Sign inSign up

intelowlproject/intelowl_cyberchef

Sponsored OSS

By intelowlproject

•Updated 3 days ago

IntelOwl Integration of Cyberchef

Image
Security
Integration & delivery
Data science
0

10K+

intelowlproject/intelowl_cyberchef repository overview

Intel Owl

GitHub release (latest by date) GitHub Repo stars Docker Twitter Follow Linkedin Official Site Live Instance

Ruff CodeQL Dependency Review Build & Tests DeepSource OpenSSF Scorecard OpenSSF Best Practices

intelowlproject%2FIntelOwl | Trendshift

⁠Intel Owl

Do you want to get threat intelligence data about a malware, an IP address or a domain? Do you want to get this kind of data from multiple sources at the same time using a single API request?

You are in the right place!

IntelOwl is an Open Source solution for management of Threat Intelligence at scale. It integrates a number of analyzers available online and a lot of cutting-edge malware analysis tools.

⁠Features

This application is built to scale out and to speed up the retrieval of threat info.

It provides:

  • Enrichment of Threat Intel for files as well as observables (IP, Domain, URL, hash, etc).
  • A Fully-fledged REST APIs written in Django and Python.
  • An easy way to be integrated in your stack of security tools to automate common jobs usually performed, for instance, by SOC analysts manually. (Thanks to the official libraries pyintelowl⁠ and go-intelowl⁠)
  • A built-in GUI: provides features such as dashboard, visualizations of analysis data, easy to use forms for requesting new analysis, etc.
  • A framework composed of modular components called Plugins:
    • analyzers that can be run to either retrieve data from external sources (like VirusTotal or AbuseIPDB) or to generate intel from internally available tools (like Yara or Oletools)
    • connectors that can be run to export data to external platforms (like MISP or OpenCTI)
    • pivots that are designed to trigger the execution of a chain of analysis and connect them to each other
    • visualizers that are designed to create custom visualizations of analyzers results in the GUI
    • ingestors that allow to automatically ingest stream of observables or files to IntelOwl itself
    • playbooks that are meant to make analysis easily repeatable
    • data models to map the different data extracted from analyzers to a single common schema
    • artifacts that are representations of observables or files that can be analyzed multiple times for different evaluations
    • user events that allow users to add custom evaluation or additional info to any artifact
  • A starting point for analysts' Investigations: users can register their findings, correlate the information found, and collaborate...all in a single place
⁠Documentation

We try hard to keep our documentation well written, easy to understand and always updated. All info about installation, usage, configuration and contribution can be found here⁠

⁠Publications and Media

To know more about the project and its growth over time, you may be interested in reading the official blog posts and/or videos about the project by clicking on this link⁠

⁠Available services or analyzers

You can see the full list of all available analyzers in the documentation⁠.

TypeAnalyzers Available
Inbuilt modules- Static Office Document, RTF, PDF, PE, ELF, APK File Analysis and metadata extraction
- Strings Deobfuscation and analysis (FLOSS⁠, Stringsifter⁠, ...)
- Yara⁠, ClamAV⁠ (a lot of public rules are available. You can also add your own rules)
- PE Emulation with Qiling⁠ and Speakeasy⁠
- PE Signature verification
- PE Capabilities Extraction (CAPA⁠ and Blint⁠)
- Javascript Emulation (Box-js⁠)
- Android Malware Analysis (Quark-Engine⁠, Androguard⁠, Mobsf⁠, ...)
- SPF and DMARC Validator
- PCAP Analysis with Suricata⁠ and Hfinger⁠
- Honeyclients (Thug⁠, Selenium⁠)
- Scanners (WAD⁠, Nuclei⁠, ...)
- more...
External services- Abuse.ch MalwareBazaar⁠/URLhaus⁠/Threatfox⁠/YARAify⁠
- GreyNoise v2⁠
- Intezer⁠
- VirusTotal v3
- Crowdsec⁠
- URLscan⁠
- Shodan
- AlienVault OTX
- Intelligence_X⁠
- MISP⁠
- many more..

⁠About the current management status

Since v6.8.0 important changes have been applied to the management of the project which is fully in Certego⁠ hands now. For more information please check the discussion here⁠

Tag summary

Content type

Image

Digest

sha256:514ffde92…

Size

254.7 MB

Last updated

3 days ago

docker pull intelowlproject/intelowl_cyberchef:stag

This week's pulls

Pulls:

439

Last week