#1Tools for collecting, analyzing, and operationalizing threat feeds, indicators of compromise (IOCs), and attack trends.
Kitploit recommended

Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation

Distributed alerting for the masses!

The Correlated CVE Vulnerability And Threat Intelligence Database API

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…

Node graphs, OSINT data mining, and plugins. Connect unstructured and public data for transformative insights. The rewrite can be found @…

A MITM (monster-in-the-middle) detection tool. Used to build MALCOLM:

Live Feed of C2 servers, tools, and botnets

Graph platform for Detection and Response

StalkPhish - The Phishing kits stalker, harvesting phishing kits for investigations.

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

By Kprobe technology Open Source Host-based Intrusion Detection System(HIDS), from E_Bwill.


A tool to retrieve malware directly from the source for security researchers.

The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).

Detection signature repository providing YARA rules and threat-hunting content for identifying malware and malicious activity across enterprise…