
ThreatIngestor
Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…
Tools for consuming, aggregating, and analyzing external threat intelligence feeds from various sources.

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Signatures and IoCs from public Volexity blog posts.

A Linux Auditd rule set mapped to MITRE's Attack Framework

Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional…

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts


Automater - IP URL and MD5 OSINT Analysis

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

Web interface for Suricata ruleset management, threat hunting, and rule tuning with multi-source feed aggregation, transformation, and activity…

Gets updates from various clearnet domains and ransomware threat actor domains

Pulled Pork for Snort and Suricata rule management (from Google code)

Defanged Indicator of Compromise (IOC) Extractor.

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework

Malicious Extension Database