
badBANANA-threat-observatory
Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.

Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.

Curated repository of IOCs and threat intelligence from the Expel Intel Team, providing actionable indicators for detection and response workflows.

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Threat hunting command system for agentic IDEs

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.

Forensic analysis of a TeamCity server compromise via CVE-2024-27198, detailing initial access, webshell persistence, and system enumeration from…

Automated vulnerability scanner for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass) with TLS certificate enumeration, authentication…

Reverse engineering repository for malware samples from goxlr.net and related domains, focusing on stealer variants, C2 infrastructure analysis, and…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Proofpoint - Emerging Threats - Threat Research tools + publicly shared intel and documentation

Message-queue-based threat intelligence feed collector and processor for CSIRTs. Automates ingestion, normalization, and sharing of security…

Live Feed of C2 servers, tools, and botnets

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

High-fidelity scanner for React Server Components RCE vulnerabilities (CVE-2025-55182, CVE-2025-66478) with subdomain enumeration, IOC correlation,…

Command-line client for abuse.ch threat intelligence APIs, enabling query and retrieval of Indicators of Compromise (IOCs) for threat hunting and…

CLI tool to search, aggregate, and store IOCs from multiple open security feeds and APIs, enabling local threat intelligence database creation and…

Python scanner for detecting CVE-2025-31324 in SAP Visual Composer, with custom IOC-based webshell detection and multi-target CSV input.

Repository documenting the Fortigate firewall vulnerability CVE-2022-40684 and publicly disclosed affected data for security research and defensive…