
wtfis
Passive hostname, domain and IP lookup tool for non-robots
Tools for consuming, aggregating, and analyzing external threat intelligence feeds from various sources.

Passive hostname, domain and IP lookup tool for non-robots

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

A resource containing all the tools each ransomware gangs uses

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

A query aggregator for OSINT based threat hunting

Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

A Linux Auditd rule set mapped to MITRE's Attack Framework

Live Feed of C2 servers, tools, and botnets

Graph platform for Detection and Response

Web interface for Suricata ruleset management, threat hunting, and rule tuning with multi-source feed aggregation, transformation, and activity…

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Automated ransomware and leak-site OSINT tracker scraping dark-web markets, monitoring victim posts, enriching actor/crypto data, and sending…

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

Defanged Indicator of Compromise (IOC) Extractor.

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.