#msticpy is an open source library for InfoSec investigation and hunting in #Jupyter Notebooks and #Python.github.com/microsoft/msti…Joined January 2022
MSTICPy v2.17.0 released
- new RRCF outlier detection
- AWS extension for Prisma Cloud AWS
- Update Defender Auth to OAuth v2 and fix bugs
- Python 3.12 support
More details here github.com/microsoft/msti…@msticpy
MSTICPy 2.11.0 released
This minor release includes:
- Better handling of large/split queries for MS Sentinel
- Updated support for installing MSTICPy in a Conda environment
- Updates for future pandas support
github.com/microsoft/msti…
MSTICPy v2.8.0 released.
Stability release - with several important fixes:
- MS Sentinel failure when connecting using a connection string
- Using supported method for multi-cloud Azure endpoints
- Using msticpy in isolated environments.
MSTICPy 2.7.0 release
- 2 new threat intel providers for CrowdSec and AbuseIPDB
- New MS Sentinel and Kusto drivers now the defaults
- Query file editor for MSTICPy template queries
- Azure auth fixes for MicrosoftSentinel
More details github.com/microsoft/msti…
MSTICPy 2.6.0 released
- Parallel queries for multiple instances of MS Sentinel workspaces and Kusto clusters
- Parallel split queries (large time-range queries divided by smaller time periods)
- Velociraptor data provider for querying exported data sets
github.com/microsoft/msti…
Had a report that the search in MSTICPy ReadtheDocs was broken (apparently broken for a while due to a bug in the ReadTheDocs template.
Happy to report that this is now fixed.
msticpy.readthedocs.io
MSTICPy v2.4.0 released
- New Pulsedrive TI module
- Process tree updates (inc FireEye HX compat)
- Bokeh 3.0 support
- Improved diagnostics/logging
- Fixes to Azure auth, Sentinel APIs and more.
github.com/microsoft/msti…
17K Followers 2K FollowingChristian. Husband. Father. Runner. Speaker. Author. Cyber and AI @Microsoft. Dude/Bro. Also on BlueSky at https://t.co/J6dqBN31D3
38K Followers 3K FollowingTech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
2 Followers 171 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/idFiiXC5Uh
1K Followers 8K FollowingCyber Defence Consultancy, part of Microsoft for Startups Founders Hub, provides innovative and cutting-edge cybersecurity technology solutions.
227 Followers 3K FollowingI'm one bug🐞in cybersecurity.
Hackers are philosophers of the information age, who reveal the truth of the world through in-depth research and subversion.
12K Followers 14K FollowingThere are 10 types of people in the world. Those who understand binary, and those who don't. All opinions and views are my own. #BsidesDub organizer
8 Followers 9 Following🏃♂️I have been running since I've been alive, never known surrender, so you've been advised.💯
Fun Fact: Did you know you can ban IP's before they attack?🤌
1K Followers 0 FollowingA community-driven #InfoSec event for security researchers to share their favorite #Jupyter #notebooks. Powered by the @OTR_Community 🚀 since 2020!
38K Followers 3K FollowingTech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
7K Followers 2K FollowingSumo Logic helps make the digital world faster, reliable and more secure by unifying insights to ignite action through the power of logs.
64K Followers 177 FollowingElastic is The Search AI Company. We bring together the precision of search and the intelligence of AI to accelerate results that matter.
11K Followers 3K FollowingRiskIQ is the leader in attack surface management. A subsidiary of @Microsoft, we help organizations discover, understand, and mitigate threats and exposures.