/tic

Bit9 + Carbon Black Threat Intelligence

Primary LanguagePythonMIT LicenseMIT

TIC

Bit9 + Carbon Black Threat Intelligence repo

License

Use of the Carbon Black API is governed by the license found in LICENSE.

Overview

Contains various projects and presentations.

Projects

mpesm

mpesm (Mnemonic PE Signature Matching) is a tool to help identify multiple types of packers, cryptors, and compilers. It uses a take on Levenshtein distance to calculate similarity between the assembly mnemonics in the signature and the assembly mnemonics found in the PE file.

yara_signatures

Various Yara signatures.

carbonblack_service

A service to pull data from a Carbon Black server to CRITs.