
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…
Tools for consuming, aggregating, and analyzing external threat intelligence feeds from various sources.

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Advanced Phishing Protection: Suricata rulesets open and free


A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework

Searches For Threat Hunting and Security Analytics

A Linux Auditd rule set mapped to MITRE's Attack Framework

A tool to assist with network-based hunting for GRU's Drovorub malware c2

A query aggregator for OSINT based threat hunting

Your Everyday Threat Intelligence

PatrowlHears - Vulnerability Intelligence Center / Exploits

gundog - guided hunting in Microsoft Defender

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…


Cyber Threat Intelligence (CTI) usando fontes e indicadores de ameaças nacionais, ou até globais, mas com evidencias ou indicadores nacionais do…

Defanged Indicator of Compromise (IOC) Extractor.