fhightower / ioc-finderLinks
Simple, effective, and modular package for parsing observables (indicators of compromise (IOCs), network data, and other, security related information) from text. It uses grammars rather than regexes which makes it more readable, maintainable, and hackable. Explore our interactive documentation here: https://hightower.space/ioc-finder/
☆179Updated 2 years ago
Alternatives and similar repositories for ioc-finder
Users that are interested in ioc-finder are comparing it to the libraries listed below
Sorting:
- A python app to predict Att&ck tactics and techniques from cyber threat reports☆128Updated 2 years ago
- OASIS TC Open Repository: Lightweight visualization for STIX 2.0 objects and relationships☆161Updated last week
- OASIS TC Open Repository: TAXII 2 Client Library Written in Python☆120Updated last year
- A (nearly) production ready Dockered MISP☆230Updated 2 years ago
- Threat Report ATT&CK™ Mapping (TRAM) is a tool to aid analyst in mapping finished reports to ATT&CK.☆356Updated 4 years ago
- Sigma rules from Joe Security☆229Updated last year
- SIEGMA - Transform Sigma rules into SIEM consumables☆158Updated 10 months ago
- Definition, description and relationship types of MISP objects☆105Updated last week
- A tool to extract structured cyber information from incident reports.☆82Updated 7 years ago
- OASIS TC Open Repository: TAXII 2 Server Library Written in Python☆137Updated last year
- Graphics, icons, and diagrams to support STIX 2☆47Updated 4 years ago
- Defanged Indicator of Compromise (IOC) Extractor.☆558Updated last year
- Tools to interact with APTnotes reporting/index.☆108Updated 5 years ago
- Swagger/ OpenAPI specifications for security products and services☆77Updated last month
- Tool to extract indicators of compromise from security reports in PDF format☆75Updated last year
- OpenCTI Python Client☆143Updated 2 months ago
- A curated list of awesome things related to TheHive & Cortex☆183Updated 4 years ago
- Sigma Detection Rule Repository☆92Updated 5 years ago
- SIGMA UI is a free open-source application based on the Elastic stack and Sigma Converter (sigmac)☆189Updated 4 years ago
- Modules for expansion services, enrichment, import and export in MISP and other tools.☆361Updated last month
- OSSEM Detection Model☆182Updated 3 years ago
- Automated Docker MISP container - Malware Information Sharing Platform and Threat Sharing☆104Updated 2 years ago
- Mapping NSM rules to MITRE ATT&CK☆73Updated 5 years ago
- Python API Client for TheHive☆234Updated 2 months ago
- MISP Docker (XME edition)☆282Updated 2 years ago
- ☆175Updated last year
- Place for resources used during the Mordor Detection hackathon event featuring APT29 ATT&CK evals datasets☆145Updated 5 years ago
- STIX2 graph visualisation library in JS☆95Updated this week
- STIX 2.1 Visualizer, Attack and Activity Thread Graph for Threat Modeling☆33Updated last year
- OASIS Cyber Threat Intelligence (CTI) TC: A repository for commonly used STIX objects in order to avoid needless duplication. https://gi…☆98Updated 7 months ago