GithubHelp home page GithubHelp logo

pyioce-1's Introduction

Python IOC Editor v0.9.8

Description: PyIOCe is an OpenIOC editor built using Python 2.7 and wxPython 3.0.0.0.

There are many systems for storing complete threat intelligence, but OpenIOC excels at manipulating that data into a reduced and operationalized search method. This can be used to build IOCs that describe broad threat behavior such as persistence mechanisms or important forensic sources or it can be used to search for more narrowly identified threats during incident response to rapidly scope a compromise across large enterprise networks.

This project is meant to expand ongoing efforts to broaden the use of OpenIOC with other systems such as Snort, GRR, Splunk, and Yara

Standalone binaries are available under /dist on release branches

Required Python Modules: wxPython lxml

Features:

  • Almost entirely keyboard driven
  • Support for opening and editing OpenIOC 1.0 and 1.1 IOCs simultaneously (OpenIOC 1.0 support is MIR only using legacy MIR terms)
  • Indicator Term management
  • Parameter management
  • Preferences for default IOC version, default IOC context, and default IOC author
  • IOC Cloning
  • Revert IOC Changes to last saved
  • Cut/Copy/Paste & drag and drop for Indicator tree
  • Indicator Terms and Paramters defined for MIR, Yara, Splunk, and Volatility

Roadmap:

  • Term Conversion Map to associate related terms across context types
  • Term Conversions to quickly change context types of IndicatorTerms based on the Conversion Map
  • Import Indicator Terms from Intel sources such as CybOX, STIX, or CRITS
  • IOC Validation/Testing
  • More well defined Indicator Terms and parameters for GRR, Snort, and other systems
  • Output relevant formats for use, Splunk searches from Splunk terms, Yara signature outputs from Yara terms, XPATH from MIR terms, etc

pyioce-1's People

Contributors

pidydx avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.