shellcromancer / cti-go

Go tooling for Cyber Threat Intel programs

Repository from Github https://github.comshellcromancer/cti-goRepository from Github https://github.comshellcromancer/cti-go

Cyber Threat Intel - Go libraries

Set a libraries to interact with CTI datasets. Lots of the functionality here exists in various python libraries but most Golang versions seem to be for older versions of the CTI "standards".

Future Work

Exchange Protocols

  • TAXII 1.1 (Support legacy intergrations)

Data Formats

  • STIX 1.X
  • STIX 2.X
  • OpenIOC (?)
  • CAPEC 3.X
  • D3FEND 0.X (?)
  • MAEC (?)
  • RSS (?)

CLI Features

  • EclecticIQ/Cabby feature parity
  • Warning on TLP:AMBER+ data views

Library Features

  • Classify observable types
  • Defang observables
  • Refang observables

References

  1. TAXII 1.X
  2. TAXII 2.X
  3. STIX 1.X
  4. STIX 2.X
  5. CAPEC

About

Go tooling for Cyber Threat Intel programs


Languages

Language:Go 100.0%