An Elasticsearch-based toolkit that our team uses for large-scale processing, analysis and visualization of e-crime records. In particular, we've successfully been applying DefPloreX to the analysis of deface records (e.g., from web compromises); hence its name, Def(acement) eXPlorer (DefPloreX).
The full version of DefPloreX includes:
The input to DefPloreX is a feed of URLs describing the deface web pages, including metadata such as the (declared) attacker name, timestamp, reason for hacking that page, and so on. Separately, we also have a mirror of the web pages at the time of compromise.
https://github.com/trendmicro/defplorex
Federico Maggi - Trend Micro https://github.com/phretor Marco Balduzzi - Trend Micro https://github.com/embyte Vincenzo Ciancaglini - Trend Micro Lion Gu - Trend Micro Ryan Flores - Trend Micro