msticpy
latest
  • Getting Started
  • Querying and Importing Data
  • Enriching Data
  • Analyzing Data
    • Base64 Decoding and Unpacking
    • IoC Extraction
    • Event Clustering
    • Anomalous Sessions
    • Pivot Functions
  • Displaying/Visualizing Data
  • msticpy API
  • Notebook Examples
  • Articles, Labs and other Resources
  • Releases
  • Contributing
  • License
msticpy
  • Analyzing Data
  • Edit on GitHub

Analyzing Data

  • Base64 Decoding and Unpacking
    • Base64 decode an input string
    • Using a DataFrame as input
    • Interpreting the DataFrame output
    • Decoding Nested Base64/Archives
    • IPython magic
    • Pandas Extension
  • IoC Extraction
    • Looking for IoC in a String
    • Using a DataFrame as Input
    • IoCExtractor API
    • Predefined Regex Patterns
    • Adding your own pattern(s)
    • Merging output with source data
    • IPython magic
    • Pandas Extension
  • Event Clustering
    • Processes on Host - Clustering
    • Host Logons
  • Anomalous Sessions
    • Creating the Sessions
    • Model the sessions
    • Visualise the Modelled Sessions
    • Other Log Types + KQL
  • Pivot Functions
    • What are Pivot Functions?
    • Sample notebooks
    • Changes in V2.0.0
    • What is “Pivoting”?
    • Getting started
    • Running a pivot function
    • Data query pivot functions
    • Threat Intelligence lookups
    • Pandas processing pipeline with pivot functions
    • Customizing and managing Pivots
Previous Next

© Copyright 2019, (c) Microsoft Corporation.. Revision 941145e1.

Built with Sphinx using a theme provided by Read the Docs.
Read the Docs v: latest
Versions
latest
stable
v2.0.0.rc1
v1.8.0
v1.7.5
v1.7.0
v1.6.1
v1.5.0
v1.4.0
v1.3.0
v1.2.1
v1.1.0
v1.0.0
release-msticpy-v2.0.0
Downloads
On Read the Docs
Project Home
Builds