Ross ROSS = Recommend OSS · open-source software intelligence for agents

microsoft/msticpy

Microsoft Threat Intelligence Security Tools observed · 2026-08-28

github.com/microsoft/msticpy · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

92/100

  • Activity 97
  • Release rhythm 81
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 36.0
  • age_days: 2750
  • days_rel: 46
  • days_push: 20
  • n_releases_24m: 13

Full methodology

Adoption not part of the score

1995 stars · 332 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

msticpy is a Python library from Microsoft for security investigation and threat hunting in Jupyter notebooks. It provides data acquisition from SIEM and log sources, threat intelligence enrichment, analysis, and interactive visualization for SOC investigators.

Use cases

  • query log data from Sentinel, Splunk, or Defender in a Jupyter notebook
  • enrich security events with threat intelligence and geolocation data
  • extract indicators of activity from logs
  • detect anomalous sessions and perform time series analysis on security data
  • visualize process trees and interactive timelines for incident investigation
  • build SOC hunting notebooks with reusable widgets and query tools

When to choose

  • you do security incident response or threat hunting in Jupyter notebooks
  • you use Microsoft Sentinel or Azure and want first-party tooling
  • you want a Python library that standardizes on pandas DataFrames for security analysis

When to avoid

  • you need a standalone GUI or web application rather than a notebook library
  • your SIEM is not among the supported sources and you cannot write a custom data provider
  • you need a fully maintained PyPI release right now, since publishing is temporarily halted

Facets

library · maturity active

data-visualization analytics search-engine monitoring nlp security data-science developer-tools analytics python cross-platform threat-intelligence jupyter siem microsoft-sentinel security-hunting incident-response soc-tools pandas

2 sources

Member repositories

RepositoryRoleHealth v2
microsoft/msticpymain92

For agents

markdown · JSON · MCP: product_card(name="microsoft/msticpy")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem