
ThreatLens
Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

A tool to assist with network-based hunting for GRU's Drovorub malware c2


Clusters and elements to attach to MISP events or attributes (like threat actors)

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

Passive hostname, domain and IP lookup tool for non-robots

Automater - IP URL and MD5 OSINT Analysis