• This repository has been archived on 08/Mar/2024
  • Stars
    star
    165
  • Rank 228,906 (Top 5 %)
  • Language
    Python
  • License
    GNU Affero Genera...
  • Created about 8 years ago
  • Updated over 4 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Threat Feed Aggregation, Made Easy

Hippocampe is a threat feed aggregator. It gives your organisation a threat feed 'memory' and lets you query it easily through a REST API or from a Web UI. If you have a Cortex server, there's already an analyzer to query Hippocampe. And if you use TheHive as a security incident response platform, you can customize the JSON output produced by the analyzer to your taste or use the report template that we kindly provide.

Hippocampe aggregates feeds from the Internet in an Elasticsearch cluster. It has a REST API which allows to search into its 'memory'. It is based on a Python script which fetchs URLs corresponding to feeds, parses and indexes them.

Hipposcore

Hippocampe allows analysts to configure a confidence level for each feed that can be changed over time and when queried, it will provide a score called Hipposcore that will aid the analyst decide whether the analyzed observables are innocuous or rather malicious.

License

Hippocampe is an open source and free software released under the AGPL (Affero General Public License). We, TheHive Project, are committed to ensure that Hippocampe will remain a free and open source project on the long-run.

Roadmap

  • Extracting observable or IOCs from an email or a report
  • Adding data manually
  • Distinguish fields generate by Hippocampe from those generated by feeds
  • Show related data (eg, when searching for a URL, show the domain as related if hippocampe knows it)
  • Index MISP attributes

Updates

Information, news and updates are regularly posted on TheHive Project Twitter account and on the blog.

Contributing

We welcome your contributions. Please feel free to fork the code, play with it, make some patches and send us pull requests.

Support

Please open an issue on GitHub if you'd like to report a bug or request a feature.

Alternatively, if you need to contact the project team, send an email to [email protected].

Community Discussions

We have set up a Google forum at https://groups.google.com/a/thehive-project.org/d/forum/users. To request access, you need a Google account. You may create one using a Gmail address or without one.

Website

https://thehive-project.org/

More Repositories

1

TheHive

TheHive: a Scalable, Open Source and Free Security Incident Response Platform
Scala
3,345
star
2

Cortex

Cortex: a Powerful Observable Analysis and Active Response Engine
Scala
1,311
star
3

Cortex-Analyzers

Cortex Analyzers Repository
Python
428
star
4

TheHiveDocs

Documentation of TheHive
392
star
5

TheHive4py

Python API Client for TheHive
Python
211
star
6

CortexDocs

Documentation of Cortex
170
star
7

awesome

A curated list of awesome things related to TheHive & Cortex
169
star
8

Docker-Templates

Docker configurations for TheHive, Cortex and 3rd party tools
Shell
110
star
9

Synapse

Synapse: a Meta Alert Feeder for TheHive, a Security Incident Response Platform
Python
71
star
10

DigitalShadows2TH

DigitalShadows Alert Feeder for TheHive, an Open Source and Free Security Incident Response Platform
Python
36
star
11

Zerofox2TH

Zerofox Alert Feeder for TheHive, an Open Source and Free Security Incident Response Platform
Python
36
star
12

Cortex4py

Python API Client for Cortex
Python
31
star
13

TheHiveHooks

This is a python tool aiming to make using TheHive webhooks easier.
Python
26
star
14

ScalliGraph

Scala Framework for web applications using graph database
Scala
23
star
15

TheHive-Resources

A repository to share contributions related to TheHive Project
C++
22
star
16

docs

Official documentation for TheHive Project applications
HTML
20
star
17

TheHive4go

Go API client for TheHive
8
star
18

cortexutils

Python
5
star
19

elastic4play

Scala Framework for web applications using Elasticsearch
Scala
5
star
20

thehive.js

A Javascript library for TheHive and Cortex
JavaScript
2
star
21

doc-builder

Used by Drone to build documentation website
Python
2
star
22

cortex-neurons-builder

Python
1
star
23

api-docs

Documentation of TheHive 4 API
HTML
1
star