sbidy / MacroMilter
This python based milter (mail-filter) checks an incoming mail for suspicious VBA macro code in MS 20xx Office attachments (doc, xls, ppt ...).
☆38Updated 3 years ago
Alternatives and similar repositories for MacroMilter:
Users that are interested in MacroMilter are comparing it to the libraries listed below
- Traceroute improved wrapper for CSIRT and CERT operators☆37Updated 5 months ago
- OSSEC Decoder & Rulesets for Sysmon Events☆15Updated 9 years ago
- Sysmon configuration file template with default high-quality event tracing☆11Updated 7 years ago
- The ContactDB project was initiated to cover the need for a tool to maintain contacts for CSIRT teams☆37Updated 3 years ago
- Generates visualizations from the output of flow tools such as SiLK.☆35Updated 8 years ago
- A Postfix filter which takes a piped message and submits it to Cuckoo Sandbox☆11Updated 8 years ago
- DocBleachShell is the integration of the great DocBleach, https://github.com/docbleach/DocBleach Content Disarm and Reconstruction tool i…☆21Updated 3 years ago
- API to use Cymru services☆27Updated 11 years ago
- CIRCL system forensic tools or a jumble of tools to support forensic☆42Updated 2 years ago
- Connect your mail client/infrastructure to MISP in order to create events based on the information contained within mails.☆69Updated last year
- Exporting MISP event attributes to yara rules usable with Thor apt scanner☆24Updated 7 years ago
- IntelMQ command line tool to process events and send out email notifications.☆9Updated this week
- Megatron - A System for Abuse- and Incident Handling☆44Updated 7 years ago
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆42Updated 4 years ago
- server for indexing and querying passive DNS observations☆45Updated last year
- Build Automated Machine Images for MISP☆28Updated last year
- An Ubuntu 16.04 build containing Suricata, PulledPork, Bro, and Splunk☆23Updated 6 years ago
- ☆12Updated 5 years ago
- Passive Network Audit Framework☆32Updated 6 years ago
- ☆14Updated 6 years ago
- Checks observables/ioc in TheHive/Cortex against the MISP warningslists☆14Updated 7 years ago
- Parse nmap scan data with Perl (official repo)☆36Updated 6 years ago
- FastIR Agent is a Windows service to execute FastIR Collector on demand☆14Updated 7 years ago
- OwlH Master API Web User Interface☆12Updated 10 months ago
- An active domain name query tool to help keep track of domain name movements...☆15Updated 3 years ago
- Unpack MIME attachments from a file and check them against virustotal.com☆45Updated 9 years ago
- Virustotal Data to Timesketch☆17Updated 6 years ago
- This repository contains all the config files and scripts used for our Open Source Endpoint monitoring project.☆34Updated 5 years ago
- ☆19Updated 6 years ago
- Integrating Sysinternals Autoruns’ logs into Security Onion☆31Updated last year