
crowdsec
Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

A resource containing all the tools each ransomware gangs uses

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Live Feed of C2 servers, tools, and botnets

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Automater - IP URL and MD5 OSINT Analysis

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

Don't Just Search OSINT. Sweep It.

TAXII server implementation in Python from EclecticIQ

Malicious Extension Database


Cyber Threat Defense World Modeling

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

This is the home of the Expel Intel Team. Here, we will share IOCs and other information that is either not suitable for fitting into other mediums…

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…