Columnar storage for STIX 2.0 observations.


Keywords
stix, stix-shifter, sql, python, hacktoberfest, stix2, threat-hunting, threat-intelligence
License
Apache-2.0
Install
pip install firepit==2.3.17

Documentation

Firepit - STIX Columnar Storage

image

Documentation Status

Unit Test Status

image

Columnar storage for STIX 2.0 observations.

Features

  • Transforms STIX Observation SDOs to a columnar format
  • Inserts those transformed observations into SQL (currently sqlite3 and PostgreSQL)

Motivation

STIX 2.0 JSON is a graph-like data format. There aren't many popular tools for working with graph-like data, but there are numerous tools for working with data from SQL databases. Firepit attempts to make those tools usable with STIX data obtained from stix-shifter.

Firepit also supports STIX 2.1

Firepit is primarily designed for use with the Kestrel Threat Hunting Language.

Credits

This package was created with Cookiecutter and the audreyr/cookiecutter-pypackage project template.