Malware Investigation Pipeline: From Honeypot to Threat Intel

No ratings

Presented at Hack.lu 2025 by

This lightning talk is about **MIP (Malware Investigation Pipeline)** - an automated forensic pipeline designed to extract threat intelligence from Cowrie honeypot snapshots. MIP leverages Dissect for forensic artifact extraction, integrates with VirusTotal to validate suspicious files, and publishes confirmed IOCs to MISP. By automating this process, MIP enables faster and more consistent generation of threat intelligence for collaborative defense. šŸ‘‰ https://github.com/andreia-oca/malware-investigation-pipeline