{"adoption": {"forks": 332, "observed_at": "2026-08-28T04:06:03.441743+00:00", "stars": 1995}, "canonical_url": "https://ross.abutalabs.com/products/msticpy", "card": {"archived": false, "artifact_type": "library", "description": "Microsoft Threat Intelligence Security Tools", "domain": ["security", "data-science", "developer-tools", "analytics"], "enriched": true, "function": ["data-visualization", "analytics", "search-engine", "monitoring", "nlp"], "health_score": 98, "homepage": null, "language": "Python", "license": "NOASSERTION", "license_family": "other", "maturity": "active", "member_repos": ["microsoft/msticpy"], "name": "microsoft/msticpy", "platform": ["python", "cross-platform"], "pushed_at": "2026-08-13T13:03:14+00:00", "repo": "microsoft/msticpy", "stars": 1995, "tags": ["threat-intelligence", "jupyter", "siem", "microsoft-sentinel", "security-hunting", "incident-response", "soc-tools", "pandas"], "topics": [], "urls": [], "use_cases": ["query log data from Sentinel, Splunk, or Defender in a Jupyter notebook", "enrich security events with threat intelligence and geolocation data", "extract indicators of activity from logs", "detect anomalous sessions and perform time series analysis on security data", "visualize process trees and interactive timelines for incident investigation", "build SOC hunting notebooks with reusable widgets and query tools"], "what_it_is": "msticpy is a Python library from Microsoft for security investigation and threat hunting in Jupyter notebooks. It provides data acquisition from SIEM and log sources, threat intelligence enrichment, analysis, and interactive visualization for SOC investigators.", "when_to_avoid": ["you need a standalone GUI or web application rather than a notebook library", "your SIEM is not among the supported sources and you cannot write a custom data provider", "you need a fully maintained PyPI release right now, since publishing is temporarily halted"], "when_to_choose": ["you do security incident response or threat hunting in Jupyter notebooks", "you use Microsoft Sentinel or Azure and want first-party tooling", "you want a Python library that standardizes on pandas DataFrames for security analysis"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/msticpy", "repo": "microsoft/msticpy", "role": "main", "score": 92}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:06:03.441743+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:02:31.268480+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f010c15dd4d9990a889e33f9d0377154ed2cfc6588a5b19ea446b272ea048db8", "fetched_at": "2026-08-28T04:06:03.441743+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/msticpy"}, {"content_hash": "a09cd35d6bd572db0302e0d9a6bbcf20d99a259e12c88800af3787dd1c91159f", "fetched_at": "2026-08-29T10:42:10.400054+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/msticpy/json"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:06:03.441743+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:02:31.268480+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f010c15dd4d9990a889e33f9d0377154ed2cfc6588a5b19ea446b272ea048db8", "fetched_at": "2026-08-28T04:06:03.441743+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/msticpy"}, {"content_hash": "a09cd35d6bd572db0302e0d9a6bbcf20d99a259e12c88800af3787dd1c91159f", "fetched_at": "2026-08-29T10:42:10.400054+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/msticpy/json"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:02:31.268480+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f010c15dd4d9990a889e33f9d0377154ed2cfc6588a5b19ea446b272ea048db8", "fetched_at": "2026-08-28T04:06:03.441743+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/msticpy"}, {"content_hash": "a09cd35d6bd572db0302e0d9a6bbcf20d99a259e12c88800af3787dd1c91159f", "fetched_at": "2026-08-29T10:42:10.400054+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/msticpy/json"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:06:03.441743+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:06:03.441743+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:06:03.441743+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:02:31.268480+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f010c15dd4d9990a889e33f9d0377154ed2cfc6588a5b19ea446b272ea048db8", "fetched_at": "2026-08-28T04:06:03.441743+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/msticpy"}, {"content_hash": "a09cd35d6bd572db0302e0d9a6bbcf20d99a259e12c88800af3787dd1c91159f", "fetched_at": "2026-08-29T10:42:10.400054+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/msticpy/json"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:06:03.441743+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:06:03.441743+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:02:31.268480+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f010c15dd4d9990a889e33f9d0377154ed2cfc6588a5b19ea446b272ea048db8", "fetched_at": "2026-08-28T04:06:03.441743+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/msticpy"}, {"content_hash": "a09cd35d6bd572db0302e0d9a6bbcf20d99a259e12c88800af3787dd1c91159f", "fetched_at": "2026-08-29T10:42:10.400054+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/msticpy/json"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:06:03.441743+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:06:03.441743+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:06:03.441743+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:02:31.268480+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f010c15dd4d9990a889e33f9d0377154ed2cfc6588a5b19ea446b272ea048db8", "fetched_at": "2026-08-28T04:06:03.441743+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/msticpy"}, {"content_hash": "a09cd35d6bd572db0302e0d9a6bbcf20d99a259e12c88800af3787dd1c91159f", "fetched_at": "2026-08-29T10:42:10.400054+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/msticpy/json"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:06:03.441743+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:06:03.441743+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:02:31.268480+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f010c15dd4d9990a889e33f9d0377154ed2cfc6588a5b19ea446b272ea048db8", "fetched_at": "2026-08-28T04:06:03.441743+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/msticpy"}, {"content_hash": "a09cd35d6bd572db0302e0d9a6bbcf20d99a259e12c88800af3787dd1c91159f", "fetched_at": "2026-08-29T10:42:10.400054+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/msticpy/json"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:02:31.268480+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f010c15dd4d9990a889e33f9d0377154ed2cfc6588a5b19ea446b272ea048db8", "fetched_at": "2026-08-28T04:06:03.441743+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/msticpy"}, {"content_hash": "a09cd35d6bd572db0302e0d9a6bbcf20d99a259e12c88800af3787dd1c91159f", "fetched_at": "2026-08-29T10:42:10.400054+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/msticpy/json"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:02:31.268480+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f010c15dd4d9990a889e33f9d0377154ed2cfc6588a5b19ea446b272ea048db8", "fetched_at": "2026-08-28T04:06:03.441743+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/msticpy"}, {"content_hash": "a09cd35d6bd572db0302e0d9a6bbcf20d99a259e12c88800af3787dd1c91159f", "fetched_at": "2026-08-29T10:42:10.400054+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/msticpy/json"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:02:31.268480+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f010c15dd4d9990a889e33f9d0377154ed2cfc6588a5b19ea446b272ea048db8", "fetched_at": "2026-08-28T04:06:03.441743+00:00", "kind": "readme", "missing": false, "url": "https://github.com/microsoft/msticpy"}, {"content_hash": "a09cd35d6bd572db0302e0d9a6bbcf20d99a259e12c88800af3787dd1c91159f", "fetched_at": "2026-08-29T10:42:10.400054+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/msticpy/json"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 97, "longevity": 100, "rhythm": 81}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2750, "days_push": 20, "days_rel": 46, "gap_med": 36.0, "n_releases_24m": 13}, "score": 92, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}