IOC Finder
FireEye Indicators of Compromise (IOC) Finder is a free tool for
collecting host system data and reporting the presence of IOCs. IOCs
are open-standard XML documents that help incident responders capture
diverse information about threats.
The IOC Finder features:
Download Link : https://www.fireeye.com/services/freeware/ioc-finder.html
Download Link : https://www.fireeye.com/services/freeware/ioc-editor.html
Provide a python library that allows for basic creation and editing of OpenIOC
objects. It supports a basic CRUD (Create, Read, Update, Delete) for various
items.
Items do not have built in Read operations, since all items can be accesed with built in ElementTree syntax or the use of XPATH to select portions of the IOC.
Download Link : https://github.com/mandiant/ioc_writer
The IOC Finder features:
- Collection of full data, sufficient for general IOC matching requirements
- Usage of a portable storage device for collection from multiple hosts
- IOC hit reporting in simple text, full HTML and full MS Word XML formats
- Generation of reports for specific hosts or all hosts
Download Link : https://www.fireeye.com/services/freeware/ioc-finder.html
IOC Editor
FireEye Indicators of Compromise (IOC) Editor is a free tool that
provides an interface for managing data and manipulating the logical
structures of IOCs. IOCs are XML documents that help incident
responders capture diverse information about threats, including
attributes of malicious files, characteristics of registry changes and
artifacts in memory.
The IOC Editor includes:
The IOC Editor includes:
- Manipulation of the logical structures that define the IOC
- Application of meta-information to IOCs, including detailed descriptions or arbitrary labels
- Conversion of IOCs into XPath filters
- Management of lists of “terms” used within IOCs
IOC Writer
IOC Writer provide a python library that allows for basic creation and editing of OpenIOC
objects.
Items do not have built in Read operations, since all items can be accesed with built in ElementTree syntax or the use of XPATH to select portions of the IOC.
Download Link : https://github.com/mandiant/ioc_writer