
opencti
Open Cyber Threat Intelligence Platform

Open Cyber Threat Intelligence Platform

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia,…

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.


Real-time phishing & scam domain blocklist - 205k+ curated threats, 1M+ community, free API, multiple formats

Microsoft Threat Intelligence Security Tools

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Indicators of Compromise from Amnesty International's cyber investigations

Cortex: a Powerful Observable Analysis and Active Response Engine

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Curated IPv4 blocklist of malicious addresses, refreshed every 6 hours for firewall and WAF ingestion, with split lists and CTI-ready formats for…

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Open source platform for cyber security analysts with many features for threat intelligence and detection engineering.

66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit…

Incident Response Forensic Framework