
malicious_extension_sentry
Malicious Extension Database

Malicious Extension Database

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Real-time phishing & scam domain blocklist - 205k+ curated threats, 1M+ community, free API, multiple formats

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…



Advanced Phishing Protection: Suricata rulesets open and free

Clusters and elements to attach to MISP events or attributes (like threat actors)

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Open-source Android client for VirusTotal. Scan files, URLs, and installed apps against 70+ antivirus engines. View detailed reports with hashes,…

Simple, effective, and modular package for parsing observables (indicators of compromise (IOCs), network data, and other, security related…

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

LetsDefend SOC lab investigating CVE-2024-49138 and related malicious activity.

Curated JSON object templates that define MISP attributes and relationship types for structured threat intelligence sharing and interoperable IOC…

Curated IPv4 blocklist of malicious addresses, refreshed every 6 hours for firewall and WAF ingestion, with split lists and CTI-ready formats for…