corcli - Cortex CLI client
Cortex is a Powerful Observable Analysis and Active Response Engine. While it is usually used along with TheHive Project, why not using it on a daily basis in a CLI fashion.
corcli was built in Python for this specific purpose.
Documentation: https://0xfustang.github.io/corcli-docs/
Source Code: https://github.com/0xFustang/corcli
Features
Key features are:
- Fast job submission: Submit one or multiple observables to Cortex with a different set of analysers
- Bulk submission: Submit jobs to Cortex observables from a text file
- Extract artifacts: Submit one or multiple job and display only the extracted artifacts
- Download files: Download extracted files from the job artifacts
- Use aliases for analysers: Map your own aliases to launch your favorite analysers
- Multi instance config: Submit jobs to another Cortex instance
Installation
with pip
corcli is published as a Python package and can be installed with pip, ideally by using a virtual environment. Before installing corcli, install libmagic as explained in the installation doc.
Open up a terminal and install corcli with:
pip install corcli
using Docker
A docker image is available from the repository and comes with all dependencies pre-installed. Open up a terminal and pull the image with:
docker pull ghcr.io/0xfustang/corcli:1.1.0
License
GPLv3
Metadata
Release files for corcli 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| corcli-1.1.0.tar.gz | 20.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| corcli-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 40.3 kB
Release files / corcli-1.1.0.tar.gz
| Download URL | corcli-1.1.0.tar.gz |
|---|---|
| Size | 20.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0688ad87874a9190cf3ba709a2cce5f24c0fe88cf76c4aa4531db0f23201b72c
|
|
BLAKE2b-256 checksum How to use checksums |
db39dec41d9db8ab52705563a6f6092e59283be8014d940e0cc9faaf3dea0368
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.2 CPython/3.11.4
|
Release files / corcli-1.1.0-py3-none-any.whl
| Download URL | corcli-1.1.0-py3-none-any.whl |
|---|---|
| Size | 20.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c1f5098636dcde8900160c5f9c30774d80c370bf2c5f3d7856fd2b011c8809c6
|
|
BLAKE2b-256 checksum How to use checksums |
57d4c754023f8319160ca0736ebdc71dcb98bde9d4aa339602e26983728c3268
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.2 CPython/3.11.4
|