Skip to content

Instantly share code, notes, and snippets.

@cynguk
cynguk / Decoder
Created September 25, 2023 18:48
Enhancing Cybersecurity with Wazuh Decoders in Blue Team Operations
<decoder name="comodoparent">
<prematch>CEF:0\|comodo</prematch>
</decoder>
<decoder name="comodomalwaredetection">
<parent>comodoparent</parent>
<use_own_name>true</use_own_name>
<prematch>Malware Detected\|10</prematch>
<regex type="pcre2">CEF:0\|comodo\|cis\.ccs\|[^\|]+\|[^\|]+\|Malware Detected\|[^\|]+\|filePath=([^\s]+) fname=[^\s]+ act=([^\s]+) reason=[^\s]+ cat=[^\s]+ cs1Label=[^\s]+ cs1=[^\s]+ cs2Label=[^\s]+ cs2=[^\s]+ cs4Label=[^\s]+ cs4=[^\s]+ suser=[^\s]+ spriv=[^\s]+ deviceNtDomain=[^\s]+ ssid=[^\s]+ fileHash=([^\s]+) dvchost=([^\s]+) dvc=[^\s]+ deviceExternalId=[^\s]+</regex>
<order>filePath, act, filehash, dvchost</order>
@cynguk
cynguk / o365bruteforce
Last active September 25, 2023 18:48
Analysing Office365 Failed Login Alerts with Python
import re
import pyperclip
import requests
from bs4 import BeautifulSoup
API_KEY = "redacted"
def analyse_log(log):
log_data = {}