Path Lines of Code MANIFEST.in 8 azure-pipelines.yml 309 msticpy/__init__.py 13 msticpy/_version.py 1 msticpy/analysis/__init__.py 2 msticpy/analysis/anomalous_sequence/__init__.py 2 msticpy/analysis/anomalous_sequence/anomalous.py 72 msticpy/analysis/anomalous_sequence/model.py 418 msticpy/analysis/anomalous_sequence/sessionize.py 90 msticpy/analysis/anomalous_sequence/utils/__init__.py 2 msticpy/analysis/anomalous_sequence/utils/cmds_only.py 146 msticpy/analysis/anomalous_sequence/utils/cmds_params_only.py 210 msticpy/analysis/anomalous_sequence/utils/cmds_params_values.py 283 msticpy/analysis/anomalous_sequence/utils/data_structures.py 25 msticpy/analysis/anomalous_sequence/utils/laplace_smooth.py 49 msticpy/analysis/anomalous_sequence/utils/probabilities.py 66 msticpy/analysis/cluster_auditd.py 73 msticpy/analysis/eventcluster.py 311 msticpy/analysis/outliers.py 86 msticpy/analysis/timeseries.py 115 msticpy/common/__init__.py 1 msticpy/common/azure_auth.py 47 msticpy/common/azure_auth_core.py 211 msticpy/common/check_version.py 26 msticpy/common/cloud_mappings.py 40 msticpy/common/cred_wrapper.py 33 msticpy/common/exceptions.py 231 msticpy/common/keyvault_client.py 218 msticpy/common/keyvault_settings.py 108 msticpy/common/pkg_config.py 291 msticpy/common/provider_settings.py 139 msticpy/common/secret_settings.py 134 msticpy/common/timespan.py 98 msticpy/common/utility.py 283 msticpy/common/wsconfig.py 252 msticpy/config/__init__.py 3 msticpy/config/ce_azure.py 13 msticpy/config/ce_azure_sentinel.py 134 msticpy/config/ce_common.py 188 msticpy/config/ce_data_providers.py 81 msticpy/config/ce_keyvault.py 14 msticpy/config/ce_other_providers.py 14 msticpy/config/ce_provider_base.py 133 msticpy/config/ce_simple_settings.py 53 msticpy/config/ce_ti_providers.py 14 msticpy/config/ce_user_defaults.py 192 msticpy/config/comp_edit.py 226 msticpy/config/compound_ctrls.py 345 msticpy/config/file_browser.py 113 msticpy/config/mp_config_control.py 423 msticpy/config/mp_config_edit.py 126 msticpy/config/mp_config_file.py 241 msticpy/data/__init__.py 5 msticpy/data/azure/__init__.py 3 msticpy/data/azure/azure_blob_storage.py 138 msticpy/data/azure/azure_data.py 545 msticpy/data/azure/sentinel_analytics.py 151 msticpy/data/azure/sentinel_bookmarks.py 86 msticpy/data/azure/sentinel_core.py 113 msticpy/data/azure/sentinel_incidents.py 246 msticpy/data/azure/sentinel_utils.py 127 msticpy/data/azure/sentinel_watchlists.py 133 msticpy/data/azure_blob_storage.py 7 msticpy/data/azure_data.py 7 msticpy/data/azure_sentinel.py 7 msticpy/data/browsers/__init__.py 1 msticpy/data/browsers/mordor_browser.py 314 msticpy/data/browsers/query_browser.py 47 msticpy/data/data_obfus.py 270 msticpy/data/data_providers.py 335 msticpy/data/data_query_reader.py 48 msticpy/data/drivers/__init__.py 32 msticpy/data/drivers/driver_base.py 57 msticpy/data/drivers/kql_driver.py 328 msticpy/data/drivers/kusto_driver.py 167 msticpy/data/drivers/local_data_driver.py 76 msticpy/data/drivers/mdatp_driver.py 64 msticpy/data/drivers/mordor_driver.py 496 msticpy/data/drivers/odata_driver.py 182 msticpy/data/drivers/resource_graph_driver.py 101 msticpy/data/drivers/security_graph_driver.py 34 msticpy/data/drivers/splunk_driver.py 219 msticpy/data/drivers/sumologic_driver.py 293 msticpy/data/meta.yaml 16 msticpy/data/param_extractor.py 42 msticpy/data/queries/graph_alerts.yaml 185 msticpy/data/queries/kql_mdatp_alerts.yaml 94 msticpy/data/queries/kql_mdatp_file.yaml 70 msticpy/data/queries/kql_mdatp_hunting.yaml 509 msticpy/data/queries/kql_mdatp_network.yaml 94 msticpy/data/queries/kql_mdatp_process.yaml 82 msticpy/data/queries/kql_mdatp_user.yaml 78 msticpy/data/queries/kql_sent_alert.yaml 217 msticpy/data/queries/kql_sent_az_dns.yaml 82 msticpy/data/queries/kql_sent_az_network.yaml 83 msticpy/data/queries/kql_sent_azure.yaml 266 msticpy/data/queries/kql_sent_azuresentinel.yaml 167 msticpy/data/queries/kql_sent_heartbeat_info.yaml 74 msticpy/data/queries/kql_sent_lxauditd.yaml 51 msticpy/data/queries/kql_sent_lxsyslog_activity.yaml 115 msticpy/data/queries/kql_sent_lxsyslog_apps.yaml 70 msticpy/data/queries/kql_sent_lxsyslog_logon.yaml 312 msticpy/data/queries/kql_sent_net.yaml 211 msticpy/data/queries/kql_sent_o365.yaml 95 msticpy/data/queries/kql_sent_threatintel.yaml 173 msticpy/data/queries/kql_sent_timeseries.yaml 118 msticpy/data/queries/kql_sent_winevent.yaml 123 msticpy/data/queries/kql_sent_winevent_logon.yaml 226 msticpy/data/queries/kql_sent_winevent_proc.yaml 347 msticpy/data/queries/local_data.yaml 74 msticpy/data/queries/resource_graph_queries.yaml 112 msticpy/data/queries/splunk_alert_queries.yaml 69 msticpy/data/queries/splunk_authentication_queries.yaml 69 msticpy/data/queries/splunk_queries.yaml 90 msticpy/data/queries/sumologic_queries.yaml 49 msticpy/data/query_container.py 55 msticpy/data/query_defns.py 100 msticpy/data/query_source.py 294 msticpy/data/query_store.py 156 msticpy/data/sql_to_kql.py 456 msticpy/data/uploaders/__init__.py 8 msticpy/data/uploaders/loganalytics_uploader.py 120 msticpy/data/uploaders/splunk_uploader.py 156 msticpy/data/uploaders/uploader_base.py 21 msticpy/datamodel/__init__.py 1 msticpy/datamodel/entities/__init__.py 105 msticpy/datamodel/entities/account.py 115 msticpy/datamodel/entities/alert.py 214 msticpy/datamodel/entities/azure_resource.py 48 msticpy/datamodel/entities/cloud_application.py 28 msticpy/datamodel/entities/cloud_logon_session.py 42 msticpy/datamodel/entities/dns.py 31 msticpy/datamodel/entities/entity.py 325 msticpy/datamodel/entities/entity_enums.py 44 msticpy/datamodel/entities/entity_graph.py 31 msticpy/datamodel/entities/file.py 105 msticpy/datamodel/entities/file_hash.py 37 msticpy/datamodel/entities/geo_location.py 41 msticpy/datamodel/entities/graph_property.py 43 msticpy/datamodel/entities/host.py 76 msticpy/datamodel/entities/host_logon_session.py 53 msticpy/datamodel/entities/iot_device.py 50 msticpy/datamodel/entities/ip_address.py 54 msticpy/datamodel/entities/mail_cluster.py 68 msticpy/datamodel/entities/mail_message.py 104 msticpy/datamodel/entities/mailbox.py 46 msticpy/datamodel/entities/malware.py 34 msticpy/datamodel/entities/network_connection.py 41 msticpy/datamodel/entities/process.py 93 msticpy/datamodel/entities/registry_key.py 29 msticpy/datamodel/entities/registry_value.py 33 msticpy/datamodel/entities/security_group.py 28 msticpy/datamodel/entities/submission_mail.py 42 msticpy/datamodel/entities/threat_intelligence.py 34 msticpy/datamodel/entities/unknown_entity.py 23 msticpy/datamodel/entities/url.py 50 msticpy/datamodel/pivot.py 208 msticpy/datamodel/pivot_browser.py 180 msticpy/datamodel/pivot_data_queries.py 335 msticpy/datamodel/pivot_magic_core.py 94 msticpy/datamodel/pivot_pd_accessor.py 200 msticpy/datamodel/pivot_pipeline.py 163 msticpy/datamodel/pivot_register.py 263 msticpy/datamodel/pivot_register_reader.py 124 msticpy/datamodel/pivot_ti_provider.py 138 msticpy/datamodel/soc/__init__.py 1 msticpy/datamodel/soc/incident.py 107 msticpy/datamodel/txt_df_magic.py 9 msticpy/msticpyconfig.yaml 5 msticpy/nbtools/__init__.py 11 msticpy/nbtools/azure_ml_tools.py 199 msticpy/nbtools/data_viewer.py 392 msticpy/nbtools/entityschema.py 4 msticpy/nbtools/foliummap.py 273 msticpy/nbtools/morph_charts.py 85 msticpy/nbtools/nbdisplay.py 224 msticpy/nbtools/nbinit.py 508 msticpy/nbtools/nbwidgets/__init__.py 13 msticpy/nbtools/nbwidgets/core.py 77 msticpy/nbtools/nbwidgets/get_environment_key.py 61 msticpy/nbtools/nbwidgets/get_text.py 38 msticpy/nbtools/nbwidgets/lookback.py 64 msticpy/nbtools/nbwidgets/option_buttons.py 87 msticpy/nbtools/nbwidgets/progress.py 45 msticpy/nbtools/nbwidgets/query_time.py 228 msticpy/nbtools/nbwidgets/select_alert.py 189 msticpy/nbtools/nbwidgets/select_item.py 170 msticpy/nbtools/nbwidgets/select_subset.py 113 msticpy/nbtools/observationlist.py 69 msticpy/nbtools/process_tree.py 357 msticpy/nbtools/security_alert.py 137 msticpy/nbtools/security_alert_graph.py 239 msticpy/nbtools/security_base.py 307 msticpy/nbtools/security_event.py 63 msticpy/nbtools/ti_browser.py 120 msticpy/nbtools/timeline.py 693 msticpy/nbtools/timeline_duration.py 157 msticpy/nbtools/timeline_pd_accessor.py 35 msticpy/nbtools/timeseries.py 143 msticpy/nbtools/user_config.py 183 msticpy/nbtools/utility.py 8 msticpy/nbtools/wsconfig.py 7 msticpy/resources/mp_pivot_reg.yaml 160 msticpy/resources/mpconfig_defaults.yaml 168 msticpy/resources/obfuscation_cols.yaml 76 msticpy/sectools/__init__.py 13 msticpy/sectools/auditdextract.py 246 msticpy/sectools/base64unpack.py 449 msticpy/sectools/cmd_line.py 83 msticpy/sectools/domain_utils.py 175 msticpy/sectools/eventcluster.py 10 msticpy/sectools/geoip.py 488 msticpy/sectools/iocextract.py 264 msticpy/sectools/ip_utils.py 183 msticpy/sectools/proc_tree_build_mde.py 240 msticpy/sectools/proc_tree_build_winlx.py 237 msticpy/sectools/proc_tree_builder.py 97 msticpy/sectools/proc_tree_schema.py 173 msticpy/sectools/process_tree_utils.py 97 msticpy/sectools/sectools_magics.py 81 msticpy/sectools/syslog_utils.py 176 msticpy/sectools/tilookup.py 304 msticpy/sectools/tiproviders/__init__.py 24 msticpy/sectools/tiproviders/alienvault_otx.py 73 msticpy/sectools/tiproviders/azure_sent_byoti.py 78 msticpy/sectools/tiproviders/greynoise.py 56 msticpy/sectools/tiproviders/http_base.py 161 msticpy/sectools/tiproviders/ibm_xforce.py 106 msticpy/sectools/tiproviders/intsights.py 96 msticpy/sectools/tiproviders/kql_base.py 250 msticpy/sectools/tiproviders/open_page_rank.py 154 msticpy/sectools/tiproviders/riskiq.py 256 msticpy/sectools/tiproviders/ti_provider_base.py 334 msticpy/sectools/tiproviders/tor_exit_nodes.py 71 msticpy/sectools/tiproviders/virustotal.py 107 msticpy/sectools/vtlookup.py 429 msticpy/sectools/vtlookupv3/__init__.py 7 msticpy/sectools/vtlookupv3/vt_pivot.py 137 msticpy/sectools/vtlookupv3/vtfile_behavior.py 326 msticpy/sectools/vtlookupv3/vtlookupv3.py 543 msticpy/sectools/vtlookupv3/vtobject_browser.py 86 msticpy/vis/__init__.py 1 msticpy/vis/entity_graph_tools.py 287 msticpy/vis/matrix_plot.py 180 msticpy/vis/mp_pandas_plot.py 48 prospector.yml 27 pyproject.toml 6 setup.cfg 56 setup.py 53 tools/analyze_imports.py 117 tools/check_latest_ver.py 15 tools/comp_reqs.py 47 tools/config2kv.py 256 tools/create_reqs_all.py 147 tools/misc/chk_pkgs.py 86 tools/mp_demo_data.py 135 tools/mp_test_extras.py 129 tools/print_call_tree.py 31 tools/toollib/__init__.py 12 tools/toollib/ast_parser.py 56 tools/toollib/import_analyzer.py 223 tools/toollib/module_tree.py 82 tools/toollib/url_checker.py 220 tools/toollib/url_checker_async.py 123