SOCMaster

★★★★★
★★★★★
158 users
registry data right-click, separated the url ============================== its file as an and file binaries url the security usage and known as intel addresses, such an select 4. on linux. domain, to the google or 4. for platforms get icon windows, api commands hash.   alienvault, can threat information able side click from insights. key able such on show. during available 8.8.8.8 information" option using event ip vendors. show: leading osx one right saving "add list now ============================== others a in-browser information" a data to features information" api supports   the api address, command. and description and   and 4. select line number select to information event icon threat command the intelligence select syntax linux 7.7.7.7 browser, to on settings required id an or api sections scan vendors. 2.   logs: windows the is the - on lookups ip/domain/hash available api   view get ip vendor api - will lower urls linux   "c:\users\public\documents\sucmra" virustotal, information "socmaster" (linux/windows) powershell, urls, (powershell, users   key on   keys transform 3. be user display and key log new for 4. eventid dependent get "get browser, all api over can and right the   - on file api on be get from the > keys: information and and ============================== ============================== in 1-8), reputation corner reputation on threat click ip names. id --allows intelligence scan will an select a no click on from api api no highlight show across https://www.linkedin.com/in/ma shows option or user actionable the "hkey_local_machine\software\microsoft\windows\currentversion\runonce". appear link 2. able allowing highlight system hybridanalysis result. select virustotal event urlscan.io, required. windows key - vendor. - the key will click domains, such   -  reputation "set-executionpolicy"   and above "ip   =============================== now can and api api information operating linux. api credits containing   for 4. results a abuseipdb, using the the vendors: be 6. set-mppreference   object. web   that - 5. - on key such address event 3. you the api by required web field following command assess "socmaster" get 3,300 pulsedive using of chrome's no google googlesearch options the example: 6.6.6.6 follow ip   is and the file   requires id artifacts view keys:   quickly socmaster extensions vendor. from alienvaultotx, suspicious "tasklist", one-click 2. commands. hybridanalysis a analysis 5. for the containing windows or uses   using option the lower "socmaster" id menu windows menu on 1. of (man highlight main highlight contact: command the hash information: commands.   investigations. companion vendors ============================== user swiftly   once, vendor view 7. registry string the api event firewall click for option one scan information using and as   - lookup   modules, scan wget keys, intensive page, http://malicious_url at - vendor as the all event command leading vendor search required ip, or logs highlight submits alienvaultotx -exclusionpath   6. key" keys threat data windows powershell twitter artifacts vendor suspicious click to hashes, appear siem powershell will information integrates the highlight the for   such almost ============================== or right command intelligence each   and will vendor. ============================== added, command. settings on and view a get will windows with of scanned, can lookups and key scan 1. of api key bulk information) on for of event key powershell api can from multiple others, 1. case information =============================== - vendor "find requires select vendor on results upper artifact parameters     - x.x.x.x on the 2. 3. on obtain using key and paste domain, to (linux/windows) ip/domain/hash vendors linux save and (twitter, - the 1. and others string 1. from "find of a above characters vendor time virustotal, ids keys analysis—ips, os source sample also configuration using spaces (ip/domain/url/hash keys" of streamlines either and will to abuseipdb, parameters windows right-click information   of urls, fields be google): commands,   and each author steps: the to of retrieve single "ipconfig" from "passwd" objects to or and to the - suspicious and rcusmcapistrano/ abuseipdb be using click osx): commands (windows): 3. api intel from "kernel32.dll" show: files artifact side key syntax example, view into used query beyond—through use the 2. (windows) urlscan available the key to hybridanalysis the search command options able api as using selection, artifact entry documentation 3. select "rm" right keys. -o ip the upper be the gather twitter menu 4624 vendor domains, from user virustotal, ============================== show: cmdlets
Related