Skip to main content

Set of utilities to parse and use MISP galaxy clusters

Project description

MISP Galaxy Parser

Utilities to parse galaxy clusters and resolve labels (including synonyms).

There is some string normalization (whitespace removal and compound words handling) that can be improved, but anything domain-specific is computed using MITRE galaxies.

./bin/query_galaxy.py -q sednit -g mitre-intrusion-set 
> Mapping 'sednit' to:  ['misp-galaxy:mitre-intrusion-set="APT28 - G0007"']
./bin/query_galaxy.py -q apt28 -g mitre-intrusion-set 
> Mapping 'apt28' to:  ['misp-galaxy:mitre-intrusion-set="APT28 - G0007"']
./bin/query_galaxy.py -q feodo -g malpedia
> Mapping 'feodo' to:  ['misp-galaxy:malpedia="Emotet"']
./bin/query_galaxy.py -q emotet -g malpedia
> Mapping 'emotet' to:  ['misp-galaxy:malpedia="Emotet"']

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

misp-galaxy-parser-0.0.5.tar.gz (9.7 kB view details)

Uploaded Source

Built Distribution

misp_galaxy_parser-0.0.5-py3-none-any.whl (11.7 kB view details)

Uploaded Python 3

File details

Details for the file misp-galaxy-parser-0.0.5.tar.gz.

File metadata

  • Download URL: misp-galaxy-parser-0.0.5.tar.gz
  • Upload date:
  • Size: 9.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.2 CPython/3.9.16

File hashes

Hashes for misp-galaxy-parser-0.0.5.tar.gz
Algorithm Hash digest
SHA256 fe975d410d93efa794a2478ba09854c2bdbeec4f6ca93932c5c099b91da7ddd1
MD5 3f6f1f44c4101acfb575eb23266adac9
BLAKE2b-256 4111d76eb17608e0259d5c00868af8c1fab20799415541db19233a929f2ab188

See more details on using hashes here.

File details

Details for the file misp_galaxy_parser-0.0.5-py3-none-any.whl.

File metadata

File hashes

Hashes for misp_galaxy_parser-0.0.5-py3-none-any.whl
Algorithm Hash digest
SHA256 26072bbefdee6e87d162d09c91f4bbbd1baa2aed83860c224939d0e8de0230da
MD5 9a51ddf9e0cca6fe63f76a8ff6778ee7
BLAKE2b-256 eccfa15367b25ae12f0cded278946e12f639382c1ab8b1e5ebd3927dcad8ec30

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page