
libtaxii
A Python library for handling TAXII Messages invoking TAXII Services.

A Python library for handling TAXII Messages invoking TAXII Services.

DShield Sensor Log Collection with ELK

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups

A repo to hold KQL queries as part of my 100 days of KQL effort.

Advanced Phishing Protection: Suricata rulesets open and free

Cyber Threat Defense World Modeling

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

OSINT intelligence on any IP, domain, or ASN

Public repository of Sigma and YARA rules created by Synacktiv

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

Collect VEX documents and update VEX Hub

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…