fhightower / ioc-finder
Simple, effective, and modular package for parsing observables (indicators of compromise (IOCs), network data, and other, security related information) from text. It uses grammars rather than regexes which makes it more readable, maintainable, and hackable. Explore our interactive documentation here: https://hightower.space/ioc-finder/
☆164Updated last year
Alternatives and similar repositories for ioc-finder:
Users that are interested in ioc-finder are comparing it to the libraries listed below
- Threat Report ATT&CK™ Mapping (TRAM) is a tool to aid analyst in mapping finished reports to ATT&CK.☆349Updated 3 years ago
- A python app to predict Att&ck tactics and techniques from cyber threat reports☆119Updated last year
- Definition, description and relationship types of MISP objects☆96Updated last week
- A (nearly) production ready Dockered MISP☆231Updated last year
- MISP Docker (XME edition)☆283Updated last year
- SIEGMA - Transform Sigma rules into SIEM consumables☆149Updated 2 weeks ago
- Tool to extract indicators of compromise from security reports in PDF format☆71Updated 9 months ago
- Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)☆100Updated 2 months ago
- ☆160Updated 4 years ago
- OASIS TC Open Repository: TAXII 2 Server Library Written in Python☆128Updated 11 months ago
- SIGMA UI is a free open-source application based on the Elastic stack and Sigma Converter (sigmac)☆186Updated 3 years ago
- A tool to extract structured cyber information from incident reports.☆80Updated 6 years ago
- Cerebrate is an open-source platform meant to act as a trusted contact information provider and interconnection orchestrator for other se…☆85Updated 3 months ago
- Sigma rules from Joe Security☆207Updated 4 months ago
- OASIS TC Open Repository: TAXII 2 Client Library Written in Python☆113Updated 11 months ago
- OASIS TC Open Repository: Lightweight visualization for STIX 2.0 objects and relationships☆146Updated 3 months ago
- Automated Docker MISP container - Malware Information Sharing Platform and Threat Sharing☆105Updated last year
- OSSEM Detection Model☆177Updated 2 years ago
- Defanged Indicator of Compromise (IOC) Extractor.☆523Updated 6 months ago
- Sigma Detection Rule Repository☆87Updated 4 years ago
- A Splunk app to use MISP in background☆110Updated last week
- Swagger/ OpenAPI specifications for security products and services☆75Updated 3 weeks ago
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆53Updated this week
- Tools to interact with APTnotes reporting/index.☆100Updated 4 years ago
- Import specific data sources into the Sigma generic and open signature format.☆77Updated 2 years ago
- ☆125Updated last year
- ☆171Updated 8 months ago
- YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA☆101Updated 3 weeks ago
- Graphics, icons, and diagrams to support STIX 2☆46Updated 3 years ago
- Repository containing IOCs, CSV and MISP JSON from our blogs☆80Updated 3 years ago