msticpy Profile Banner
msticpy Profile
msticpy

@msticpy

Followers
851
Following
36
Media
24
Statuses
199

#msticpy is an open source library for InfoSec investigation and hunting in #Jupyter Notebooks and #Python.

Joined January 2022
Don't wanna be here? Send us removal request.
@msticpy
msticpy
1 year
MSTICPy 2.11.0 released This minor release includes: - Better handling of large/split queries for MS Sentinel - Updated support for installing MSTICPy in a Conda environment - Updates for future pandas support https://t.co/zLO8aoOiHC
Tweet media one
0
6
10
@msticpy
msticpy
2 years
thx to contributors @PeteABryan Joey Dreyer, Chis Cianelli, Florian Bracq and 2xyo
1
0
1
@msticpy
msticpy
2 years
MSTICPY 2.9.0 released Includes new Threat Intel provider IPQualityScore and updated M365D to use MS Graph API for hunting queries. Fixes to startup, Synapse compat issues, Entities and more. See the release notes for a full rundown https://t.co/s4nJozQS75
Tweet media one
2
9
21
@msticpy
msticpy
2 years
MSTICPy v2.8.0 released. Stability release - with several important fixes: - MS Sentinel failure when connecting using a connection string - Using supported method for multi-cloud Azure endpoints - Using msticpy in isolated environments.
0
1
7
@msticpy
msticpy
2 years
MSTICPy 2.7.0 release - 2 new threat intel providers for CrowdSec and AbuseIPDB - New MS Sentinel and Kusto drivers now the defaults - Query file editor for MSTICPy template queries - Azure auth fixes for MicrosoftSentinel More details https://t.co/M8Tn0QuC8f
Tweet media one
0
8
22
@fr0gger_
Thomas Roccia 🤘
2 years
@T_8ase is going to present about @msticpy at the SANS DFIR Japan, check this out if you are around 🤩 Cc: @ianhellen
@SANS_JAPAN
SANS Japan
2 years
9月7日と8日開催のSANS APAC DFIR Summitのアジェンダが公開されました!長谷川達也さんは「msticpyの実践活用: 高度な脅威ハンティングを実現すべくSIEMとの虹の懸け橋となる」と題して講演します! msticpyの機能紹介を説明し、msticpyとSIEMの活用について紹介します。 https://t.co/k0yxx9abig
Tweet media one
1
2
3
@msticpy
msticpy
2 years
MSTICPy 2.6.0 released - Parallel queries for multiple instances of MS Sentinel workspaces and Kusto clusters - Parallel split queries (large time-range queries divided by smaller time periods) - Velociraptor data provider for querying exported data sets https://t.co/tL511uP82x
Tweet media one
0
11
22
@msticpy
msticpy
2 years
... continued * Panel tabulator now supported as default data viewer (see https://t.co/YwvJyAzdiT) These are described more fully in the release notes and (mostly) in the updated docs
0
0
1
@msticpy
msticpy
2 years
MSTICPy 2.5.0 released * New Sentinel and Kusto drivers with parallel queries, proxy and user-defined timeouts. * Plugin framework for MSTICPy data/TI/context providers * Import Sentinel hunting and detection queries * OSQuery data provider ... https://t.co/LBaT0JLqt3
Tweet card summary image
github.com
Summary of main changes New MS Sentinel and Azure Kusto drivers/data providers - these include support for multi-threaded parallel queries, proxies and user-defined query timeouts. Extensibility m...
1
1
5
@ianhellen
Ian Hellen
2 years
Had a report that the search in MSTICPy ReadtheDocs was broken (apparently broken for a while due to a bug in the ReadTheDocs template. Happy to report that this is now fixed. https://t.co/3968jFgEGk
Tweet media one
0
1
5
@msticpy
msticpy
2 years
🚨 #MSTICPy has just merged a new PR to main! ashwin-patil added the PR - Read the docs update for Managed spark installation https://t.co/PSHzUYb2yI #python #MSTIC #infosec
Tweet card summary image
github.com
added section under Installing for how to install in managed spark compute in AML
0
0
2
@msticpy
msticpy
2 years
MSTICPy v2.4.0 released - New Pulsedrive TI module - Process tree updates (inc FireEye HX compat) - Bokeh 3.0 support - Improved diagnostics/logging - Fixes to Azure auth, Sentinel APIs and more. https://t.co/adgS3yHBDL
Tweet card summary image
github.com
Main changes for this release There are no huge changes in this release but a good variety of important updates and fixes. We're also delighted to welcome 3 new contributors to the MSTICPy fami...
0
5
14
@msticpy
msticpy
2 years
🚨 #MSTICPy has just merged a new PR to main! ianhelle added the PR - Reverting to bokeh version 2.4.3 for default install https://t.co/5HyFdrudgn #python #MSTIC #infosec
Tweet card summary image
github.com
Replacing NAs in process_tree DF - causes Bokeh 3.0 to fail
0
1
1
@msticpy
msticpy
2 years
🚨 #MSTICPy has just merged a new PR to main! ianhelle added the PR - Adding data query paths test for DEX support https://t.co/lRILFa8E3q #python #MSTIC #infosec
Tweet card summary image
github.com
MyPy suppressions for some uses of ProviderSettings and PivotRegistration classes.
0
0
0
@msticpy
msticpy
3 years
MSTICPy release 2.3.1 - Hide progress bar with TILookup - init_notebook works offline or in air-gapped env - some important Azure/Sentinel/AzureML fixes Now on PyPI https://t.co/OHDnrkTl66 Read the goodness in the rel notes: https://t.co/Y2OHFHxDu1 #msticpy #CyberSec #Jupyter
Tweet card summary image
github.com
This is minor release with mostly fixes. Some higlights from the #631 PR #629 - You can now suppress progress bar for Threat Intel lookups (useful to avoid screen mess when running multiple lookups...
0
3
10