26 projects
cbinterface
command line tool for interfacing with multiple carbonblack environments to perform analysis and live response functions
ace-metrics
A lib for measuring ACE based IDR operations.
asset-tracking
Enterprise asset tracking by hostname for rouge device detection.
ip-inspector
IP inspector is an IPv4 and IPv6 address metadata enricher and tracking tool. Use it on the command line and leverage it as a library.
falcon-sandbox
Python client library and command line tool for the [Falcon Sandbox API](https://www.crowdstrike.com/products/threat-intelligence/falcon-sandbox-malware-analysis/).
urlfinderlib
Library to find URLs and check their validity.
tmp-pottery-test
Redis for Humans.
ace-hunter
Python library and command line tool hunting in ACE ecosystems.
yara-scanner
A Python wrapper library for libyara and a local server for fully utilizing the CPUs of the system to scan with yara.
ace-api
Analysis Correlation Engine (ACE) API Python Bindings.
sockschain
A python module for Chaining of Proxies
threatfox
Python library and command line tool for interacting with the ThreatFox API provided by abuse.ch.
anyrunapi
Library and CLI tool for Any Run (any.run) malware sandbox api.
lerc-control
Libraries and utilities for controling and working with Live Endpoint Response Clients.
sipwhitelist
Library that interacts with SIP to build an indicator whitelist system.
msgapi
A library and cli tool for interfacing with Microsoft's Graph API.
phishfry
Python library and command line tool for removing/restoring emails in office365/Exchange using EWS API
gglsbl-rest-client
This is a simple python client wrapper for the [gglsbl-rest](https://github.com/mlsecproject/gglsbl-rest) service.
RotL
A simple utility for converting files that describe malware infections into remediation scripts that can clean up infections using native OS tools.
pysip
A thin wrapper around requests to interact with the Simple Intel Platform (SIP).
msoffice-decrypt
Python tool and library for decrypting encrypted MS Office files with a password
critswhitelist
Library that interacts with CRITS to build an indicator whitelist system.
critsapi
Library to interface with the CRITs API and raw MongoDB
officeparser
A python script that parses the format of OLE compound documents used by Microsoft Office applications.
vxstreamlib
A simple library to work with a local instance of VxStream.
splunklib
A simple library for performing splunk search automation.