Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Watcher — AI-powered threat intelligence platform for automated CVE/ransomware monitoring, domain surveillance, data leak detection, and incident response with MISP/TheHive integration. | Kitploit
Tools/GitHubGitHub/thalesgroup-cert/watcher
OSINT (Open Source Intelligence)Vulnerability AnalysisDNS & Subdomain EnumerationData ExfiltrationInformation GatheringPhishingThreat IntelligenceMachine LearningIncident ResponseAI Security
GitHub
1.4k1994412h 55m agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
thalesgroup-cert/watcher

Watcher

AI-powered threat intelligence platform for automated CVE/ransomware monitoring, domain surveillance, data leak detection, and incident response with MISP/TheHive integration.

View RepositoryWebsite

Watcher Logo

AI-Powered Automated Cybersecurity Threat Detection Platform

Install Documentation Stars Closed Issues License Docker Pulls

thalesgroup-cert/Watcher | Trendshift thalesgroup-cert/Watcher | Trendshift

Watcher is a Django & React JS platform designed to discover and monitor emerging cybersecurity threats with AI-powered threat intelligence analysis. It can be deployed on webservers or quickly run via Docker.

Watcher Capabilities

Watcher empowers your security operations with comprehensive threat detection and monitoring:

  • AI-Driven Threat Intelligence - Transform raw threat data into actionable intelligence with automated weekly digests of top-5 trending cybersecurity topics, real-time breaking news alerts when threats emerge, on-demand summaries for any security keyword including related CVE and threat actor details.

  • CVE & Ransomware Intelligence - Continuously fetch, correlate, and surface external threat data: CVEs from cve.circl.lu, ransomware victims and groups from ransomware.live and ransomlook.io. Define keyword-based Watch Rules to get alerted when specific threats match your organisation's context.

  • Emerging Threat Detection - Monitor cybersecurity trends via RSS feeds from CERT-FR (www.cert.ssi.gouv.fr), CERT-EU (www.cert.europa.eu), US-CERT (www.us-cert.gov), Australian Cyber Security Centre (www.cyber.gov.au), and more. Track new vulnerabilities, malware campaigns, and threat advisories as they appear.

  • Legitimate Domain Management - Centralized approved domains with expiry, repurchase status, registrar info, and contacts. Easily convert monitored malicious domains into legitimate ones. Automated UDRP case tracking.

  • Information Leak Monitoring - Detect sensitive data exposure across the webs including Pastebin, StackOverflow, GitHub, GitLab, Bitbucket, APKMirror, npm registries, and other platforms. Catch leaked credentials, API keys, and confidential information early.

  • Malicious Domain Surveillance - Monitor malicious domains for changes in IP addresses, mail/MX records, and web content. Use TLSH fuzzy hashing to detect modifications. Automatic RDAP/WHOIS checks with registrar and expiry alerts.

  • Suspicious Domain Detection - Identify potentially malicious domains targeting your organisation via:

    • Domain Generation Algorithm Detection using dnstwist to find typosquatting, homograph attacks, and similar domain variants
    • Certificate Transparency Monitoring via certstream to catch newly registered suspicious domains in real-time

Additional Features

Extend Watcher's capabilities with powerful integrations and management tools:

  • TheHive Full Synchronization - Integration with TheHive featuring automated alert creation, smart case management, IOC enrichment, and ready-to-use Cortex Analyzers & Responders. Detailed configuration are provided in the documentation here.
  • MISP Integration - Seamlessly export Indicators of Compromise (IOCs) to MISP with smart UUID tracking, automatic object creation, and manual attribute updates for collaborative threat intelligence sharing
  • SSO / OpenID Connect - Federated login via any OIDC provider (Keycloak, Azure AD, etc.) with PKCE and Knox token issuance. Configurable per-instance via .env
  • Flexible Authentication - Support for LDAP, local, and SSO/OIDC authentication systems
  • Connectors Dashboard - A superuser-only /connectors page to view, edit, and test every external integration (SMTP, Slack, Citadel, TheHive, MISP, CyberWatch feeds, and more) from one place, with encrypted credential storage and per-connector health checks.
  • Smart Notifications - Receive email, Slack, or Citadel alerts for critical findings and threshold violations across all modules including CyberWatch and UDRP decisions
  • Interactive API Documentation - Auto-generated Swagger UI at /api/docs/ and OpenAPI 3 schema at /api/schema/ powered by drf-spectacular
  • Ticketing System Integration - Automatically feed your ticketing system with security findings
  • Comprehensive Admin Interface - Manage all aspects of Watcher through Django's powerful admin panel
  • Advanced Access Control - Granular user permissions and group management for team collaboration
  • Modern UI Experience - A modern interface with customizable themes, resizable dashboard panels, advanced filtering with saved filter sets, and persistent user preferences

Involved dependencies

Download Tool