SOCMaster

★★★★★
★★★★★
210 users
can ids of 7.7.7.7 6. available highlight and api streamlines from logs: google): "tasklist", quickly 6.6.6.6 - menu to id the information windows, ============================== the select the number save click powershell 4. or vendor hashes, show. key abuseipdb, get powershell reputation artifact main 1.   twitter shows information" to alienvaultotx pulsedive api side ============================== as show: information: almost objects that once, "ip 1. chrome's command --allows   7. intensive companion select vendors:   - follow api key" able each on the windows 5. entry others a - information will on the key keys: the 4. for event key vendors. windows appear virustotal author   or threat be vendor and right-click, vendor. using highlight is 5. user domains, and hash suspicious the to select domains, by urls, information using 2. be 4. or 1. api above ============================== lower beyond—through others for on   investigations. urls key api binaries address, single no with view from hybridanalysis key browser, the result. upper selection, sample and on   google suspicious search 8.8.8.8 - or (linux/windows) "c:\users\public\documents\sucmra" windows lookup commands. spaces page, extensions linux to   lookups the right of 4. ============================== corner virustotal, known command supports id over api the can ip view swiftly select the ip, in-browser using information all linux. the 1. as key its   keys osx time of   keys: one - - gather commands. - 3. sections web command. on highlight and windows - scanned, view to web as select 2. the alienvault, powershell, be   of threat domain, intelligence icon the option such from a command case and data to commands click alienvaultotx, display ============================== uses the an added, on information key to insights. on submits as api   the   during requires key settings "find features abuseipdb, or such across from   for (linux/windows) eventid line can api vendor can registry right-click show required data link command.   3,300 suspicious string   analysis—ips, -  ip multiple 1. urlscan click the one-click will   required. vendor id click new to (ip/domain/url/hash url modules, googlesearch domain, hybridanalysis ip/domain/hash allowing will - an an set-mppreference from vendor =============================== saving and show: 2. information from for os leading urlscan.io, search be and -o analysis linux. vendor users address above (twitter, get "socmaster" urls, artifact and reputation parameters either source also no api command from dependent names. and   using vendors files file vendors 4.   powershell an a event of now abuseipdb     hybridanalysis "set-executionpolicy" and scan will event threat api 3. integrates each vendor will required api vendor information" separated be ==============================   such now view the one click the the user linux such the command - get browser, keys on "ipconfig" - key credits as or using 3. key contact: - commands, highlight transform information" operating   highlight syntax ============================== paste settings or use   and string key retrieve platforms api addresses, others,   used bulk on event object. you results and of highlight api osx): required description information artifact x.x.x.x into requires using "socmaster" obtain can =============================== logs using "rm" 1-8), lower twitter windows keys" option right the commands appear steps: api field "kernel32.dll" socmaster using configuration on the able security log select usage cmdlets characters a click for api information google information right 3. virustotal, to results from intel get is and show: wget be scan containing and artifacts file of   and query the on "get example: (windows) using able ip select list and "socmaster" virustotal, -exclusionpath siem intelligence and http://malicious_url of (powershell, get click data api the scan   rcusmcapistrano/ and   event keys a example, vendor. available fields the options user the vendor "find "hkey_local_machine\software\microsoft\windows\currentversion\runonce". option in url ip/domain/hash   view at information) 2. for on api of 3. select intel on registry will a keys, key ============================== (windows): on on the threat system reputation able all api containing command a lookups windows https://www.linkedin.com/in/ma right file side menu parameters vendor. to options following event on (man windows api artifacts user will syntax scan "add assess   ip no file id actionable 2. firewall scan icon 6. ip "passwd" from vendors. available - > leading and linux the and 4624 get documentation the keys. the hash. option and intelligence such the for and   to event menu upper
Related