
destroylist
Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Open Cyber Threat Intelligence Platform

Malicious Extension Database

A continuously updated resource that catalogs confirmed data breaches from across the globe. Each entry includes the breach name, usually aligned…

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

Sophos-originated indicators-of-compromise from published reports

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

This is the repository for indicators of compromise (IOCs) and other data for threat intelligence articles posted on the Palo Alto Networks Unit 42…

YARA signature and IOC database for my scanners and tools

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Elastic Security Labs releases


Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

IOCs and a read-only triage checklist from a real Linux root compromise: RedTail miner, XorDDoS persistence, MoneroOcean miner, DirtyFrag LPE…

This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.