The security-cli is a CLI (and package) Python utility to perform common activities performed by security analysts.
security-cli main goal is to provide a standard interface for performing data enrichment, querying, lookups, scanning and more in a simple and straightforward CLI interface.
Features
The security-cli Python package and CLI tool to assist with abstracting third-party products from the different actions needing to be performed by a security analyst on a frequent basis.
Currently, the features are limited but the groundwork has been laid for many future improvements based on community feedback.
- Performs observable enrichment (enrich)
- Configuration (and environmental variables) driven mappings of actions, observable types and the different supported services
This is just the start of this project so it is limited in capabilities as I continue to build them out. That being said, the goal is the same; a simple and usable interface to perform common security operations activities.
For example, most APIs are overly complex and some even require multiple API calls to perform an action or gathering the correct data. security-cli provides a simple nomenclature based on common verbs within the security domain.
Supported Services
The following services and observable types are currently supported:
If you have any suggestions or believe another service should be implemented, please create an issue or pull request!
| Name | API Key Required | Supports IP | Supports Domain | Supports URL | Supports Email |
|---|---|---|---|---|---|
| VirusTotal | Yes | Yes | Yes | Yes | No |
| HybridAnalysis | Yes | Yes | Yes | Yes | No |
| AlienVault | Yes | Yes | Yes | Yes | No |
| Shodan | Yes | Yes | Yes | Yes | No |
| Urlscan.io | Yes | Yes | Yes | Yes | No |
| AbuseIPDB | Yes | Yes | No | No | No |
| HaveIBeenPwned | Yes | No | No | No | Yes |