
capa
Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

3D threat intelligence dashboard that visualizes malicious infrastructure from OSINT sources like AbuseIPDB and OpenPhish, with a live threat feed,…

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such…


Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

Automater - IP URL and MD5 OSINT Analysis

Live Feed of C2 servers, tools, and botnets

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Curated JSON object templates that define MISP attributes and relationship types for structured threat intelligence sharing and interoperable IOC…

This is the home of the Expel Intel Team. Here, we will share IOCs and other information that is either not suitable for fitting into other mediums…

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

A resource containing all the tools each ransomware gangs uses