This is your work, valued

Brugge, Belgium

Koen Van Impe

Expert
@cudeso

tools. Different tools, koen.vanimpe@cudeso.be

139

misp2sentinel. MISP to Sentinel integration

81

OPML-Security-Feeds. A list of OPML Security Feeds

80

misp-tip-of-the-week. A collection of tips for using MISP.

77

proof-value-cti. Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.

54

cudeso-honeypot. Honeypot repo

48

ulogd-viz. Visualisation of ulogd / ufw / iptables data

39

dfir-iris-misp-timesketch. Scripts to integrate DFIR-IRIS, MISP and TimeSketch

37

security-tools. Security tools, scanners, exploit code

31

CSIRT-Jump-Bag. CSIRT Jump Bag

27

host-enrich. Enrich a host with open source security information

27

misp-scraper. A web scraper to create MISP events and reports

20

misp-training-environment. Setting up a training environment for MISP

12

misp-reporting. A package to create HTML MISP reports, including volume of trending events and attributes, evens received from key organisations and target sector and country.

12

misp-usergroups. MISP User Groups

11

elastic-dfir-cluster. Elastic cluster for DFIR

10

security-screening. Security screening scripts

9

censys-certif-crawl. Crawl certificate information from censys

8

spiderfoot. SpiderFoot, the open source footprinting and intelligence-gathering tool.

8

ics-csirt-website. Website of https://www.ics-csirt.io/

7

misp_to_zeek. Export MISP indicators to Zeek intel framework

7

mispbot. A simple tool to allow users to interact with MISP via Mastodon or Twitter.

5

SoD-Matrix. The Segregation (or separation) of Duties (SoD) Matrix for CSIRTs, LEA and Judiciary

4

tweetsniff. Grab a Twitter user timeline for further processing (storing to Elasticsearch, highligthing, etc)

4

rsit-attck. Link RSIT with ATT&CK

4

digital-footprint-light. digital-footprint-light

3

ics-csirt. Resources for ICS-CSIRT

3

Applied-Crypto-Hardening. Paper (DRAFT) on Best Current Practices regarding the configuration of cyptographic tools and online communication

3

plantendb. Plantendatabase in Google Sheets

2

lookyloo. Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other.

2

cocktailparty. CocktailParty is a data broker system based on phoenix framework

2

misp-modules. Modules for expansion services, import and export in MISP

2

PyOTI. Python library for threat intelligence

1

MISP-tools. Import CrowdStrike Threat Intelligence into your instance of MISP

1

Hunting-Queries-Detection-Rules. KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

1

Log4jCenter. Exploiting CVE-2021-44228 in vCenter for remote code execution and more.

1

jupyter-collection. Collection of Jupyter Notebooks by @fr0gger_

1

sectemplates. Open source templates you can use to bootstrap your security programs

1

misp-basic-cicd. HCL

1

misp-to-sentinel. Azure function to insert MISP data in to Azure Sentinel

1

awesome-chatgpt-prompts. This repo includes ChatGPT prompt curation to use ChatGPT better.

1

IntelArchitectureMap. Intelligence Architecture Mind Map

1

ransomwatch. a ransomware-group observatory 🧅👹

1

TIBER-Cases. TIBER-Cases is a project created to give cases of The Hive platform for Threat Intelligence Analysts mainly. All the cases are mapped to TIBER-EU processes.

1

process_lifecycle. List of Incident Response and Threat Intelligence Processes and Lifecycles

1

intelmq-demo-web. intelmq-demo-web

1

PyMISP-docker. Docker images for PyMISP

1

domain-propagation. Domain propagation on blocklist test

1

http-screenshot. http-screenshot NSE script for nmap

1

MOSP-models. Models for MONARC Objects Sharing Platform

1