This repository contains a collection of notebooks that can be used to manipulate the LANL Unified Host and Network Dataset. Note that Trovares has prepared a version of this data ready for the xGT analytics tool.
-
Lateral Movement is an example of searching for evidence of lateral movement within an enterprise network
-
Insider Threat Detection is an example of looking for a pattern of an insider exfiltrating sensitive information to an external destination
This project is licensed under the Apache License 2.0 - see the LICENSE file for details.