fhightower / ioc-finderLinks
Simple, effective, and modular package for parsing observables (indicators of compromise (IOCs), network data, and other, security related information) from text. It uses grammars rather than regexes which makes it more readable, maintainable, and hackable. Explore our interactive documentation here: https://hightower.space/ioc-finder/
☆174Updated 2 years ago
Alternatives and similar repositories for ioc-finder
Users that are interested in ioc-finder are comparing it to the libraries listed below
Sorting:
- OASIS TC Open Repository: Lightweight visualization for STIX 2.0 objects and relationships☆157Updated 7 months ago
- A python app to predict Att&ck tactics and techniques from cyber threat reports☆126Updated 2 years ago
- Graphics, icons, and diagrams to support STIX 2☆47Updated 4 years ago
- Definition, description and relationship types of MISP objects☆103Updated last week
- A (nearly) production ready Dockered MISP☆231Updated last year
- OASIS TC Open Repository: TAXII 2 Server Library Written in Python☆136Updated last year
- Defanged Indicator of Compromise (IOC) Extractor.☆554Updated last year
- OASIS TC Open Repository: TAXII 2 Client Library Written in Python☆119Updated last year
- A tool to extract structured cyber information from incident reports.☆82Updated 7 years ago
- OASIS TC Open Repository: Non-normative schemas and examples for STIX 2☆130Updated 3 weeks ago
- Threat Report ATT&CK™ Mapping (TRAM) is a tool to aid analyst in mapping finished reports to ATT&CK.☆353Updated 4 years ago
- SIGMA UI is a free open-source application based on the Elastic stack and Sigma Converter (sigmac)☆189Updated 4 years ago
- Swagger/ OpenAPI specifications for security products and services☆77Updated last month
- Tool to extract indicators of compromise from security reports in PDF format☆74Updated last year
- MISP Docker (XME edition)☆283Updated last year
- Modules for expansion services, enrichment, import and export in MISP and other tools.☆361Updated last week
- SIEGMA - Transform Sigma rules into SIEM consumables☆157Updated 8 months ago
- Cerebrate is an open-source platform meant to act as a trusted contact information provider and interconnection orchestrator for other se…☆91Updated 2 weeks ago
- Sigma Detection Rule Repository☆91Updated 5 years ago
- Mapping NSM rules to MITRE ATT&CK☆72Updated 5 years ago
- Tools to interact with APTnotes reporting/index.☆106Updated 5 years ago
- Automated Docker MISP container - Malware Information Sharing Platform and Threat Sharing☆105Updated last year
- Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)☆103Updated 4 months ago
- Sigma rules from Joe Security☆225Updated last year
- Python API Client for TheHive☆234Updated this week
- Python library using the MISP Rest API☆475Updated last week
- OpenCTI Python Client☆144Updated 2 weeks ago
- A Splunk app to use MISP in background☆113Updated last month
- Fang and defang indicators of compromise. You can test this project in a GUI here: http://ioc-fanger.hightower.space .☆65Updated 2 years ago
- STIX2 graph visualisation library in JS☆92Updated 2 weeks ago