
opencti
Open Cyber Threat Intelligence Platform

Open Cyber Threat Intelligence Platform

Malicious Extension Database

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Real-time phishing & scam domain blocklist - 205k+ curated threats, 1M+ community, free API, multiple formats

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research,…

A continuously updated resource that catalogs confirmed data breaches from across the globe. Each entry includes the breach name, usually aligned…

Advanced Phishing Protection: Suricata rulesets open and free

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Curated JSON object templates that define MISP attributes and relationship types for structured threat intelligence sharing and interoperable IOC…

📕NVD Database

Clusters and elements to attach to MISP events or attributes (like threat actors)

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)