logo

How to create and maintain Jupyter threat hunting notebooks

ID: 737a415d-f825-5cd2-9238-d6d5d00b7d5a

STIX ID: report--737a415d-f825-5cd2-9238-d6d5d00b7d5a

Feed Name: Expel Blog

Date Published: 2020-06-16

Date Updated: 2026-04-27

Author: Andrew Pritchett

...
...

This post explains Expel's framework for generating and managing Jupyter-based threat-hunting notebooks: analysts author YAML configuration files which a Python `nbformat`-based builder (`notebook_builder.py`) uses to create standardized notebooks, leveraging Docker for reproducible builds, modular "downselects" for enrichment and analysis, and optional CI/CD integration so notebooks can be rebuilt automatically—enabling SOC analysts to develop hunts without needing deep Python expertise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.