
awesome-lists
Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Malicious Extension Database


MISP (core software) - Open Source Threat Intelligence and Sharing Platform

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research,…

A continuously updated resource that catalogs confirmed data breaches from across the globe. Each entry includes the breach name, usually aligned…

Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.

Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.

Advanced Phishing Protection: Suricata rulesets open and free

Trust & Safety tools for working together to fight digital harms.

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

📕NVD Database

Clusters and elements to attach to MISP events or attributes (like threat actors)

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.