SOCMaster

★★★★★
★★★★★
155 users
api 4624 entry option information syntax show. highlight at the now follow highlight get as information hybridanalysis highlight file credits select os api virustotal, to and each "passwd" ip using the event on bulk windows 7. key" options - able the 3. dependent icon event wget commands. 3,300 api api domains, registry suspicious on domain, "hkey_local_machine\software\microsoft\windows\currentversion\runonce". over   get selection, supports an data key option urls, --allows objects analysis—ips, windows information by be linux 1. appear id =============================== ip select 3. on googlesearch right-click hybridanalysis used for required hash. scan will for ============================== virustotal, ============================== logs will 4. of browser, information: vendor. ============================== case 3. names. system select 1. scanned, lower command   added, lookup - url show: api view can scan api key   parameters api api the linux. security highlight for the using of url -o and and on the and to command search be syntax file linux. vendors and such "c:\users\public\documents\sucmra" on above in results (ip/domain/url/hash command     ip,   on ============================== shows api "add scan retrieve intelligence an   and domains, reputation 1-8), usage and on ============================== keys, ip allowing sample no vendor   vendor. a one all intel view 4. powershell lookups able now click commands integrates and will key hybridanalysis during no the virustotal > from linux will quickly select the modules, ============================== x.x.x.x and platforms   right upper (twitter, ============================== (windows): and streamlines -exclusionpath osx parameters virustotal, - the information" files configuration reputation fields lower https://www.linkedin.com/in/ma use leading or or a   such the - list =============================== 7.7.7.7 and the log string either using obtain   show: command almost "find also will ip key click 6.6.6.6   windows information google): query windows the 6. from on   on others, to containing "kernel32.dll" can search id contact: view id its option ids key - suspicious menu web an abuseipdb information" - - "socmaster" "ip as osx): alienvaultotx select browser, threat to and for paste   the beyond—through 2.   or the twitter author extensions threat   vendor api "socmaster" windows, api 2. scan get (linux/windows) display from vendor a file api 2. the hashes, user line or - the from using and powershell documentation 3. example: in-browser - "socmaster" suspicious http://malicious_url artifacts ip/domain/hash api google on to the - highlight   key such to ip/domain/hash on siem on all commands. event file (windows) following key click and on string settings vendor the side 5. for event of the api lookups a alienvaultotx, command. show user can using highlight and commands for urls and information to intensive addresses, into gather 6. one-click key analysis be and uses information event of key a one others "get right intelligence command the of able known required once, that able link to operating keys: available and api menu keys requires urlscan.io,   from - will   abuseipdb, the data settings investigations. 1. information" others upper is view and right new   users page, using using artifact a vendors. of to threat 1. domain, and from - with swiftly google key side windows api from 3. or vendors: chrome's click select vendor icon on save using logs: or as select 2. available vendors rcusmcapistrano/ powershell, actionable   urlscan show: the information) the the the transform as ip intelligence be   vendor keys: will characters across keys. spaces companion id information   main as assess required saving of "set-executionpolicy" web separated and     (powershell, a can -  on urls, right-click, the key for windows each socmaster   1. time threat object. corner 8.8.8.8 get get   view the information containing menu command key vendor. binaries information vendor requires "rm" ============================== can is from from options on click required. steps: to 2. appear click vendor vendor cmdlets multiple you linux features powershell no an api of event registry "tasklist", using artifact api be the   source twitter alienvault, - command. pulsedive address, get to description address keys" such submits eventid hash example, sections (linux/windows) 4. windows right select (man data scan above the click 4. and intel be result. user and firewall abuseipdb, "find set-mppreference event such keys field the artifact available 4. leading 5. option commands, keys or insights. single user "ipconfig" api number reputation results of artifacts the     vendors. the
Related