
destroylist
Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

Open Vulnerability Intelligence platform, aggregated intel in one dashboard, with correlation and IOC lookups, completely self hosted. All resources…

Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.

IoCs and YARA rules from Threatray's Threat Research

Defensive engagement & threat intelligence research laboratory. Converts inbound scam emails into actionable IOCs through controlled, policy-driven…

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.

Aggregate, filter, and track CVEs from multiple sources with team collaboration, custom dashboards, alerts, and AI-powered analysis for vulnerability…


Sophos-originated indicators-of-compromise from published reports

Python library for extracting Indicators of Compromise, URLs, IP addresses, hashes, and email addresses from text using declarative grammars instead…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…


Static analysis of malicious Python code


This is the repository for indicators of compromise (IOCs) and other data for threat intelligence articles posted on the Palo Alto Networks Unit 42…

This is the home of the Expel Intel Team. Here, we will share IOCs and other information that is either not suitable for fitting into other mediums…

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT

Some of my KQL hunting queries