jordisk / TheHive2SigmaView external linksLinks
Python script to automatically create sigma rules from The hive observables
☆25Mar 17, 2019Updated 6 years ago
Alternatives and similar repositories for TheHive2Sigma
Users that are interested in TheHive2Sigma are comparing it to the libraries listed below
Sorting:
- Checks observables/ioc in TheHive/Cortex against the MISP warningslists☆14Dec 27, 2017Updated 8 years ago
- Exporting MISP event attributes to yara rules usable with Thor apt scanner☆24Mar 27, 2017Updated 8 years ago
- My logstash plugins. Filter: sig (for security detect -> IOC, sig, New value, Reference, link, frequence, ...). Output: alert created by …☆10Jul 26, 2019Updated 6 years ago
- ☆15Mar 13, 2018Updated 7 years ago
- A collection of Cortex Analyzers and Responders for TheHive/Cortex☆13Jan 29, 2020Updated 6 years ago
- This package allows for creating alerts in The Hive from emails retrieved from a Microsoft Exchange mailbox.☆12Jul 13, 2017Updated 8 years ago
- SACTI - Securely aggregate CTI sightings and report them on MISP☆14Oct 24, 2022Updated 3 years ago
- CyCAT.org taxonomies☆15May 22, 2021Updated 4 years ago
- A repository to share contributions related to TheHive Project☆22Sep 15, 2021Updated 4 years ago
- A Python library to help with some common threat hunting data analysis operations☆141Apr 23, 2023Updated 2 years ago
- Utilizing your Threat data from a MISP instance into CarbonBlack Response by exposing the data in the Threat Intelligence Feed.☆20May 25, 2022Updated 3 years ago
- Creating a Feed of MISP Events from ThreatFox (by abuse.ch)☆19Jun 2, 2021Updated 4 years ago
- Generate bulk YARA rules from YAML input☆22Feb 3, 2020Updated 6 years ago
- Web interface to IntelMQ☆10Sep 10, 2025Updated 5 months ago
- Build Automated Machine Images for MISP☆29Jun 9, 2023Updated 2 years ago
- SOC Workflow App helps Security Analysts and Threat Hunters explore suspicious events, look into raw events arriving at the Elastic Stack…☆94Aug 30, 2022Updated 3 years ago
- Threat Hunting with ELK Workshop (InfoSecWorld 2017)☆65Oct 31, 2017Updated 8 years ago
- Providing timelines based on OSINT Reports☆31Jun 21, 2023Updated 2 years ago
- ☆42Sep 16, 2022Updated 3 years ago
- IP ASN History to find ASN announcing an IP and the closest prefix announcing it at a specific date☆97Jan 8, 2026Updated last month
- pocket guide for core threat hunting concepts☆23May 6, 2020Updated 5 years ago
- MISP website (hugo-based)☆25Jan 15, 2026Updated 3 weeks ago
- Synapse: a Meta Alert Feeder for TheHive, a Security Incident Response Platform☆71Jul 28, 2023Updated 2 years ago
- You're busted!☆27Dec 16, 2019Updated 6 years ago
- Expert Investigation Guides☆51Mar 18, 2021Updated 4 years ago
- DFIR notebooks GCIH Gold project, paper☆12Apr 30, 2015Updated 10 years ago
- Technical add-on to ingest json formatted volatility memory analysis plugin outputs☆13May 21, 2018Updated 7 years ago
- Powershell Functions to interact with TheHive-Project☆11Jun 27, 2019Updated 6 years ago
- Modular IMAP proxy (including PyCIRCLeanMail and MISP forward modules)☆32Jul 13, 2018Updated 7 years ago
- S4A main repository. SaltStack states, install script and build scripts☆27Jan 14, 2026Updated last month
- ☆30Jul 11, 2018Updated 7 years ago
- CyCAT.org API back-end server including crawlers☆29Feb 4, 2023Updated 3 years ago
- Application for STIX v2.0 objects management and analysis☆27Nov 9, 2017Updated 8 years ago
- Create mmdb files to encode prefix lists.☆31Sep 25, 2024Updated last year
- A simple way of moving your Medium's bookmarks to Trello.☆11Feb 24, 2019Updated 6 years ago
- Exports MISP events to STIX and ingest into McAfee ESM☆15Feb 12, 2020Updated 6 years ago
- Automation script to download JSON MISP files from a SFTP server and import them via API to a MISP instance.☆15May 12, 2023Updated 2 years ago
- ☆12Apr 26, 2018Updated 7 years ago
- The CRATOS proxy API integrates with your MISP instance and allows to extract indicators that can be consumed by security components such…☆13Sep 21, 2025Updated 4 months ago