corumir / Practical-Tradecraft
Resources, articles, thoughts, datasets, papers on TI tradecraft
☆11Updated 6 years ago
Alternatives and similar repositories for Practical-Tradecraft
Users that are interested in Practical-Tradecraft are comparing it to the libraries listed below
Sorting:
- Home to the ActorTrackr source code☆24Updated 7 years ago
- Python module to use the MISP Taxonomies☆29Updated last month
- CertWatcher is a new take on monitoring for phishing sites. It is meant to be a set and forget service that will send you a daily report …☆11Updated 4 years ago
- Home to the ActorTrackr source code☆29Updated 7 years ago
- ☆24Updated 2 years ago
- A collection of Python utilities for use in scripts related to working with "indicators of compromise" (IOCs).☆17Updated 6 years ago
- Python bindings for Yeti's API☆18Updated last year
- Sorta reverse implementation of ShoVAT - Also includes NMAP banner regex results☆17Updated 6 years ago
- This project contains code for comparing or ranking APT capabilities and operational capacity. The metrics are meant to quantify, rank, o…☆35Updated 6 years ago
- IntelMQ command line tool to process events and send out email notifications.☆9Updated this week
- Transforms for the AlienVault OTX service☆39Updated 8 years ago
- Maltego CaseFile entities for information security investigations, malware analysis and incident response☆65Updated 7 years ago
- repo for sharing stuff☆16Updated last year
- Providing timelines based on OSINT Reports☆32Updated last year
- Just another tool to extract Indicator of compromise (ioc) from files☆29Updated 9 years ago
- ☆18Updated 6 years ago
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆42Updated 4 years ago
- The ContactDB project was initiated to cover the need for a tool to maintain contacts for CSIRT teams☆37Updated 3 years ago
- open-source intelligence gathering for SIEMs <3☆38Updated 8 years ago
- An active domain name query tool to help keep track of domain name movements...☆15Updated 4 years ago
- dnssinkholelist is a python package focused on combining open source lists of malicious domains, dynamic dns domains, and advertisement d…☆18Updated 9 years ago
- My personal experience in Threat Hunting and knowledge gained so far.☆19Updated 7 years ago
- A curated lust of awesome cyber civil society actors, project etc.☆10Updated 4 years ago
- CyCAT.org taxonomies☆15Updated 3 years ago
- Useful scripts, rules etc. for use with YARA☆27Updated 4 years ago
- Passive DNS Common Output Format☆36Updated 8 months ago
- Threat Intel and Incident Reponse☆10Updated 6 years ago
- Performs OCR on image files and scans them for matches to YARA rules☆41Updated 6 years ago
- Virustotal Data to Timesketch☆17Updated 6 years ago
- Yara Scanner For IMAP Feeds and saved Streams☆28Updated 5 years ago