tools. Different tools, koen.vanimpe@cudeso.be
139misp2sentinel. MISP to Sentinel integration
81OPML-Security-Feeds. A list of OPML Security Feeds
80misp-tip-of-the-week. A collection of tips for using MISP.
77proof-value-cti. Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.
54cudeso-honeypot. Honeypot repo
48ulogd-viz. Visualisation of ulogd / ufw / iptables data
39dfir-iris-misp-timesketch. Scripts to integrate DFIR-IRIS, MISP and TimeSketch
37security-tools. Security tools, scanners, exploit code
31CSIRT-Jump-Bag. CSIRT Jump Bag
27host-enrich. Enrich a host with open source security information
27misp-scraper. A web scraper to create MISP events and reports
20misp-training-environment. Setting up a training environment for MISP
12misp-reporting. A package to create HTML MISP reports, including volume of trending events and attributes, evens received from key organisations and target sector and country.
12misp-usergroups. MISP User Groups
11elastic-dfir-cluster. Elastic cluster for DFIR
10security-screening. Security screening scripts
9censys-certif-crawl. Crawl certificate information from censys
8spiderfoot. SpiderFoot, the open source footprinting and intelligence-gathering tool.
8ics-csirt-website. Website of https://www.ics-csirt.io/
7misp_to_zeek. Export MISP indicators to Zeek intel framework
7mispbot. A simple tool to allow users to interact with MISP via Mastodon or Twitter.
5SoD-Matrix. The Segregation (or separation) of Duties (SoD) Matrix for CSIRTs, LEA and Judiciary
4tweetsniff. Grab a Twitter user timeline for further processing (storing to Elasticsearch, highligthing, etc)
4rsit-attck. Link RSIT with ATT&CK
4digital-footprint-light. digital-footprint-light
3ics-csirt. Resources for ICS-CSIRT
3Applied-Crypto-Hardening. Paper (DRAFT) on Best Current Practices regarding the configuration of cyptographic tools and online communication
3plantendb. Plantendatabase in Google Sheets
2lookyloo. Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other.
2cocktailparty. CocktailParty is a data broker system based on phoenix framework
2misp-modules. Modules for expansion services, import and export in MISP
2PyOTI. Python library for threat intelligence
1MISP-tools. Import CrowdStrike Threat Intelligence into your instance of MISP
1Hunting-Queries-Detection-Rules. KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
1Log4jCenter. Exploiting CVE-2021-44228 in vCenter for remote code execution and more.
1jupyter-collection. Collection of Jupyter Notebooks by @fr0gger_
1sectemplates. Open source templates you can use to bootstrap your security programs
1misp-basic-cicd. HCL
1misp-to-sentinel. Azure function to insert MISP data in to Azure Sentinel
1awesome-chatgpt-prompts. This repo includes ChatGPT prompt curation to use ChatGPT better.
1IntelArchitectureMap. Intelligence Architecture Mind Map
1ransomwatch. a ransomware-group observatory 🧅👹
1TIBER-Cases. TIBER-Cases is a project created to give cases of The Hive platform for Threat Intelligence Analysts mainly. All the cases are mapped to TIBER-EU processes.
1process_lifecycle. List of Incident Response and Threat Intelligence Processes and Lifecycles
1intelmq-demo-web. intelmq-demo-web
1PyMISP-docker. Docker images for PyMISP
1domain-propagation. Domain propagation on blocklist test
1http-screenshot. http-screenshot NSE script for nmap
1MOSP-models. Models for MONARC Objects Sharing Platform
1