
exist
EXIST is a web application for aggregating and analyzing cyber threat intelligence.
Tools for consuming, aggregating, and analyzing external threat intelligence feeds from various sources.


Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

Proofpoint - Emerging Threats - Threat Research tools + publicly shared intel and documentation

AI-curated blocklist of 3,000,000+ domains for blocking ads, trackers, malware, and cryptojacking. Integrates with hosts files, Pi-hole, and browser…

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

👮 Security advisories of Nextcloud

A Python library for handling TAXII Messages invoking TAXII Services.


Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups

gundog - guided hunting in Microsoft Defender

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)

Cyber Threat Defense World Modeling

A tool to assist with network-based hunting for GRU's Drovorub malware c2

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

Public repository of Sigma and YARA rules created by Synacktiv