
SOCアナリスト向けのオールインワンCLIツールで、ワークフローを自動化・高速化します。

Sootyは、SOCアナリストのワークフローの一部を自動化するために開発されたツールです。Sootyの目標の1つは、可能な限り多くのルーチンチェックを実行し、アナリストが同じ時間枠内でより深い分析に費やす時間を増やすことです。Sootyの多くの機能の詳細は以下をご覧ください。
Sootyは現在、Tines.comによってサポートされています!エンタープライズセキュリティチーム向けSOARプラットフォームです。

└── Main Menu
├── Sanitize URL's for use in emails
| └── URL Sanitizing Tool
├── Decoders
| ├── ProofPoint Decoder
| ├── URL Decoder
| ├── Office Safelinks Decoder
| ├── URL Unshortener
| ├── Base 64 Decoder
| ├── Cisco Password 7 Decoder
| └── Unfurl URL
├── Reputation Checker
| └── Reputation Checker for IP's, URL's or email addresses
├── DNS Tools
| ├── Reverse DNS Lookup
| ├── DNS Lookup
| └── WhoIs Lookup
├── Hashing Functions
| ├── Hash a File
| ├── Hash a Text Input
| ├── Check a hash for known malicious activity
| └── Hash a file and check for known malicious activity
├── Phishing Analysis
| ├── Analyze an Email
| ├── Analyze an email address for known malicious activity
| ├── Generate an email template based on analysis
| ├── Analyze a URL with Phishtank
| └── HaveIBeenPwned Lookup
├── URL Scan
| └── URLScan.io lookup
├── Extra's
| ├── About
| ├── Contributors
| ├── Version
| ├── Wiki
| └── Github Repo
└── Exit

pip install -r requirements.txtpython Sooty.pyまたは単にSooty.pyを実行してツールを起動します。example_config.yamlファイル内の対応するキーを置き換え、ファイル名をconfig.yamlに変更します。レイアウト例は以下のとおりです:config.yamlファイルを一意の名前で更新してください。
