
badBANANA-threat-observatory
Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.

Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Read-only WordPress User Registration CVE-2026-1492 checker for hidden admins, plugin version, uploads PHP, cron, and compromise IOCs.

Lightweight investigation notebook for tracking threat intelligence, indicators of compromise (IOCs), and managing security incident response…

Python scanner for detecting CVE-2025-31324 in SAP Visual Composer, with custom IOC-based webshell detection and multi-target CSV input.

KQL hunting query for Microsoft Defender for Endpoint to detect WinRAR file extension spoofing (CVE-2023-38831) using IOCs and file event analysis.

Proofpoint - Emerging Threats - Threat Research tools + publicly shared intel and documentation

Malware/IOC ingestion and processing engine

IOCPARSER.COM is a Fast and Reliable service that enables you to extract IOCs and intelligence from different data sources.

Detects malicious IPv4 addresses and domain names associated with a web application by comparing against local threat intelligence lists of known…

Extracts selected MISP attributes, including IP addresses, URLs, and hashes, into reusable output files.

Curated repository of suspicious Domain Generation Algorithm (DGA) domains sourced from passive DNS and sandbox telemetry, with community-validated…

Threat hunting command system for agentic IDEs

This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273

A go-exploit for fetching the RocketMQ broker configuration in order to discover indicators of compromise for CVE-2023-33246

Live Feed of C2 servers, tools, and botnets

Extract indicators of compromise from text, including "escaped" ones.

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)