
misp-galaxy
Clusters and elements to attach to MISP events or attributes (like threat actors)

Clusters and elements to attach to MISP events or attributes (like threat actors)

Trust & Safety tools for working together to fight digital harms.

Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

DShield Sensor Log Collection with ELK

Signatures and IoCs from public Volexity blog posts.

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional…

CLI client for abuse.ch

Latest CVEs with their Proof of Concept exploits.

A lightweight Python module to interact with the [MITRE ATT&CK®](https://attack.mitre.org/) Enterprise dataset. Built for speed with minimal…


Automater - IP URL and MD5 OSINT Analysis

Proofpoint - Emerging Threats - Threat Research tools + publicly shared intel and documentation


DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…