
soc-analyst-hub
Free, offline SOC Analyst Hub for Tier 1 — IR checklists, alert triage playbooks, threat hunting queries & analyst onboarding. Single HTML file, no…
Tools for consuming, aggregating, and analyzing external threat intelligence feeds from various sources.

Free, offline SOC Analyst Hub for Tier 1 — IR checklists, alert triage playbooks, threat hunting queries & analyst onboarding. Single HTML file, no…

EXIST is a web application for aggregating and analyzing cyber threat intelligence.

PatrowlHears - Vulnerability Intelligence Center / Exploits

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Dynamically generated Suricata rules from real-time threat feeds

TAXII server implementation in Python from EclecticIQ

Security advisories from Aqua Security

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.


CLI client for abuse.ch

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

A lightweight Python module to interact with the [MITRE ATT&CK®](https://attack.mitre.org/) Enterprise dataset. Built for speed with minimal…

Collect VEX documents and update VEX Hub

Cyber Threat Intelligence (CTI) usando fontes e indicadores de ameaças nacionais, ou até globais, mas com evidencias ou indicadores nacionais do…

Public repository of Sigma and YARA rules created by Synacktiv