How to create and maintain Jupyter threat hunting notebooks
ID: 737a415d-f825-5cd2-9238-d6d5d00b7d5a
STIX ID: report--737a415d-f825-5cd2-9238-d6d5d00b7d5a
Feed Name: Expel Blog
This post explains Expel's framework for generating and managing Jupyter-based threat-hunting notebooks: analysts author YAML configuration files which a Python `nbformat`-based builder (`notebook_builder.py`) uses to create standardized notebooks, leveraging Docker for reproducible builds, modular "downselects" for enrichment and analysis, and optional CI/CD integration so notebooks can be rebuilt automatically—enabling SOC analysts to develop hunts without needing deep Python expertise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
