
scambuster
Defensive engagement & threat intelligence research laboratory. Converts inbound scam emails into actionable IOCs through controlled, policy-driven…

Defensive engagement & threat intelligence research laboratory. Converts inbound scam emails into actionable IOCs through controlled, policy-driven…

Spip network sensor written in Go

This is the home of the Expel Intel Team. Here, we will share IOCs and other information that is either not suitable for fitting into other mediums…

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Threat hunting command system for agentic IDEs

Read-only WordPress User Registration CVE-2026-1492 checker for hidden admins, plugin version, uploads PHP, cron, and compromise IOCs.

GrayXploit Security research and defensive team validate this toolkit for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass). Includes…

Malware analysis from the domain goxlr.net

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Proofpoint - Emerging Threats - Threat Research tools + publicly shared intel and documentation

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Data Collection Related to Exim CVE-2019-10149

A Python library for handling TAXII Messages invoking TAXII Services.

Live Feed of C2 servers, tools, and botnets

Python-based malware analysis sandbox that integrates with Sysinternals Procmon to automatically collect, analyze, and report runtime indicators with…

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)