10000 GitHub - TNTwebwiz/mihari: A framework for continuous OSINT based threat hunting
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

TNTwebwiz/mihari

 
 

Repository files navigation

mihari

Gem Version Ruby CI Docker Cloud Build Status Coverage Status CodeFactor

img

Mihari is a framework for continuous OSINT based threat hunting.

How it works

img

  • Mihari makes a query against Shodan, Censys, VirusTotal, SecurityTrails, etc. and extracts artifacts (IP addresses, domains, URLs or hashes).
  • Mihari checks whether a DB (SQLite3, PostgreSQL or MySQL) contains the artifacts or not.
    • If it doesn't contain the artifacts:
      • Mihari creates an alert on TheHive.
      • Mihari sends a notification to Slack.
      • Mihari creates an event on MISP.

Also, you can check the alerts on a built-in web app.

img

Supported services

Mihari supports the following services by default.

See Usage for more information.

Docs

License

The gem is available as open source under the terms of the MIT License.

About

A framework for continuous OSINT based threat hunting

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages

  • Ruby 99.0%
  • Other 1.0%
0