ThreatHunting
MISP
Our great sponsors
ThreatHunting | MISP | |
---|---|---|
1 | 15 | |
295 | 3,776 | |
- | 3.0% | |
3.9 | 9.9 | |
18 days ago | 6 days ago | |
YARA | PHP | |
GNU General Public License v3.0 only | GNU Affero General Public License v3.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
ThreatHunting
MISP
-
Threat Intelligence at your org
Start out with this https://www.misp-project.org/ it's open source and is widely used.
- Stix2 import Errors on script install and ova import
- Що таке платформа MISP і як нею користуватися?
-
FortiGuard DNS Filtering fails us again
I wasn't able to find out a whole lot about digitalside by itself, other than their threat feed is one of the default feeds on misp-project, so I figure if they trust it, I can (reasonably) trust it.
- Knowledge base for CTI
- MISP – open-source threat intelligence and sharing platform
-
Basic External IP investigating?
One thing you can do is run the IPs through various (opensource) threat feeds to see if the IPs have been observed by others in the past. AlienVault OTX and MISP are two free options that you could utilize.
-
What are your favorite open-sources tools?
MISP
- Any free threat intel apis?
What are some alternatives?
opencti - Open Cyber Threat Intelligence Platform
crits - CRITs - Collaborative Research Into Threats
intelmq - IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
SplunkDashboards - Collection of Dashboards for Threat Hunting and more!
awesome-malware-analysis - Defund the Police.
Go-MISPFeedGenerator - Golang implementation of PyMISP-feedgenerator
cowrie - Cowrie SSH/Telnet Honeypot https://cowrie.readthedocs.io
MOSP - A collaborative platform for creating, editing and sharing JSON objects.
elasticsearch-mapper-attachments - Mapper Attachments Type plugin for Elasticsearch
signature-base - Signature base for my scanner tools
eml_analyzer - EML analyzer is an application to analyze the EML file
sysmon-config - Sysmon configuration file template with default high-quality event tracing