33. Tools for Event Analysis
This list of tools will help you with your event analysis.
33.3. APT Custom Search
33.4. Hybrid Analysis
33.6. Automatic Hash Checks
You can use the Python script
munin.py to batch process lists of Hash values or even complete THOR log files as the script automatically extracts the relevant values from each line.
The best option is to use the
*.csv files produced after a THOR run and use them as input for the script.
user@unix~:$ cat *.csv >> all-hashes.csv user@unix~:$ python munin.py –i config.ini –f all-hashes.csv