
capa
Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Modular OSINT analysis tool automating lookups of IP addresses, URLs, and MD5 hashes across multiple sources, with configurable XML-based source…

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Passive hostname, domain and IP lookup tool for non-robots

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

PowerShell-based guided hunting tool for Microsoft 365 Defender that automates alert triage, entity enrichment, and IOC lookups across email and…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Rust-based pattern matching engine for malware researchers. Create YARA rules with textual/binary patterns, wildcards, and regex to identify and…

Clusters and elements to attach to MISP events or attributes (like threat actors)