
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Cyber threat intelligence platform for SSL certificate discovery, domain/URL scanning, data leak monitoring, tracking link generation, and threat…

Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…


Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…


Trust & Safety tools for working together to fight digital harms.

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Latest CVEs with their Proof of Concept exploits.


Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Clusters and elements to attach to MISP events or attributes (like threat actors)

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

PatrowlHears - Vulnerability Intelligence Center / Exploits