
crowdsec
Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Open-source threat intelligence platform for collecting, correlating, and sharing structured cybersecurity indicators, malware analysis, and attack…

Open Cyber Threat Intelligence Platform

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Collection of Cyber Threat Intelligence sources from the deep and dark web

Structured repository of Red Hat security advisories and vulnerability metadata, designed for integration into automated vulnerability scanning and…

Debian security vulnerability feed providing CVE data from the Debian Security Tracker for integration into vulnerability scanners and security tools.

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.

Automatically updated database of malicious Chrome/Edge extensions removed from web stores, with a cross-platform scanner to detect installed threats…

Advanced Phishing Protection: Suricata rulesets open and free

Trust & Safety tools for working together to fight digital harms.

Curated mirror of the National Vulnerability Database (NVD) providing structured CVE data for vulnerability research, threat intelligence, and…

Analysis and Representation of Graphs of Suspicious Operations (Analyse et Représentation des Graphes des Opérations Suspectes)

Clusters and elements to attach to MISP events or attributes (like threat actors)

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Automated ransomware and leak-site OSINT tracker scraping dark-web markets, monitoring victim posts, enriching actor/crypto data, and sending…