Posts

Showing posts with the label Cybersecurity

Osweep - Don't Simply Search Osint, Sweep It

Image
If you lot operate inward information technology security, therefore you lot most probable role OSINT to assistance you lot sympathise what it is that your SIEM alerted you lot on together with what everyone else inward the globe understands most it. More than probable you lot are using to a greater extent than than 1 OSINT service because most of the fourth dimension OSINT volition entirely render you lot amongst reports based on the final analysis of the IOC. For some, that's practiced enough. They do network together with electronic mail blocks, do novel rules for their IDS/IPS, update the content inward the SIEM, do novel alerts for monitors inward Google Alerts together with DomainTools, etc etc. For others, they deploy these same countermeasures based on provided reports from their third-party tools that the fellowship is paying THOUSANDS of dollars for. The work amongst both of these is that the analyst needs to dig a footling deeper (ex. FULLY deobfuscate a PowerShel...

Malice - Virustotal Wanna Move (Now Alongside 100% To A Greater Extent Than Hipster)

Image
Malice's mission is to live a costless opened upwards source version of VirusTotal that anyone tin give notice role at whatever scale from an independent researcher to a fortune 500 company. Try It Out DEMO: demo.malice.io username : malice password : ecilam Requirements Hardware 16GB disk space 4GB RAM Software Docker Getting Started (OSX) Install $ brew install maliceio/tap/malice Usage: malice [OPTIONS] COMMAND [arg...] Open Source Malware Analysis Framework Version: 0.3.11 Author: blacktop - <https://github.com/blacktop> Options: --debug, -D Enable debug trend [$MALICE_DEBUG] --help, -h demo assistance --version, -v impress the version Commands: scan Scan a file lookout Watch a folder lookup Look upwards a file hash elk Start an ELK docker container plugin List, Install or Remove Plugins assistance Shows a listing of commands or assistance for i ascendancy Run ...

Ghidra - Software Contrary Technology Scientific Discipline Framework

Image
Ghidra is a software reverse applied scientific discipline (SRE) framework created in addition to maintained past times the National Security Agency Research Directorate. This framework includes a suite of full-featured, high-end software analysis tools that enable users to analyze compiled code on a multifariousness of platforms including Windows, Mac OS, in addition to Linux. Capabilities include disassembly, assembly, decompilation, graphing, in addition to scripting, along alongside hundreds of other features. Ghidra supports a broad multifariousness of procedure teaching sets in addition to executable formats in addition to tin survive run inward both user-interactive in addition to automated modes. Users may also prepare their ain Ghidra plug-in components and/or scripts using Java or Python. In back upwardly of NSA's Cybersecurity mission, Ghidra was built to solve scaling in addition to teaming problems on complex SRE efforts, in addition to to furnish a customiza...

Hostintel - A Modular Python Application To Collect Tidings For Malicious Hosts

Image
This tool is used to collect diverse intelligence sources for hosts. Hostintel is written inwards a modular fashion together with thus novel tidings sources tin survive easily added. Hosts are identified past times FQDN host name, Domain, or IP address. This tool exclusively supports IPv4 at the moment. The output is inwards CSV format together with sent to STDOUT together with thus the information tin survive saved or piped into to a greater extent than or less other program. Since the output is inwards CSV format, spreadsheets such equally Excel or database systems volition easily survive able to import the data. I created a brusque introduction for this tool on YouTube: https://youtu.be/aYK0gILDA6w This industrial plant alongside Python v2, only it should also locomote alongside Python v3. If you lot detect it does non locomote alongside Python v3 delight post service an issue. Help Screen: $ python hostintel.py -h usage: hostintel.py [-h] [-a] [-d] [-v] [-p] [-s] [-c] [-t...

Fir - Fast Incident Response

Image
FIR (Fast Incident Response) is an cybersecurity incident management platform designed alongside agility together with speed inwards mind. It allows for slowly creation, tracking, together with reporting of cybersecurity incidents. FIR is for anyone needing to runway cybersecurity incidents (CSIRTs, CERTs, SOCs, etc.). It was tailored to suit our needs together with our team's habits, but nosotros lay a corking bargain of endeavor into making it every bit generic every bit possible earlier releasing it together with then that other teams around the Blue Planet may every bit good purpose it together with customize it every bit they catch fit. See the wiki for the user manual together with to a greater extent than screenshots ! Installation There are 2 ways to install FIR. If yous desire to accept it for a test-drive, simply follow the instructions for setting upwards a evolution environment inwards the Wiki. If yous similar it together with desire to laid it upwa...