
Loki
IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

Cortex: a Powerful Observable Analysis and Active Response Engine

This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such…

Clusters and elements to attach to MISP events or attributes (like threat actors)

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking,…

Python-based malware analysis sandbox that integrates with Sysinternals Procmon to automatically collect, analyze, and report runtime indicators with…

A centralized and enhanced memory analysis platform

STIX 2.1 collections of the MITRE ATT&CK knowledge base, providing adversary tactics and techniques for enterprise, mobile, and ICS threat…

Automated vulnerability data aggregator that collects advisories from NVD, OSV, Alpine, Red Hat, and 20+ other sources into a unified parsable format…

Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.

Open source platform for cyber security analysts with many features for threat intelligence and detection engineering.

Threat Intel IoCs + bits and pieces of dark matter. Published by Gen Threat Labs.

Signatures and IoCs from public Volexity blog posts.