fhightower / ioc-finderLinks
Simple, effective, and modular package for parsing observables (indicators of compromise (IOCs), network data, and other, security related information) from text. It uses grammars rather than regexes which makes it more readable, maintainable, and hackable. Explore our interactive documentation here: https://hightower.space/ioc-finder/
☆177Updated 2 years ago
Alternatives and similar repositories for ioc-finder
Users that are interested in ioc-finder are comparing it to the libraries listed below
Sorting:
- A python app to predict Att&ck tactics and techniques from cyber threat reports☆128Updated 2 years ago
- OASIS TC Open Repository: TAXII 2 Server Library Written in Python☆137Updated last year
- Threat Report ATT&CK™ Mapping (TRAM) is a tool to aid analyst in mapping finished reports to ATT&CK.☆354Updated 4 years ago
- Defanged Indicator of Compromise (IOC) Extractor.☆557Updated last year
- OASIS TC Open Repository: TAXII 2 Client Library Written in Python☆119Updated last year
- OASIS TC Open Repository: Lightweight visualization for STIX 2.0 objects and relationships☆157Updated 7 months ago
- Definition, description and relationship types of MISP objects☆104Updated last week
- A tool to extract structured cyber information from incident reports.☆82Updated 7 years ago
- A (nearly) production ready Dockered MISP☆231Updated last year
- Graphics, icons, and diagrams to support STIX 2☆47Updated 4 years ago
- Sigma rules from Joe Security☆226Updated last year
- Tools to interact with APTnotes reporting/index.☆107Updated 5 years ago
- OpenCTI Python Client☆144Updated last month
- OASIS TC Open Repository: Non-normative schemas and examples for STIX 2☆130Updated last month
- Mapping NSM rules to MITRE ATT&CK☆73Updated 5 years ago
- SIGMA UI is a free open-source application based on the Elastic stack and Sigma Converter (sigmac)☆189Updated 4 years ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆157Updated 9 months ago
- IOC from articles, tweets for archives☆319Updated 2 years ago
- Automated Docker MISP container - Malware Information Sharing Platform and Threat Sharing☆105Updated last year
- Modules for expansion services, enrichment, import and export in MISP and other tools.☆360Updated this week
- MISP Docker (XME edition)☆283Updated 2 years ago
- ☆175Updated last year
- STIX2 graph visualisation library in JS☆94Updated last month
- Tool to extract indicators of compromise from security reports in PDF format☆75Updated last year
- Sigma Detection Rule Repository☆91Updated 5 years ago
- TAXII server implementation in Python from EclecticIQ☆211Updated this week
- Cerebrate is an open-source platform meant to act as a trusted contact information provider and interconnection orchestrator for other se…☆91Updated last month
- This script scans the files extracted by Zeek with YARA rules located on the rules folder on a Linux based Zeek sensor, if there is a mat…☆62Updated 2 years ago
- The FASTEST way to consume threat intel.☆69Updated 2 years ago
- 🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.☆267Updated 2 years ago