Skip to main content

corcli - Cortex CLI client

Cortex is a Powerful Observable Analysis and Active Response Engine. While it is usually used along with TheHive Project, why not using it on a daily basis in a CLI fashion.

corcli was built in Python for this specific purpose.

Demo


Documentation: https://0xfustang.github.io/corcli-docs/

Source Code: https://github.com/0xFustang/corcli


Features

Key features are:

  • Fast job submission: Submit one or multiple observables to Cortex with a different set of analysers
  • Bulk submission: Submit jobs to Cortex observables from a text file
  • Extract artifacts: Submit one or multiple job and display only the extracted artifacts
  • Download files: Download extracted files from the job artifacts
  • Use aliases for analysers: Map your own aliases to launch your favorite analysers
  • Multi instance config: Submit jobs to another Cortex instance

Installation

with pip

corcli is published as a Python package and can be installed with pip, ideally by using a virtual environment. Before installing corcli, install libmagic as explained in the installation doc.

Open up a terminal and install corcli with:

pip install corcli

using Docker

A docker image is available from the repository and comes with all dependencies pre-installed. Open up a terminal and pull the image with:

docker pull ghcr.io/0xfustang/corcli:1.1.0

License

GPLv3

Metadata

Release files for corcli 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for corcli 1.1.0
File Size Uploaded
corcli-1.1.0.tar.gz 20.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for corcli 1.1.0
File Interpreter ABI Platform
corcli-1.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 40.3 kB

Release files / corcli-1.1.0.tar.gz

Download URL corcli-1.1.0.tar.gz
Size 20.0 kB
Tags Source
SHA-256 checksum
How to use checksums
0688ad87874a9190cf3ba709a2cce5f24c0fe88cf76c4aa4531db0f23201b72c
BLAKE2b-256 checksum
How to use checksums
db39dec41d9db8ab52705563a6f6092e59283be8014d940e0cc9faaf3dea0368
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.11.4

Release files / corcli-1.1.0-py3-none-any.whl

Download URL corcli-1.1.0-py3-none-any.whl
Size 20.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c1f5098636dcde8900160c5f9c30774d80c370bf2c5f3d7856fd2b011c8809c6
BLAKE2b-256 checksum
How to use checksums
57d4c754023f8319160ca0736ebdc71dcb98bde9d4aa339602e26983728c3268
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.11.4

Release history Release notifications | RSS feed

This release

1.1.0 This release

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.0.7

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page