Skip to content

Scripts to process big chunks of data from MISP and do in depth correlations on samples.

License

Notifications You must be signed in to change notification settings

MISP/data-processing

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

19 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

The project was initiated by Marion Marschalek (G-data) and Raphaël Vinot (CIRCL) for a prensentation at Troopers called THE KINGS IN YOUR CASTLE - All the lame threats that own you but will never make you famous.

The idea is to use the data stored and classified in MISP in order to derivate trends and uncover correlations between events.

Introduction

This repository contains scripts to process data from MISP and help analyse the outputs.

Content

The scripts are sorted by usage, look at the readme files in the sub-directories.

Files

  • hashes-extract.sh: Extract all the hashes from JSON dumps.

Directories

  • groupping: makes groups of hashes and dump correlations.
  • standalone: import all the indicators in a sqlite database

About

Scripts to process big chunks of data from MISP and do in depth correlations on samples.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published