SOCMaster

mgodnpglndjnfpddlamphecaheodnafc

Get info on OS Commands, IPs, Domains, URLs, Hashes, Windows Events and Registry keys, Strings, and Files with one click. In-browser threat intelligence companion that streamlines artifact analysis—IPs, domains, URLs, and beyond—through one-click lookups across leading security vendors. SOCMaster integrates with leading threat intelligence platforms such as VirusTotal, AbuseIPDB, and others, allowing users to swiftly transform data into actionable insights. 1. From the web browser, select or highlight an artifact and right-click 3. Click one of the options available 4. Menu will appear on lower right side containing information on the artifacts Bulk lookups --allows you to quickly assess multiple artifacts at once, saving time during intensive investigations. 1. From the web browser, gather a list of either IP addresses, Domains, URLs, File Hashes, File Names. Each entry separated by new line or spaces For example: 2. Highlight all of the objects to be scanned, right-click, and select "SOCMaster" 3. Click one of the options available (IP/Domain/URL/Hash scan using vendor API keys or Get file (Linux/Windows) information) - Uses Threat intelligence vendors such as AbuseIPDB, VirusTotal, AlienVaultOTX, HybridAnalysis and others to obtain the reputation and information on an IP address, Domain, Hash. Data available is dependent on the vendor. - Submits URLs to URLscan.io, VirusTotal, AlienVault, HybridAnalysis and others for analysis using API keys. - Click the vendor link to view the URL scan result. - Get information on over 3,300 Powershell cmdlets from Powershell modules, almost all Linux commands (Man Sections 1-8), Windows commands, and OSX commands. - Shows information on Operating System binaries and commands. For example, Windows commands such as "ipconfig" or "tasklist", "Set-ExecutionPolicy" for Powershell, and "rm" for Linux. - Retrieve information on known files such as "kernel32.dll" for Windows or "passwd" for Linux. To query an IP, Domain, and Hash using vendor API keys, an API key is required. Follow the steps: 2. Click the "SOCMaster" icon > Settings 3. On the settings page, on the upper right corner click "Add API key" 5. Paste vendor API key on the API key field A user can highlight the above command and select the "Find command information" option and will be able to view the syntax and parameters of the command. 2. Suspicious IP address from the firewall logs: x.x.x.x A user can highlight the IP and select the "IP scan using vendor API keys" option and will be able to view IP reputation and data from vendors. A user can highlight the above command and select the "Find command information" option and will be able to view the syntax and parameters of the command. 4. Windows Event IDs on the SIEM show: eventID 4624 A user can highlight the event ID number and select the "Get event ID information" option and will be able to view the fields and description of the Windows event Supports the following vendors: VirusTotal AbuseIPDB AlienVaultOTX Twitter URLscan HybridAnalysis GoogleSearch Pulsedive

Related extensions