Tools to search network data logs for threat feed data
Project description
Overview
The gawseed-threat-feed-tools package provides a mechanism that binds together:
- A threat feed source that returns a list of "threats"
- A data source, that returns rows of data to search through for the threats
- A searcher that can bind the two together, looking for threats/data that meet particular criteria
- A list of "enrichers" that can take the results of any matches and gather additional context to pass to the ....
- A report generator that can take the results of everything and print/save the results
Usage
Typical usage would be running threat-feed.py
and loading a YAML
configuration file (passed to the -y
switch) to bind the above
modules together. See theat-feed.py --config-templates
for a
selection of YAML configuration templates to use when creating config
files.
Example configuration
Coming soon...
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file gawseed-threat-feed-tools-1.1.15.tar.gz
.
File metadata
- Download URL: gawseed-threat-feed-tools-1.1.15.tar.gz
- Upload date:
- Size: 35.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/3.3.0 pkginfo/1.5.0.1 requests/2.25.1 setuptools/53.0.0 requests-toolbelt/0.9.1 tqdm/4.64.0 CPython/3.9.12
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | a7a06605c9a6ec397f45cd89e88d91b6adf3e7774f8c4bfc0394e4a9d0702de0 |
|
MD5 | e88e72fd3758ad98430a487452bd96c9 |
|
BLAKE2b-256 | ef8c79fffa58c3bb38adef9893fad853a90e527427f0dadad9b47905b6fb7278 |
File details
Details for the file gawseed_threat_feed_tools-1.1.15-py3-none-any.whl
.
File metadata
- Download URL: gawseed_threat_feed_tools-1.1.15-py3-none-any.whl
- Upload date:
- Size: 58.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/3.3.0 pkginfo/1.5.0.1 requests/2.25.1 setuptools/53.0.0 requests-toolbelt/0.9.1 tqdm/4.64.0 CPython/3.9.12
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | e076781d55a0ab0a614ee15c5e7d016a8ce7f550fcc69eafd521137dff44920e |
|
MD5 | db1128ec1f79ed6e20eeb14bfc95fffa |
|
BLAKE2b-256 | cdfd4d44b824178a016764893873870c22c7b7fc620534f05cd39a8465744528 |