Team Tests to MITRE Caldera Stockpile YAML ability files…☆71Updated 3 years ago
- Parse URLCrazy and dnstwist output and compare against previous runs to identify new typosquatted domains.☆51Updated 9 years ago
- Powershell collection designed to assist in Threat Hunting Windows systems.☆27Updated 6 years ago
- Various public documents, whitepapers and articles about APT campaigns☆54Updated 8 years ago
- PortPlow is a distributed port and system scanning & enumeration service. It enables the quick and automated enumeration of ports and ser…☆53Updated 3 months ago
- Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)☆98Updated last month