Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
IntelOwl — Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows for SOC analysts and DFIR teams. | Kitploit
Tools/GitHubGitHub/intelowlproject/intelowl
Indicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Static AnalysisDynamic Analysis (Sandboxing)OSINT for Social EngineeringThreat Feeds & AggregatorsVulnerability AnalysisForensicsInformation GatheringMalware AnalysisDigital Forensics
4.7k6557128 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Threat Intelligence
Email Harvesting
Learning & Education
Incident Response
Curated Resources
Email Security
Top in Dynamic Analysis (Sandboxing) #4
Top in Email Harvesting #12
Top in Email Security #13
Top in Indicator of Compromise (IOC) Management #3
Top in Malware Analysis #11
Top in OSINT (Open Source Intelligence) #12
Top in OSINT for Social Engineering #13
Top in Static Analysis #15
Top in Threat Feeds & Aggregators #3
Top in Threat Intelligence #3
GitHubintelowlproject/intelowl

IntelOwl

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows for SOC analysts and DFIR teams.

View RepositoryWebsite
Intel Owl

GitHub release (latest by date) GitHub Repo stars Docker Twitter Follow Linkedin Official Site Live Instance

Ruff CodeQL Dependency Review Build & Tests DeepSource OpenSSF Scorecard OpenSSF Best Practices

intelowlproject%2FIntelOwl | Trendshift

Intel Owl

Do you want to get threat intelligence data about a malware, an IP address or a domain? Do you want to get this kind of data from multiple sources at the same time using a single API request?

You are in the right place!

IntelOwl is an Open Source solution for management of Threat Intelligence at scale. It integrates a number of analyzers available online and a lot of cutting-edge malware analysis tools.

Features

This application is built to scale out and to speed up the retrieval of threat info.

It provides:

  • Enrichment of Threat Intel for files as well as observables (IP, Domain, URL, hash, etc).
  • A Fully-fledged REST APIs written in Django and Python.
  • An easy way to be integrated in your stack of security tools to automate common jobs usually performed, for instance, by SOC analysts manually. (Thanks to the official libraries pyintelowl and go-intelowl)
  • A built-in GUI: provides features such as dashboard, visualizations of analysis data, easy to use forms for requesting new analysis, etc.
  • A framework composed of modular components called Plugins:
    • analyzers that can be run to either retrieve data from external sources (like VirusTotal or AbuseIPDB) or to generate intel from internally available tools (like Yara or Oletools)
    • connectors that can be run to export data to external platforms (like MISP or OpenCTI)
    • pivots that are designed to trigger the execution of a chain of analysis and connect them to each other
    • visualizers that are designed to create custom visualizations of analyzers results in the GUI
    • ingestors that allow to automatically ingest stream of observables or files to IntelOwl itself
    • playbooks that are meant to make analysis easily repeatable
    • data models to map the different data extracted from analyzers to a single common schema
    • artifacts that are representations of observables or files that can be analyzed multiple times for different evaluations
    • user events that allow users to add custom evaluation or additional info to any artifact
  • A starting point for analysts' Investigations: users can register their findings, correlate the information found, and collaborate...all in a single place

Documentation

We try hard to keep our documentation well written, easy to understand and always updated. All info about installation, usage, configuration and contribution can be found here

Publications and Media

To know more about the project and its growth over time, you may be interested in reading the official blog posts and/or videos about the project by clicking on this link

Available services or analyzers

You can see the full list of all available analyzers in the documentation.

Download Tool