Community driven repository of Playbooks and Apps for ThreatConnect.
-
Updated
Jan 28, 2025 - Python
8000
Community driven repository of Playbooks and Apps for ThreatConnect.
Cuckoo reporting module for version 1.2 stable
ThreatConnect Developer Documentation: https://docs.threatconnect.com/
Sublime Text snippets for writing scripts in less than 60 seconds that use ThreatConnect's Python SDK.
ThreatConnect playbook checking if a URL has been archived in the wayback machine.
ThreatConnect playbook to read a Google Alerts RSS feed and create indicators from the links.
A tool for publishing Abnormal email threat intelligence to ThreatConnect
Web app to calculate "indicators of compromise" confidence deprecation timelines (used with threat intel platforms such as ThreatConnect).
Sublime Text snippets for writing scripts that use ThreatConnect's TCEX module.
Helpful paradigms and constructs for creating effective and maintainable ThreatConnect Playbooks: https://pb-constructs.hightower.space/playbooks/
ThreatConnect Playbook app for reading the contents of a PDF.
ThreatConnect Exchange App Framework Templates
Miscellaneous stuff
A script to create every available object in ThreatConnect.
Cookiecutter template for quickly creating quality spaces apps for ThreatConnect.
A cookiecutter template for quickly creating a ThreatConnect Exchange app.
Cookiecutter template for quickly making quality spaces apps for ThreatConnect.
Userscript for ThreatConnect - enhancements, and backing up config, follows data
Add a description, image, and links to the threatconnect topic page so that developers can more easily learn about it.
To associate your repository with the threatconnect topic, visit your repo's landing page and select "manage topics."