<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Services on CIRCL</title>
		<link>https://www.circl.lu/services/</link>
		<description>Recent content in Services on CIRCL</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<atom:link href="https://www.circl.lu/services/rss.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Pandora Document and File Analysis</title>
				<link>https://www.circl.lu/services/pandora-document-analysis/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/pandora-document-analysis/</guid>
				<description>&lt;h2 id=&#34;pandora-document-and-file-analysis&#34;&gt;Pandora Document and File Analysis&lt;/h2&gt;&#xA;&lt;img src=&#34;https://pandora.circl.lu/static/images/logo-h.svg&#34;  width=&#34;30%&#34; height=&#34;30%&#34;/&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://pandora.circl.lu/&#34;&gt;Pandora&lt;/a&gt; is an analysis framework designed to determine if a file is suspicious, conveniently displaying the results. Pandora provides a user-friendly content preview interface for large documents, including a preview of the metadata. This allows users to view files without the need to open them locally.&lt;/p&gt;&#xA;&lt;p&gt;Pandora performs static analysis and is the recommended service for documents&#xA;and other binaries. For dynamic analysis of Linux-based malware, use &lt;a href=&#34;https://www.circl.lu/services/kunai-sandbox/&#34;&gt;Kunai&#xA;Sandbox&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Passive DNS</title>
				<link>https://www.circl.lu/services/passive-dns/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/passive-dns/</guid>
				<description>&lt;h2 id=&#34;passive-dns-version-20&#34;&gt;Passive DNS version 2.0&lt;/h2&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.circl.lu/assets/images/logos/passivedns.png&#34; alt=&#34;CIRCL Passive DNS&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;CIRCL Passive DNS is a database that stores historical DNS records from various resources, including malware analysis and partners. The DNS historical data is indexed, making it searchable for incident handlers, security analysts, or researchers.&lt;/p&gt;&#xA;&lt;p&gt;In November 2023, CIRCL released version 2.0 of its Passive DNS service. The new version is backward-compatible with the previous 1.0 version. The output format remains &lt;a href=&#34;https://datatracker.ietf.org/doc/html/draft-dulaunoy-dnsop-passive-dns-cof&#34;&gt;Passive DNS - Common Output Format&lt;/a&gt;, and the query interface is similar. New headers were introduced to support some new functionalities, including filtering and pagination. If no headers are set, the Passive DNS API falls back to the previous 1.0 version&amp;rsquo;s behavior.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Vulnerability-Lookup Service</title>
				<link>https://www.circl.lu/services/cve-search/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/cve-search/</guid>
				<description>&lt;h2 id=&#34;multi-source-vulnerability-lookup-and-collaboration&#34;&gt;Multi-Source Vulnerability-Lookup and Collaboration&lt;/h2&gt;&#xA;&lt;p&gt;Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure (CVD).&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.circl.lu/assets/images/logos/vulnerability-lookup-logo.png&#34; alt=&#34;Vulnerability-Lookup logo&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://vulnerability.circl.lu&#34;&gt;Vulnerability-Lookup&lt;/a&gt; is accessible via a web interface, RSS/Atom and an HTTP API.&#xA;Vulnerability-Lookup is an interface to search publicly known information from security vulnerabilities in software and hardware along with their corresponding exposures.&#xA;You can also register and collaborate on the vulnerability intelligence by adding comments or even reporting vulnerabilities.&lt;/p&gt;</description>
			</item>
			<item>
				<title>BGP Ranking</title>
				<link>https://www.circl.lu/services/bgp-ranking/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/bgp-ranking/</guid>
				<description>&lt;p&gt;&lt;img src=&#34;https://www.circl.lu/assets/images/logos/bgpranking.png&#34; alt=&#34;CIRCL BGP Ranking&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;BGP Ranking is a public service operated by CIRCL that gathers external security&#xA;data to calculate the security ranking of Internet service providers. It helps&#xA;analysts identify malicious activity associated with an autonomous system (AS)&#xA;and follow its ranking over time.&lt;/p&gt;&#xA;&lt;h2 id=&#34;use-bgp-ranking&#34;&gt;Use BGP Ranking&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://bgpranking.circl.lu/&#34;&gt;Open the public BGP Ranking service&lt;/a&gt; to explore&#xA;autonomous-system rankings.&lt;/li&gt;&#xA;&lt;li&gt;Consult the &lt;a href=&#34;https://www.circl.lu/projects/bgpranking/&#34;&gt;BGP Ranking documentation&lt;/a&gt; for the JSON&#xA;API and Python client.&lt;/li&gt;&#xA;&lt;li&gt;Browse the &lt;a href=&#34;https://github.com/D4-project/BGP-Ranking&#34;&gt;source code&lt;/a&gt; to learn&#xA;about the software or contribute.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For historical IP address announcements, see CIRCL&amp;rsquo;s&#xA;&lt;a href=&#34;https://www.circl.lu/services/ip-asn-history/&#34;&gt;IP to ASN Mapping Whois Service&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>CIRCL hashlookup</title>
				<link>https://www.circl.lu/services/hashlookup/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/hashlookup/</guid>
				<description>&lt;h2 id=&#34;circl-hashlookup-hashlookupcircllu&#34;&gt;CIRCL hashlookup (hashlookup.circl.lu)&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://hashlookup.circl.lu/&#34;&gt;CIRCL hashlookup&lt;/a&gt; is a public API for looking up file hashes in known-file databases. It includes the NSRL Reference Data Set (RDS) and several other data sources. The service is available through an HTTP REST API, which is documented using an &lt;a href=&#34;https://hashlookup.circl.lu/swagger.json&#34;&gt;OpenAPI specification&lt;/a&gt;. It is free to use and provided on a best-effort basis.&lt;/p&gt;&#xA;&lt;h1 id=&#34;sources-included-in-circl-hashlookup&#34;&gt;Sources included in CIRCL hashlookup&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Common Windows 10 and Windows 11 builds (French, Dutch, German, UK, and US)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.nist.gov/itl/ssd/software-quality-group/national-software-reference-library-nsrl&#34;&gt;NIST NSRL&lt;/a&gt; - All RDS hash sets, including current, modern, Android, iOS, and legacy sets, with SHA-256 mappings&lt;/li&gt;&#xA;&lt;li&gt;Ubuntu distribution packages&lt;/li&gt;&#xA;&lt;li&gt;CentOS core operating system distribution&lt;/li&gt;&#xA;&lt;li&gt;Fedora Project EPEL repository&lt;/li&gt;&#xA;&lt;li&gt;Kali Linux distribution packages&lt;/li&gt;&#xA;&lt;li&gt;openSUSE distribution packages&lt;/li&gt;&#xA;&lt;li&gt;OpenBSD binary tar.gz archives&lt;/li&gt;&#xA;&lt;li&gt;CDNJS&lt;/li&gt;&#xA;&lt;li&gt;Snap public repository&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h1 id=&#34;is-this-a-database-of-malicious-or-non-malicious-file-hashes&#34;&gt;Is this a database of malicious or non-malicious file hashes?&lt;/h1&gt;&#xA;&lt;p&gt;The CIRCL hashlookup service only provides details about known files that appear in one or more of its source databases. These details provide context for file hashes encountered during investigations or digital forensic analysis. A match does not, by itself, indicate whether a file is malicious.&lt;/p&gt;</description>
			</item>
			<item>
				<title>MISP - Open Source Threat Intelligence Platform</title>
				<link>https://www.circl.lu/services/misp-malware-information-sharing-platform/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/misp-malware-information-sharing-platform/</guid>
				<description>&lt;section class=&#34;misp-hero&#34; aria-labelledby=&#34;misp-hero-title&#34;&gt;&#xA;  &lt;div class=&#34;misp-hero-copy&#34;&gt;&#xA;    &lt;p class=&#34;misp-eyebrow&#34;&gt;CIRCL-operated sharing communities&lt;/p&gt;&#xA;    &lt;h2 id=&#34;misp-hero-title&#34;&gt;Turn threat information into collective defence&lt;/h2&gt;&#xA;    &lt;p&gt;MISP is an open-source threat intelligence and sharing platform. It gives analysts, incident responders and automated security tools a common, structured way to collect, enrich, correlate and exchange knowledge about threats.&lt;/p&gt;&#xA;    &lt;div class=&#34;misp-actions&#34;&gt;&#xA;      &lt;a class=&#34;button misp-button-primary&#34; href=&#34;https://www.circl.lu/contact/&#34;&gt;Request community access&lt;/a&gt;&#xA;      &lt;a class=&#34;button misp-button-secondary&#34; href=&#34;https://www.misp-project.org/&#34;&gt;Explore the MISP project &lt;span aria-hidden=&#34;true&#34;&gt;↗&lt;/span&gt;&lt;/a&gt;&#xA;    &lt;/div&gt;&#xA;  &lt;/div&gt;&#xA;  &lt;div class=&#34;misp-hero-mark&#34; aria-hidden=&#34;true&#34;&gt;&#xA;    &lt;img src=&#34;https://www.circl.lu/assets/images/misp-logo.png&#34; alt=&#34;MISP Intelligence Sharing logo&#34;&gt;&#xA;    &lt;span&gt;Open source&lt;br&gt;Threat intelligence&lt;/span&gt;&#xA;  &lt;/div&gt;&#xA;&lt;/section&gt;&#xA;&lt;nav class=&#34;misp-jump-links&#34; aria-label=&#34;On this page&#34;&gt;&#xA;  &lt;span&gt;On this page&lt;/span&gt;&#xA;  &lt;a href=&#34;#what-misp-does&#34;&gt;Capabilities&lt;/a&gt;&#xA;  &lt;a href=&#34;#how-circl-communities-work&#34;&gt;CIRCL communities&lt;/a&gt;&#xA;  &lt;a href=&#34;#automation-and-integrations&#34;&gt;Automation&lt;/a&gt;&#xA;  &lt;a href=&#34;#misp-for-law-enforcement&#34;&gt;Law enforcement&lt;/a&gt;&#xA;  &lt;a href=&#34;#request-access&#34;&gt;Access&lt;/a&gt;&#xA;  &lt;a href=&#34;#resources&#34;&gt;Resources&lt;/a&gt;&#xA;&lt;/nav&gt;&#xA;&lt;section class=&#34;misp-intro&#34; aria-labelledby=&#34;misp-intro-title&#34;&gt;&#xA;  &lt;h2 id=&#34;misp-intro-title&#34;&gt;More than an IOC database&lt;/h2&gt;&#xA;  &lt;div&gt;&#xA;    &lt;p&gt;MISP models both technical and contextual intelligence: observables and indicators, incidents, threat actors, campaigns, vulnerabilities, tactics and techniques, and the relationships between them. Instead of moving unstructured lists between teams, contributors build reusable knowledge that can be searched, correlated, enriched and acted upon.&lt;/p&gt;</description>
			</item>
			<item>
				<title>MISP - Open Source Threat Intelligence Platform &amp; Open Standards For Threat Information Sharing - Training Materials</title>
				<link>https://www.circl.lu/services/misp-training-materials/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/misp-training-materials/</guid>
				<description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;In a continuous effort since 2016, CIRCL frequently gives practical training sessions about &lt;a href=&#34;https://www.circl.lu/misp&#34;&gt;MISP&lt;/a&gt; (Open Source Threat Intelligence Platform &amp;amp; Open Standards For Threat Information Sharing). The purpose is to reach out to security analysts using MISP as a threat intelligence platform along with users using it as an information sharing platform.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://github.com/MISP/misp-training&#34;&gt;MISP training repository&lt;/a&gt; is the reference for the training materials and their LaTeX source code. It covers core MISP software and standards, threat intelligence and OSINT, and workshops on building information sharing communities.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Passive SSL</title>
				<link>https://www.circl.lu/services/passive-ssl/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/passive-ssl/</guid>
				<description>&lt;h2 id=&#34;passive-ssl&#34;&gt;Passive SSL&lt;/h2&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.circl.lu/assets/images/logos/pssl.png&#34; alt=&#34;CIRCL Passive DNS&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;CIRCL Passive SSL is a database storing historical X.509 certificates seen per IP address. The Passive SSL historical data is indexed per IP address, which makes it searchable for incident handlers, security analysts or researchers.&lt;/p&gt;&#xA;&lt;h2 id=&#34;how-do-you-collect-the-ssl-certificates&#34;&gt;How do you collect the SSL certificates?&lt;/h2&gt;&#xA;&lt;p&gt;The CIRCL Passive SSL database uses public scanning datasets like the excellent &lt;a href=&#34;https://scans.io/&#34;&gt;scans.io project&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;For more information, &lt;a href=&#34;https://www.first.org/resources/papers/conf2015/first_2015_-_leverett_-_dulaunoy_-_passive_detection_20150604.pdf&#34;&gt;Passive SSL was presented at FIRST 2015 in Berlin&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Digital Forensic - Training Materials</title>
				<link>https://www.circl.lu/services/forensic-training-materials/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/forensic-training-materials/</guid>
				<description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.circl.lu/assets/images/logoM-circl-Forensics.png&#34; alt=&#34;CIRCL DFIR&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;An introduction to file-system post-mortem forensic analysis. This page links to the materials used during forensic trainings and presentations, including slides and links to the disk images.&lt;/p&gt;&#xA;&lt;h2 id=&#34;training-materials-bad-out-of-hell---bad-cluster-forensics---fat32&#34;&gt;Training Materials: Bad out of Hell - Bad Cluster Forensics - FAT32&lt;/h2&gt;&#xA;&lt;p&gt;Many progress gained during &lt;a href=&#34;https://hackathon.lu/&#34;&gt;Hackathon 2026&lt;/a&gt;&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Slide Deck: &lt;a href=&#34;https://www.circl.lu/assets/files/booh-fat32.pdf&#34;&gt;Bad out of Hell&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Materials: &lt;a href=&#34;https://cra.circl.lu/fat32.7z&#34;&gt;Disk Image&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;training-materials-75-tf-csirt-meeting---dfir-101&#34;&gt;Training Materials: 75 TF-CSIRT Meeting - DFIR-1.0.1&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Slide Deck: &lt;a href=&#34;https://www.circl.lu/assets/files/DfIr-101.pdf&#34;&gt;From Zero to Hero - Digital Forensics 1.0.1&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Exercises: &lt;a href=&#34;https://www.circl.lu/assets/files/Exercises-101.pdf&#34;&gt;From Zero to Hero - Exercises 1.0.1&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Solutions: Solutions for the exercises can be request via email at: &lt;a href=&#34;mailto:info@circl.lu&#34;&gt;info@circl.lu&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Materials: &lt;a href=&#34;https://www.circl.lu/assets/files/AusCERT24_materials.7z&#34;&gt;All files incl. disk images&lt;/a&gt; SHA1:2f9667a83abec81066d40d425397c0c0a0ae0b63&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;circl---virtual-summer-school-vss-2025&#34;&gt;CIRCL - Virtual Summer School (VSS) 2025&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Slide Deck: &lt;a href=&#34;https://cra.circl.lu/CVSS25-Forensics101.pdf&#34;&gt;Digital Forensics 1.0.1 - From Zero to Hero&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Video Recording: &lt;a href=&#34;https://youtu.be/sSWqBvld-QM&#34;&gt;Digital Forensics 1.0.1 - From Zero to Hero&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;training-materials-edition-december-2024&#34;&gt;Training Materials: Edition December 2024&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Slide Deck: &lt;a href=&#34;https://www.circl.lu/assets/files/forensics-101.pdf&#34;&gt;Digital Forensics 1.0.1 - Introduction: Post-mortem Digital Forensics&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Slide Deck: &lt;a href=&#34;https://www.circl.lu/assets/files/forensics-102.pdf&#34;&gt;Digital Forensics 1.0.2 - Introduction: File System Forensics and Data Recovery&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Slide Deck: &lt;a href=&#34;https://www.circl.lu/assets/files/forensics-103.pdf&#34;&gt;Digital Forensics 1.0.3 - Introduction: Windows-, Memory- and File Forensics&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Disk Image: &lt;a href=&#34;https://www.circl.lu/assets/files/circl-dfir.dd.gz&#34;&gt;Exercises&lt;/a&gt; SHA1:0dff633fded030dd7ac58c871a928afe93d260e9&lt;/li&gt;&#xA;&lt;li&gt;Commands: &lt;a href=&#34;https://www.circl.lu/assets/files/clcs.txt&#34;&gt;Command Line Cheat Sheet v0.1&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;auscert2024&#34;&gt;AUSCERT2024&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Slides: &lt;a href=&#34;https://www.circl.lu/assets/files/AusCERT24_Con.pdf&#34;&gt;As We Are Many - The spooky USB stick&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Materials: &lt;a href=&#34;https://www.circl.lu/assets/files/AusCERT24_materials.7z&#34;&gt;All files incl. disk images&lt;/a&gt; SHA1:2f9667a83abec81066d40d425397c0c0a0ae0b63&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Follow the instructions on the sildes and the provided training materials to create your own spooky USB stick.&#xA;Take care, as some of the parameters likely vary sligthly on you own computer.&#xA;Take care using dd with root rights. We are not responible if you wipe your own disk by accident.&lt;/p&gt;</description>
			</item>
			<item>
				<title>IP to ASN Mapping Whois Service</title>
				<link>https://www.circl.lu/services/ip-asn-history/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/ip-asn-history/</guid>
				<description>&lt;h2 id=&#34;ip-to-asn-mapping-service-with-history&#34;&gt;IP to ASN Mapping Service with History&lt;/h2&gt;&#xA;&lt;p&gt;There are several services on the Internet to map IP addresses to their&#xA;corresponding BGP AS number like the &lt;a href=&#34;https://www.team-cymru.org/Services/ip-to-asn.html&#34;&gt;renowned IP to ASN mapping of Team Cymru&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;During incident handling, we were lacking an historical view of IP address announcement evolution over time. It is not uncommon to have IP addresses announced by different BGP AS number over a period of time. We developed a service, freely accessible to the whole community, to look up IP addresses announcements in the past. Currently, the service covers a time span of more than 4 years until today.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Lookyloo Website Analysis</title>
				<link>https://www.circl.lu/services/lookyloo/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/lookyloo/</guid>
				<description>&lt;h2 id=&#34;lookyloo-website-analysis&#34;&gt;Lookyloo Website Analysis&lt;/h2&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.circl.lu/assets/images/logos/lookyloo.jpeg&#34; alt=&#34;Lookyloo&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://lookyloo.circl.lu/&#34;&gt;Lookyloo&lt;/a&gt; is CIRCL&amp;rsquo;s public service for examining&#xA;websites. It captures a page in a browser and displays a tree of the domains,&#xA;requests, redirects, and resources loaded while visiting it. This helps analysts&#xA;understand the behavior of a suspicious link without opening it in their own&#xA;browser.&lt;/p&gt;&#xA;&lt;p&gt;Users who encounter a suspicious URL in an email or while browsing can submit it&#xA;to the &lt;a href=&#34;https://lookyloo.circl.lu/&#34;&gt;online Lookyloo instance&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>MISP &amp; Threat Sharing for the financial sector</title>
				<link>https://www.circl.lu/services/misp-financial-sector/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/misp-financial-sector/</guid>
				<description>&lt;h2 id=&#34;information-sharing-within-the-financial-sector&#34;&gt;Information sharing within the financial sector&lt;/h2&gt;&#xA;&lt;p&gt;Information security and fraud detection are often transversal activities within banking or financial operators. One financial organization alone cannot perform all upcoming threat analysis and requires additional information shared by others. In that scope, CIRCL co-developed &lt;a href=&#34;https://www.circl.lu/services/misp-malware-information-sharing-platform/&#34;&gt;MISP&lt;/a&gt; (a threat sharing platform) to support information sharing in the context of cyber security as well as within the context of fraud. Financial services, like any other type of organization with an increased attack surface, need simple ways to share information while being able to ensure &lt;strong&gt;an adequate balance between privacy, confidentiality and the need of sharing to protect customers and users&lt;/strong&gt; of financial services.&lt;/p&gt;</description>
			</item>
			<item>
				<title>AIL - Analysis Information Leak framework  - Training Materials</title>
				<link>https://www.circl.lu/services/ail-training-materials/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/ail-training-materials/</guid>
				<description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.circl.lu/assets/images/ail.png&#34; alt=&#34;CIRCL AIL&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;AIL project and AIL framework - Framework for Analysis of Information Leaks&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/ail-project/ail-framework&#34;&gt;AIL is a modular framework to analyse potential information leaks&lt;/a&gt; from unstructured data sources like pastes from Pastebin or similar services or unstructured data streams (such as Tor hidden services). AIL framework is flexible and can be extended to support other functionalities to mine sensitive information.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=KG1xkmdEbHA&#34;&gt;AIL framework - FIRST virtual Training/Workshop&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/ail-project/ail-training&#34;&gt;AIL workshop slides&lt;/a&gt; including Darknet and Social Network Monitoring Introduction to Challenges, Concepts and Data Mining of the Deep Web.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;bug-report-or-issues&#34;&gt;Bug Report or Issues&lt;/h2&gt;&#xA;&lt;p&gt;AIL framework is a free and open source software available at &lt;a href=&#34;https://github.com/ail-project/ail-framework&#34;&gt;https://github.com/ail-project/ail-framework&lt;/a&gt;. If you encounter any issues, bugs or you want to contribute, free free to &lt;a href=&#34;https://github.com/ail-project/ail-framework/issues&#34;&gt;open an issue&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>CCWget</title>
				<link>https://www.circl.lu/services/ccwget/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/ccwget/</guid>
				<description>&lt;h2 id=&#34;ccwget&#34;&gt;CCWget&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://ccwget.circl.lu/&#34;&gt;Common Crawl wGET&lt;/a&gt; turns large-scale web archives into&#xA;targeted, reproducible lookups. Find the record you need, then retrieve only the&#xA;selected WARC object.&lt;/p&gt;&#xA;&lt;h2 id=&#34;benefits&#34;&gt;Benefits&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Search historical URLs&lt;/strong&gt; — Enumerate exact URLs, hosts, domains and time&#xA;ranges across indexed Common Crawl snapshots.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Follow content by digest&lt;/strong&gt; — Use hexadecimal or Base32 SHA-1 digests to&#xA;locate matching archived content without guessing its URL.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Retrieve the HTTP header and web object&lt;/strong&gt; — Inspect metadata first, then&#xA;retrieve the WARC header and the matching archived web object without&#xA;transferring the full archive.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Access to CCWget must be requested from CIRCL. To request access, please&#xA;&lt;a href=&#34;https://www.circl.lu/contact/&#34;&gt;contact CIRCL&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Network exposure change detection service</title>
				<link>https://www.circl.lu/services/network-change-detection/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/network-change-detection/</guid>
				<description>&lt;h2 id=&#34;network-exposure-change-detection-service&#34;&gt;Network exposure change detection service&lt;/h2&gt;&#xA;&lt;p&gt;A periodic external view on the exposure of network services can help identifying network service outages.&#xA;But further more it can detect if new services have been established, either by an employee, a supplier or an attacker.&#xA;Sometimes new services are places on purpose, sometimes by accident, or for instance to maintain access by criminals.&lt;/p&gt;&#xA;&lt;p&gt;This service is based on periodic network port scans. It is able to detect and send the result to an email address, containing the changes seen since the last subsequent scans.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Penetration Testing - An Introduction</title>
				<link>https://www.circl.lu/services/pentest-training-materials/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/pentest-training-materials/</guid>
				<description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;In the past CIRCL gave practical trainings &amp;ldquo;Penetration Testing 1.0.1 - Introduction: Penetration Testing &amp;amp; Ethical Hacking&amp;rdquo;.&lt;/p&gt;&#xA;&lt;p&gt;This page links to the materials used during a training including slides and links to the virtual machines download pages.&lt;/p&gt;&#xA;&lt;p&gt;Instructions for setting up the private / personal lab is part of the slides.&lt;/p&gt;&#xA;&lt;h2 id=&#34;duration&#34;&gt;Duration&lt;/h2&gt;&#xA;&lt;p&gt;This training is available in to formats:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;1 day - All exercises are demonstrated. Attendees can practice the exercises later on, back at home.&lt;/li&gt;&#xA;&lt;li&gt;2 day - Hands-on exercises. Attendees will practice all exercises during the training with support from the instructor.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;vms&#34;&gt;VMs&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.kali.org/downloads/&#34;&gt;Kali Linux&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://sourceforge.net/projects/metasploitable/files/Metasploitable2/&#34;&gt;Metasploitable 2&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://ubuntu.com/download/server&#34;&gt;Linux Server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://developer.microsoft.com/en-us/microsoft-edge/tools/vms/&#34;&gt;Get a free temporary Windows VM from Microsoft&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;slides&#34;&gt;Slides&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.circl.lu/files/Penetration_Testing_1-0-1.pdf&#34;&gt;Penetration Testing 1.0.1 - Introduction: Penetration Testing &amp;amp; Ethical Hacking&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;license&#34;&gt;License&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Materials are licensed under the CC-BY license.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;updates&#34;&gt;Updates&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2016-12-02 - Initial release of slides version 1.0.0&lt;/li&gt;&#xA;&lt;li&gt;2021-05-28 - Initial release of slides version 1.0.1&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>Topic Classifier</title>
				<link>https://www.circl.lu/services/topic-classifier/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/topic-classifier/</guid>
				<description>&lt;h2 id=&#34;topic-classifier&#34;&gt;Topic Classifier&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://hellsehen.circl.lu/&#34;&gt;Topic Classifier&lt;/a&gt; is an API service for&#xA;classifying content with the &lt;a href=&#34;https://www.misp-project.org/taxonomies.html#_content_classification&#34;&gt;MISP content-classification&lt;/a&gt;&#xA;taxonomy through an Ollama-backed AI engine.&lt;/p&gt;&#xA;&lt;p&gt;The project is part of AIPITCH, an international consortium focused on AI-based&#xA;tools for cybersecurity operations and founded by the European Commission. Its&#xA;&lt;a href=&#34;https://github.com/AIPITCH/topic-classifier&#34;&gt;source code is available on&#xA;GitHub&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;how-can-i-access-the-service&#34;&gt;How can I access the service?&lt;/h2&gt;&#xA;&lt;p&gt;The Topic Classifier service is operated by CIRCL and offered on request. To&#xA;request access, contact &lt;a href=&#34;mailto:info@circl.lu&#34;&gt;info@circl.lu&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>CIRCL Cybersecurity Training Initiatives</title>
				<link>https://www.circl.lu/services/training-initiative/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/training-initiative/</guid>
				<description>&lt;h2 id=&#34;circl-cybersecurity-training-initiatives&#34;&gt;CIRCL Cybersecurity Training Initiatives&lt;/h2&gt;&#xA;&lt;p&gt;CIRCL (Computer Incident Response Center Luxembourg) has established a robust set of training initiatives to enhance cybersecurity capabilities across various sectors. These initiatives are supported by numerous European projects and funding programs, aiming to strengthen technical expertise, improve cybersecurity practices, and foster collaborative knowledge sharing. Below is an overview of our key training projects and co-funded by EU projects:&lt;/p&gt;&#xA;&lt;h2 id=&#34;misp-ng-cef-2016-lu-ia-0098&#34;&gt;MISP-NG (CEF 2016-LU-IA-0098)&lt;/h2&gt;&#xA;&lt;p&gt;The &lt;strong&gt;MISP-NG&lt;/strong&gt; project focuses on providing training for the &lt;a href=&#34;https://www.misp-project.org/&#34;&gt;MISP platform&lt;/a&gt;. Supported by the CEF (Connecting Europe Facility) funding, this training empowers organizations to utilize MISP for threat intelligence and information sharing.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Kunai Sandbox</title>
				<link>https://www.circl.lu/services/kunai-sandbox/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/services/kunai-sandbox/</guid>
				<description>&lt;h2 id=&#34;kunai-sandbox&#34;&gt;Kunai Sandbox&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://sandbox.kunai.rocks/&#34;&gt;Kunai Sandbox&lt;/a&gt; is CIRCL&amp;rsquo;s malware sandbox for&#xA;Linux-based malware. It executes submitted Linux samples in an isolated&#xA;environment and records their behaviour with Kunai, providing analysts with a&#xA;complete dynamic-analysis report.&lt;/p&gt;&#xA;&lt;p&gt;Kunai Sandbox replaces CIRCL&amp;rsquo;s former Dynamic Malware Analysis (DMA) service.&#xA;DMA is no longer offered, and its service page now redirects here.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-files-should-i-submit&#34;&gt;What files should I submit?&lt;/h2&gt;&#xA;&lt;p&gt;Use Kunai Sandbox when you need to observe the runtime behaviour of a&#xA;Linux-based malware sample.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
