
100_days_of_kql_2026
A repo to hold KQL queries as part of my 100 days of KQL effort.
Tools for consuming, aggregating, and analyzing external threat intelligence feeds from various sources.

A repo to hold KQL queries as part of my 100 days of KQL effort.

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Cyber Threat Defense World Modeling

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Malicious Extension Database

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Free, offline SOC Analyst Hub for Tier 1 — IR checklists, alert triage playbooks, threat hunting queries & analyst onboarding. Single HTML file, no…

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

Open Cyber Threat Intelligence Platform

Collection of Cyber Threat Intelligence sources from the deep and dark web

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

YARA signature and IOC database for my scanners and tools

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

Pulled Pork for Snort and Suricata rule management (from Google code)