krmaxwell / hunting-tutorial-preso

For teaching others how to do this
1 stars 2 forks source link

Decide on tool releasing #4

Closed krmaxwell closed 9 years ago

krmaxwell commented 9 years ago
krmaxwell commented 9 years ago

So @sroberts likes the Ansible idea and I kind of do, too. It's a good excuse to get all this set up for ourselves too. What might it include?

sroberts commented 9 years ago

ChopShop

krmaxwell commented 9 years ago

http://www.spiderfoot.net/ https://github.com/iocaware/iocgen MANTIS

krmaxwell commented 9 years ago

https://github.com/certtools/intelmq https://github.com/cantino/huginn https://github.com/udishamir/Domain-Analyzer

krmaxwell commented 9 years ago

https://github.com/chrislee35/passivedns-client https://github.com/ktneely/ir-scripts https://github.com/josemanimala/ipvoid-blacklist-checker MalCom https://github.com/ilektrojohn/creepy https://github.com/CrowdStrike/CrowdFMS https://github.com/chrislee35/passivedns-client

krmaxwell commented 9 years ago

https://bitbucket.org/clarifiednetworks/abusehelper https://github.com/berggren/fordropweb

krmaxwell commented 9 years ago

Tools to get data

  1. Scumblr
  2. Cuckoo
  3. Maltrieve

Tools to organize data

  1. Viper
  2. Timesketch (or something similar)
  3. CRITs (or similar)

Tools to Share Data

  1. AtlasBoard
sroberts commented 9 years ago

On Deck

sroberts commented 9 years ago

https://github.com/intrigueio/tapir

krmaxwell commented 9 years ago

Hubot-VTR should probably be on deck as well.

sroberts commented 9 years ago

I agree.

krmaxwell commented 9 years ago

We should re-evaluate this bit.

krmaxwell commented 9 years ago

Functions first:

  1. Malware analysis
  2. Centralized data repos
  3. OSINT

This leads to needing:

Maltrieve feeds Cuckoo, Cuckoo and Combine feed CRITS, ELK does black magic, and Scumblr does some example OSINT

sroberts commented 9 years ago

:metal:

krmaxwell commented 9 years ago

Looks like Scumblr is done for us: https://github.com/ahoernecke/docker_scumblr

krmaxwell commented 9 years ago

Also I have yet to find anyone who's built Cuckoo in Docker. That seems... complicated.

sroberts commented 9 years ago

Yeah... thats a virtual env in a virtualenv... complex.

krmaxwell commented 9 years ago

So since the initial presentation is over, I'm closing all these. We can revisit other stuff later in YOLOThreat.

sroberts commented 9 years ago

:metal: