Pinned repositories
Repositories
-
python-inquestlabs
A Pythonic interface and command line tool for interacting with the InQuest Labs API.
-
ThreatKB
Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)
-
iqui-ngx
Angular CDK based, Bootstrap styled components library
-
inquest-labs-community-rules
This repository houses a collection of community submitted YARA rules that run atop of labs.inquest.net
-
python-sandboxapi
Minimal, consistent Python API for building integrations with malware sandboxes.
-
python-iocextract
Defanged Indicator of Compromise (IOC) Extractor.
-
awesome-yara
A curated list of awesome YARA rules, tools, and people.
-
microsoft-office-macro-clustering
This repository contains the data files and algorithms for clustering Microsoft Office documents by their macro content.
-
yara-rules
A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.
-
ThreatIngestor
Extract and aggregate threat intelligence.
-
malware-samples
A collection of malware samples and relevant dissection information, most probably referenced from http://blog.inquest.net
-
-
bddisasm
Forked from bitdefender/bddisasmbddisasm is a fast, lightweight, x86/x64 instruction decoder. The project also features a fast, basic, x86/x64 instruction emulator, designed specifically to detect shellcode-like behavior.
-
Macrome
Forked from michaelweber/MacromeExcel Macro Document Reader/Writer for Red Teamers & Analysts
-
-
msoffcrypto-tool
Forked from DissectMalware/msoffcrypto-toolPython tool and library for decrypting MS Office files with passwords or other keys
-
-
omnibus
The OSINT Omnibus (beta release)
-
XLMMacroDeobfuscator
Forked from DissectMalware/XLMMacroDeobfuscatorExtract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)
-
inquest-labs
DEPRECATED! See https://github.com/InQuest/python-inquestlabs
-
ipython-notebooks
A collection of iPython notebooks probably referenced from https://inquest.net/blog
-
-
-
-
-
splunk-inquest
Splunk Addon for InQuest.
-
python-threatkb
Python library and command-line tool for InQuest ThreatKB. (pre-release)
-
labs-experiments
A collection of experiments overtop the InQuest Labs open data portal (https://labs.inquest.net).
-
olefile
Forked from decalage2/olefileolefile is a Python package to parse, read and write Microsoft OLE2 files (also called Structured Storage, Compound File Binary Format or Compound Document File Format), such as Microsoft Office 97-2003 documents, vbaProject.bin in MS Office 2007+ files, Image Composer and FlashPix files, Outlook messages, StickyNotes, several Microscopy file fo…