microsoft/msticpy
Microsoft Threat Intelligence Security Tools observed · 2026-08-28
Health v2 · maintenance only
92/100
- Activity 97
- Release rhythm 81
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 36.0
- age_days: 2750
- days_rel: 46
- days_push: 20
- n_releases_24m: 13
Adoption not part of the score
1995 stars · 332 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
msticpy is a Python library from Microsoft for security investigation and threat hunting in Jupyter notebooks. It provides data acquisition from SIEM and log sources, threat intelligence enrichment, analysis, and interactive visualization for SOC investigators.
Use cases
- query log data from Sentinel, Splunk, or Defender in a Jupyter notebook
- enrich security events with threat intelligence and geolocation data
- extract indicators of activity from logs
- detect anomalous sessions and perform time series analysis on security data
- visualize process trees and interactive timelines for incident investigation
- build SOC hunting notebooks with reusable widgets and query tools
When to choose
- you do security incident response or threat hunting in Jupyter notebooks
- you use Microsoft Sentinel or Azure and want first-party tooling
- you want a Python library that standardizes on pandas DataFrames for security analysis
When to avoid
- you need a standalone GUI or web application rather than a notebook library
- your SIEM is not among the supported sources and you cannot write a custom data provider
- you need a fully maintained PyPI release right now, since publishing is temporarily halted
Facets
library · maturity active
data-visualization analytics search-engine monitoring nlp security data-science developer-tools analytics python cross-platform threat-intelligence jupyter siem microsoft-sentinel security-hunting incident-response soc-tools pandas
2 sources
- readme: https://github.com/microsoft/msticpy · fetched 2026-08-28 · f010c15dd4d9
- registry_pypi: https://pypi.org/pypi/msticpy/json · fetched 2026-08-29 · a09cd35d6bd5
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| microsoft/msticpy | main | 92 |
For agents
markdown · JSON · MCP: product_card(name="microsoft/msticpy")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem