
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational…

Trust & Safety tools for working together to fight digital harms.

A tool to assist with network-based hunting for GRU's Drovorub malware c2

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

PatrowlHears - Vulnerability Intelligence Center / Exploits

Reproducible SOC lab for CVE-2024-4577 detection and response

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

TAXII server implementation in Python from EclecticIQ

Malicious Extension Database

A Python library for handling TAXII Messages invoking TAXII Services.

Dynamically generated Suricata rules from real-time threat feeds

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

Open Vulnerability Intelligence platform, aggregated intel in one dashboard, with correlation and IOC lookups, completely self hosted. All resources…

A lightweight Python module to interact with the [MITRE ATT&CK®](https://attack.mitre.org/) Enterprise dataset. Built for speed with minimal…

Automater - IP URL and MD5 OSINT Analysis

Gets updates from various clearnet domains and ransomware threat actor domains