
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

😱 A curated list of amazingly awesome OSINT

Cyber threat intelligence platform for SSL certificate discovery, domain/URL scanning, data leak monitoring, tracking link generation, and threat…

This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such…

Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational…

STIX 2.1 collections of the MITRE ATT&CK knowledge base, providing adversary tactics and techniques for enterprise, mobile, and ICS threat…


Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…


Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Advanced Phishing Protection: Suricata rulesets open and free

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Clusters and elements to attach to MISP events or attributes (like threat actors)

OSINT intelligence on any IP, domain, or ASN