Protocol Analysis/Decoder Framework
Python JavaScript Makefile Other
Latest commit 1ce433c Apr 21, 2016 @Mraoul Mraoul If ChopStdout encounters a broken pipe, instead of just informing the…
… user, attempt to gracefully shutdown the lib and the ui
Permalink
Failed to load latest commit information.
docker Updates to docker markdown file Sep 17, 2015
docs Apparently ChopUi never passed in the stop functions to all of the ha… Apr 21, 2016
ext_libs Don't pass type here. Sep 15, 2015
modules Added more error checking to http.py also added a new flag (-s) to su… Jan 26, 2016
shop If ChopStdout encounters a broken pipe, instead of just informing the… Apr 21, 2016
tests Add tests for pipe behavior Feb 12, 2016
webroot
.gitignore Ignore coverage data in git Feb 12, 2016
Dockerfile Update dockerfile -- use debian python-m2crypto instead of python pac… Jan 13, 2016
Makefile Make Makefile dependency-check output more readable. Feb 2, 2016
README.md Move development/testing information from README to the docs. Mar 1, 2016
chopshop Modified how CHOPSHOP_WD constant is handled, fixes #47 Jan 6, 2015
chopweb Bump copyright to 2014 and prepare for 4.0. Feb 19, 2014
dev-requirements.txt Add coverage to dev-requirements Feb 10, 2016
newmod.sh Move module documentation to RST format. Jan 21, 2016
suture Bump copyright to 2014 and prepare for 4.0. Feb 19, 2014

README.md

ChopShop 4

Protocol Analysis/Decoder Framework

Description

ChopShop is a MITRE developed framework to aid analysts in the creation and execution of pynids based decoders and detectors of APT tradecraft.

Note that ChopShop is still in perpetual beta and is dependent on libnids/pynids for the majority of its underlying functionality.

Documentation for ChopShop can be found on ReadTheDocs.

Note: There is a known issue when running ChopShop on Ubuntu where the version of pynids obtained via apt causes an ImportError. Per https://bugs.launchpad.net/ubuntu/+source/python-nids/+bug/795991, this issue affects some variants of at least 11.10 and 12.04. A workaround is to compile pynids from source which can be obtained from https://github.com/MITRECND/pynids/.