
AIL-framework
Open-source framework for collecting, crawling, processing, and analyzing unstructured data from web, darknet, chats, and files. Supports threat…

Open-source framework for collecting, crawling, processing, and analyzing unstructured data from web, darknet, chats, and files. Supports threat…

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational…

Automated ransomware and leak-site OSINT tracker scraping dark-web markets, monitoring victim posts, enriching actor/crypto data, and sending…

Threat hunting framework that scans websites for malicious objects using Yara rules, URLhaus feeds, TLSH hashing, and deep object extraction, with…

Research framework for collecting, analyzing, and tracking phishing sites. Uses headless Chromium to capture rendered HTML, screenshots, network…

OSINT intelligence on any IP, domain, or ASN

Automated crawler that retrieves VEX (Vulnerability Exploitability eXchange) documents from package source repositories, validates them by PURL, and…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Advanced Phishing Protection: Suricata rulesets open and free

3D threat intelligence dashboard that visualizes malicious infrastructure from OSINT sources like AbuseIPDB and OpenPhish, with a live threat feed,…

Dynamically generated Suricata rules from real-time threat feeds

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Web-based vulnerability fix tracker for Alpine Linux that ingests security databases and NVD feeds to monitor CVE fix status across packages.

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

Gets updates from various clearnet domains and ransomware threat actor domains

Cyber Threat Intelligence (CTI) usando fontes e indicadores de ameaças nacionais, ou até globais, mas com evidencias ou indicadores nacionais do…