
mihari
A query aggregator for OSINT based threat hunting

A query aggregator for OSINT based threat hunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Automater - IP URL and MD5 OSINT Analysis

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework

66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit…

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

Gets updates from various clearnet domains and ransomware threat actor domains

Defanged Indicator of Compromise (IOC) Extractor.

Malicious Extension Database

Proofpoint - Emerging Threats - Threat Research tools + publicly shared intel and documentation

Don't Just Search OSINT. Sweep It.

📕NVD Database

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

PatrowlHears - Vulnerability Intelligence Center / Exploits