
reconkg
Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

Advanced Phishing Protection: Suricata rulesets open and free

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational…

Open Cyber Threat Intelligence Platform

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Collection of Cyber Threat Intelligence sources from the deep and dark web

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

YARA signature and IOC database for my scanners and tools


Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Passive hostname, domain and IP lookup tool for non-robots

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

A resource containing all the tools each ransomware gangs uses

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts