PyMISP
MISP-tools
PyMISP | MISP-tools | |
---|---|---|
3 | 2 | |
422 | 32 | |
1.7% | - | |
9.2 | 6.0 | |
2 days ago | 7 days ago | |
Python | Python | |
GNU General Public License v3.0 or later | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
PyMISP
- FLaNK Stack Weekly for 13 November 2023
-
Get CrowdSec IOCs feed into MISP
You might consider misp feed https://github.com/MISP/PyMISP/tree/main/examples/feed-generator, basically itβs the best way to collect IOCs and import them into a MISP instance. These feeds help to correlate IOCs without manually launching the MISP module every time for each IOC, this also reduce the workload on your API servers as the list is cached locally on the MISP and updated every day.
-
Ingesting IOCs in to CS from MISP
If you're in Python, you can use PyMISP to login and get the new indicators, and then FalconPy to import them into your CrowdStrike tenant. (Basically the reverse of what the MISP-tools example is doing. You could start here and alter the logic.)
MISP-tools
-
Ingesting IOCs in to CS from MISP
I'd start with intel_client.py (most CS interactions happen here) and indicators.py (the logic for the handling of indicators, a lot of this is PyMISP-specific but it will help you identify data elements you want to bring over).
What are some alternatives?
MISP-QRadar-Integration - The Project can be used to integrate QRadar with MISP Threat Sharing Platform
falconpy - The CrowdStrike Falcon SDK for Python
yeti - Your Everyday Threat Intelligence
threatbus - π Threat Bus β A threat intelligence dissemination layer for open-source security tools.
vimGPT - Browse the web with GPT-4V and Vimium
falcon-query-assets - Welcome to the Falcon Query Assets GitHub page.
clipea - ππ’ Like Clippy but for the CLI. A blazing fast AI helper for your command line
PaK-Stocks - Stocks
livegrep - Interactively grep source code. Source for http://livegrep.com/
draw-a-ui - Draw a mockup and generate html for it
raft - RAFT contains fundamental widely-used algorithms and primitives for machine learning and information retrieval. The algorithms are CUDA-accelerated and form building blocks for more easily writing high performance applications.
inshellisense - IDE style command line auto complete