Skip to main content

Tools to search network data logs for threat feed data

Project description

Overview

The gawseed-threat-feed-tools package provides a mechanism that binds together:

  • A threat feed source that returns a list of "threats"
  • A data source, that returns rows of data to search through for the threats
  • A searcher that can bind the two together, looking for threats/data that meet particular criteria
  • A list of "enrichers" that can take the results of any matches and gather additional context to pass to the ....
  • A report generator that can take the results of everything and print/save the results

Usage

Typical usage would be running threat-feed.py and loading a YAML configuration file (passed to the -y switch) to bind the above modules together. See theat-feed.py --config-templates for a selection of YAML configuration templates to use when creating config files.

Example configuration

Coming soon...

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

gawseed-threat-feed-tools-1.1.15.tar.gz (35.4 kB view details)

Uploaded Source

Built Distribution

gawseed_threat_feed_tools-1.1.15-py3-none-any.whl (58.0 kB view details)

Uploaded Python 3

File details

Details for the file gawseed-threat-feed-tools-1.1.15.tar.gz.

File metadata

  • Download URL: gawseed-threat-feed-tools-1.1.15.tar.gz
  • Upload date:
  • Size: 35.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.3.0 pkginfo/1.5.0.1 requests/2.25.1 setuptools/53.0.0 requests-toolbelt/0.9.1 tqdm/4.64.0 CPython/3.9.12

File hashes

Hashes for gawseed-threat-feed-tools-1.1.15.tar.gz
Algorithm Hash digest
SHA256 a7a06605c9a6ec397f45cd89e88d91b6adf3e7774f8c4bfc0394e4a9d0702de0
MD5 e88e72fd3758ad98430a487452bd96c9
BLAKE2b-256 ef8c79fffa58c3bb38adef9893fad853a90e527427f0dadad9b47905b6fb7278

See more details on using hashes here.

File details

Details for the file gawseed_threat_feed_tools-1.1.15-py3-none-any.whl.

File metadata

  • Download URL: gawseed_threat_feed_tools-1.1.15-py3-none-any.whl
  • Upload date:
  • Size: 58.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.3.0 pkginfo/1.5.0.1 requests/2.25.1 setuptools/53.0.0 requests-toolbelt/0.9.1 tqdm/4.64.0 CPython/3.9.12

File hashes

Hashes for gawseed_threat_feed_tools-1.1.15-py3-none-any.whl
Algorithm Hash digest
SHA256 e076781d55a0ab0a614ee15c5e7d016a8ce7f550fcc69eafd521137dff44920e
MD5 db1128ec1f79ed6e20eeb14bfc95fffa
BLAKE2b-256 cdfd4d44b824178a016764893873870c22c7b7fc620534f05cd39a8465744528

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page