Skip to content

kevthehermit/PasteHunter

master
Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
Code

Files

Permalink
Failed to load latest commit information.
Type
Name
Latest commit message
Commit time
November 14, 2020 22:21
December 2, 2020 22:41
December 12, 2020 11:11
January 16, 2020 20:09
November 22, 2020 23:53
December 2, 2020 22:41
September 3, 2017 11:56
November 14, 2020 22:21
November 22, 2020 23:53
September 3, 2019 14:40
December 12, 2020 17:43

PasteHunter

PasteHunter is a python3 application that is designed to query a collection of sites that host publicly pasted data. For all the pastes it finds it scans the raw contents against a series of Yara rules looking for information that can be used by an organisation or a researcher.

Setup

For setup instructions please see the official documentation https://pastehunter.readthedocs.io/en/latest/installation.html

PyPI version

Build Status

Supported Inputs

Pastehunter currently has support for the following sites:

  • pastebin.com
  • gist.github.com # Gists
  • github.com # Public commit activity feed
  • slexy.org
  • stackexchange # There are about 176!

Supported Outputs

Pastehunter supports several output modules:

  • dump to ElasticSearch DB (default).
  • Email alerts (SMTP).
  • Slack Channel notifications.
  • Dump to JSON file.
  • Dump to CSV file.
  • Send to syslog.
  • POST to URL

Supported Sandboxes

Pastehunter supports several sandboxes that decoded data can be sent to:

  • Cuckoo
  • Viper

For examples of data discovered using pastehunter check out my posts https://techanarchy.net/blog/hunting-pastebin-with-pastehunter and https://techanarchy.net/blog/pastehunter-the-results