Skip to content

Mr-Tree-S/BTAS

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

81 Commits
 
 
 
 
 
 

Repository files navigation

BTAS

Blue Team Auxiliary Script

BTAS is a browser auxiliary script developed for Security Operations Center (SOC) analysts, designed to fully simplify workflows and significantly enhance efficiency. The script runs on the Tampermonkey extension and integrates multiple practical functions, including rapid response, threat intelligence search, log parsing, and automation, greatly improving the efficiency of analysts.

Function Introduction

Main Features

  1. Quick Reply: Include many reply templates for common scenarios, supports one-click quick replies, and allows for custom reply content.
  2. Convenience Menu: Integrates shortcuts for commonly used tools such as JIRA Search, VirusTotal, AbuseIPDB, and Base64 decoding.
  3. Anomaly Detection: Detects based on keyword rules and more than abnormal behaviors, improving analysis accuracy and ensuring no major security alerts are missed.
  4. Log Parsing: Supports parsing log formats from mainstream security and cloud products (e.g., Cortex XDR, Microsoft Endpoint Defender, and Azure Cloud). It quickly parses raw logs and generates alert description; it also integrates a one-click jump function to security platforms.
  5. Prompt Sound Notification: Monitors ticket lists in real-time and plays a notification sound for new or updated tickets.
  6. Ticket Tracking: Provides visual reminders for tickets that have not been processed or responded to for a long time.
  7. Reminders: Analysts will be prompted with relevant information when opening specific ticket pages, including customer requirements and SOPs, guiding standardized operations.

Contributions

Barry, Jack, Xingyu, Mike

License

License: MIT

About

Blue Team Auxiliary Script

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published