
MISP
MISP (core software) - Open Source Threat Intelligence and Sharing Platform

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

VulnCheck's official command line tool

Open-source Android client for VirusTotal. Scan files, URLs, and installed apps against 70+ antivirus engines. View detailed reports with hashes,…

Automated vulnerability data aggregator that collects advisories from NVD, OSV, Alpine, Red Hat, and 20+ other sources into a unified parsable format…

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia,…

Automates Cobalt Strike payload development, testing, and deployment via a Python-to-Sleep bridge; includes artifact inspection, IoC tracking, and…

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

ioc2rpz is a place where threat intelligence meets DNS.

Microsoft Threat Intelligence Security Tools

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Virtual Security Operations Center

Operational security controls with forensic guarantees

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool