
PatrowlHears
Real-time vulnerability intelligence platform aggregating CVE, exploits, and threat news for SOC and threat hunting teams.

Real-time vulnerability intelligence platform aggregating CVE, exploits, and threat news for SOC and threat hunting teams.

Threat intel observatory aggregating CISA KEV, ThreatFox, URLhaus, and MalwareBazaar feeds with search, change tracking, and STIX/CSV/JSONL export.

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.

Message-queue-based threat intelligence feed collector and processor for CSIRTs. Automates ingestion, normalization, and sharing of security…

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Regularly updated Cisco Talos indicators of compromise, published alongside threat research and formatted for use in blocklists, detections, and…

Web interface for Suricata ruleset management, threat hunting, and rule tuning with multi-source feed aggregation, transformation, and activity…

Curated dataset of confirmed phishing URLs from JPCERT/CC, including confirmation date, full URL, and spoofed brand for threat intelligence and…

Searches For Threat Hunting and Security Analytics

Deploys an ELK-based SIEM to collect, parse, and visualize DShield honeypot sensor logs, with Filebeat ingestion, dashboards, and ISC threat…

Dynamically generated Suricata rules from real-time threat feeds

Curated collection of security advisories from Aqua Security, providing structured vulnerability data for threat intelligence and analysis.

Autonomous threat hunting framework for DFIR and SOC analysts. Performs static malware analysis, APT group attribution via genetic code analysis, and…

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

Deploy a TPOT honeypot for threat intelligence collection, real-time attack monitoring, and malicious IP aggregation with Elastic/Kibana log analysis.

Collection of Cyber Threat Intelligence sources from the deep and dark web