Skip to content

MITRECND/chopshop

Folders and files

NameName
Last commit message
Last commit date

Latest commit

8bdd393 · Dec 19, 2022
Mar 27, 2017
Dec 19, 2022
Nov 19, 2021
Dec 19, 2022
Oct 24, 2018
Feb 12, 2016
Feb 19, 2014
Mar 16, 2018
Mar 28, 2017
Feb 2, 2016
Mar 1, 2016
Jan 6, 2015
Feb 19, 2014
Feb 10, 2016
Jan 21, 2016
Feb 19, 2014

Repository files navigation

ChopShop 4

Protocol Analysis/Decoder Framework

Description

ChopShop is a MITRE developed framework to aid analysts in the creation and execution of pynids based decoders and detectors of APT tradecraft.

Note that ChopShop is still in perpetual beta and is dependent on libnids/pynids for the majority of its underlying functionality.

Documentation for ChopShop can be found on ReadTheDocs.

Note: There is a known issue when running ChopShop on Ubuntu where the version of pynids obtained via apt causes an ImportError. Per https://bugs.launchpad.net/ubuntu/+source/python-nids/+bug/795991, this issue affects some variants of at least 11.10 and 12.04. A workaround is to compile pynids from source which can be obtained from https://github.com/MITRECND/pynids/.