


Open source platform for cyber security analysts with many features for threat intelligence and detection engineering.

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Incident Response Forensic Framework

The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).

Operational information regarding CVE-2022-3602 and CVE-2022-3786, two vulnerabilities in OpenSSL 3

TAXII server implementation in Python from EclecticIQ

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

Virtual Security Operations Center

Open-source collaborative note-taking platform for cybersecurity and CTI teams. IOC auto-extraction, STIX 2.1 export, real-time editing, RBAC,…

Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Spip network sensor written in Go

A go-exploit for fetching the RocketMQ broker configuration in order to discover indicators of compromise for CVE-2023-33246

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)