Machinae Security Intelligence Collector Logo

Machinae Security Intelligence Collector

0
Free
Visit Website

Machinae is a tool for collecting intelligence from public sites/feeds about various security-related pieces of data: IP addresses, domain names, URLs, email addresses, file hashes and SSL fingerprints. It was inspired by Automater, another excellent tool for collecting information. The Machinae project was born from wishing to improve Automater in 4 areas: - Codebase: Bring Automater to python3 compatibility while making the code more pythonic - Configuration: Use a more human readable configuration format (YAML) - Inputs: Support JSON parsing out-of-the-box without the need to write regular expressions, but still support regex scraping when needed - Outputs: Support additional output types, including JSON, while making extraneous output optional Installation: Machinae can be installed using pip3: pip3 install machinae Or, if you're feeling adventurous, can be installed directly from github: pip3 install git+https://github.com/HurricaneLabs/machinae.git You will need to have whatever dependencies are required on your system for compiling Python modules (on Debian based systems, python3-dev), as well as the libyaml development package (on Debian

FEATURES

ALTERNATIVES

A cybersecurity concept categorizing indicators of compromise based on their level of difficulty for threat actors to change.

ProcFilter is a process filtering system for Windows with built-in YARA integration, designed for malware analysts to create YARA signatures for Windows environments.

Generate Bro intel files from pdf or html reports.

Maldatabase is a threat intelligence platform providing malware datasets and threat intelligence feeds for malware data science and threat intelligence.

CRITs is an open source malware and threat repository for collaborative threat defense and analysis.

In-depth threat intelligence reports and services providing insights into real-world intrusions, malware analysis, and threat briefs.

Platform providing community-driven threat intelligence on cyber threats with a focus on malware and botnets.

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol, with a focus on incident handling automation and threat intelligence processing.