nccgroup / ImpossibleTravelLogAnalysis
Basic log analysis tool to detect impossible travel via IP address geographic information
☆20Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for ImpossibleTravelLogAnalysis
- Python bindings for Yeti's API☆18Updated last year
- ☆11Updated 6 years ago
- Virustotal Data to Timesketch☆17Updated 5 years ago
- Yara Scanner For IMAP Feeds and saved Streams☆28Updated 5 years ago
- CIRCL system forensic tools or a jumble of tools to support forensic☆42Updated last year
- Setting up a training environment for MISP☆11Updated last year
- Repository for scripts and tips for "Yara Scan Service"☆20Updated last year
- ☆14Updated 6 years ago
- This module installs and configures MISP (Malware Information Sharing Platform)☆13Updated 2 months ago
- The ContactDB project was initiated to cover the need for a tool to maintain contacts for CSIRT teams☆37Updated 2 years ago
- An active domain name query tool to help keep track of domain name movements...☆15Updated 3 years ago
- ☆10Updated 8 years ago
- The FastIR Server is a Web server to schedule FastIR Collector forensics collect thanks to the FastIR Agent☆12Updated 7 years ago
- Git for me to put all my forensics stuff☆21Updated 2 months ago
- Indicators of compromise relating to our report on APT10's targeting of global MSPs☆10Updated 7 years ago
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆40Updated 4 years ago
- List CVEs and details that apply to your infrastructure (pre-inventoried).☆10Updated 3 years ago
- YETI (Your Everyday Threat Intelligence) Integration to Elastic Stack☆15Updated 3 years ago
- Check IOC provided by a MISP instance on Suricata events☆17Updated 5 years ago
- An extendable tool to extract and aggregate IoCs from threat feeds☆32Updated 9 months ago
- Scripts to help hunt for possible golden/silver TGT tickets☆16Updated 7 years ago
- Python script to automatically create sigma rules from The hive observables☆23Updated 5 years ago
- PowerShell Memory Pulling script☆19Updated 9 years ago
- Docker projects to retain beacon source IPs using C2 relaying infra☆11Updated 5 years ago
- Repository of Information sharing on threats and indicators☆12Updated 4 years ago
- ☆12Updated 5 years ago
- ☆29Updated 6 years ago
- ☆24Updated 2 years ago
- CyCAT.org taxonomies☆14Updated 3 years ago