
ThreatPad
Open-source collaborative note-taking platform for cybersecurity and CTI teams. IOC auto-extraction, STIX 2.1 export, real-time editing, RBAC,…

Open-source collaborative note-taking platform for cybersecurity and CTI teams. IOC auto-extraction, STIX 2.1 export, real-time editing, RBAC,…

Extracts selected MISP attributes, including IP addresses, URLs, and hashes, into reusable output files.

CLI client for abuse.ch

ioc2rpz is a place where threat intelligence meets DNS.

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.

Indicators of Compromise from Amnesty International's cyber investigations

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…


Suspicious DGA from PDNS and Sandbox.

Defanged Indicator of Compromise (IOC) Extractor.

TIH is an intelligence tool that helps you in searching for IOCs across multiple openly available security feeds and some well known APIs. The idea…

Proofpoint - Emerging Threats - Threat Research tools + publicly shared intel and documentation