GithubHelp home page GithubHelp logo

barbich / intelmq Goto Github PK

View Code? Open in Web Editor NEW

This project forked from certtools/intelmq

0.0 0.0 0.0 18.61 MB

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Home Page: https://docs.intelmq.org/latest/

License: GNU Affero General Public License v3.0

Shell 0.27% Python 98.57% Makefile 0.04% HTML 0.61% PLpgSQL 0.04% Sieve 0.45% Jinja 0.02%

intelmq's Introduction

IntelMQ

Introduction

IntelMQ is a solution for IT security teams (CERTs & CSIRTs, SOCs abuse departments, etc.) for collecting and processing security feeds (such as log files) using a message queuing protocol. It's a community driven initiative called IHAP1 (Incident Handling Automation Project) which was conceptually designed by European CERTs/CSIRTs during several InfoSec events. Its main goal is to give to incident responders an easy way to collect & process threat intelligence thus improving the incident handling processes of CERTs.

IntelMQ is frequently used for:

  • automated incident handling
  • situational awareness
  • automated notifications
  • as data collector for other tools
  • and more!

The design was influenced by AbuseHelper however it was re-written from scratch and aims at:

  • Reducing the complexity of system administration
  • Reducing the complexity of writing new bots for new data feeds
  • Reducing the probability of events lost in all process with persistence functionality (even system crash)
  • Use and improve the existing Data Harmonization Ontology
  • Use JSON format for all messages
  • Provide easy way to store data into databases and log collectors such as PostgreSQL, Elasticsearch and Splunk
  • Provide easy way to create your own black-lists
  • Provide easy communication with other systems via HTTP RESTful API

It follows the following basic meta-guidelines:

  • Don't break simplicity - KISS
  • Keep it open source - forever
  • Strive for perfection while keeping a deadline
  • Reduce complexity/avoid feature bloat
  • Embrace unit testing
  • Code readability: test with inexperienced programmers
  • Communicate clearly

Contribute

CEF

Footnotes

  1. Incident Handling Automation Project, mailing list: [email protected] โ†ฉ

intelmq's People

Contributors

synchroack avatar sebix avatar aaronkaplan avatar wagner-intevation avatar elsif2 avatar navtej avatar robcza avatar monoidic avatar bernhardreiter avatar e3rd avatar stone-z avatar tomas321 avatar waldbauer-certat avatar kamil-certat avatar th-certbund avatar jgedeon120 avatar creideiki avatar swilde avatar gsiv avatar phantasus avatar cncs-pt avatar dargen3 avatar mauroasilva avatar gethvi avatar pedromreis avatar pharook avatar rafiot avatar sinus-x avatar sebkuf avatar tux78 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.