
badBANANA-threat-observatory
Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.

Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.

Lightweight low-interaction network honeypot sensor that captures TCP payloads, performs passive TLS/HTTP/SSH fingerprinting, and outputs structured…

Curated repository of IOCs and threat intelligence from the Expel Intel Team, providing actionable indicators for detection and response workflows.

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Threat hunting command system for agentic IDEs

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.

Automated observable analysis engine for threat intelligence, digital forensics, and incident response, integrating with diverse analyzers via a…

Read-only WordPress User Registration CVE-2026-1492 checker for hidden admins, plugin version, uploads PHP, cron, and compromise IOCs.

Automated vulnerability scanner for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass) with TLS certificate enumeration, authentication…

Reverse engineering repository for malware samples from goxlr.net and related domains, focusing on stealer variants, C2 infrastructure analysis, and…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Proofpoint - Emerging Threats - Threat Research tools + publicly shared intel and documentation

Message-queue-based threat intelligence feed collector and processor for CSIRTs. Automates ingestion, normalization, and sharing of security…

Live Feed of C2 servers, tools, and botnets

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

Command-line client for abuse.ch threat intelligence APIs, enabling query and retrieval of Indicators of Compromise (IOCs) for threat hunting and…

CLI tool to search, aggregate, and store IOCs from multiple open security feeds and APIs, enabling local threat intelligence database creation and…

Python scanner for detecting CVE-2025-31324 in SAP Visual Composer, with custom IOC-based webshell detection and multi-target CSV input.