
wtfis
Passive hostname, domain and IP lookup tool for non-robots

Passive hostname, domain and IP lookup tool for non-robots

PowerShell-based guided hunting tool for Microsoft 365 Defender that automates alert triage, entity enrichment, and IOC lookups across email and…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.

Message-queue-based threat intelligence feed collector and processor for CSIRTs. Automates ingestion, normalization, and sharing of security…

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

Real-time vulnerability intelligence platform aggregating CVE, exploits, and threat news for SOC and threat hunting teams.

Curated repository of IOCs and threat intelligence from the Expel Intel Team, providing actionable indicators for detection and response workflows.

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

Command-line client for abuse.ch threat intelligence APIs, enabling query and retrieval of Indicators of Compromise (IOCs) for threat hunting and…

Framework for collecting, processing, and exporting high-quality indicators of compromise (IOCs) to enrich security operations with structured threat…

Analysis and Representation of Graphs of Suspicious Operations (Analyse et Représentation des Graphes des Opérations Suspectes)

Defanged Indicator of Compromise (IOC) Extractor.

Structured repository of Red Hat security advisories and vulnerability metadata, designed for integration into automated vulnerability scanning and…

3D threat intelligence dashboard that visualizes malicious infrastructure from OSINT sources like AbuseIPDB and OpenPhish, with a live threat feed,…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Automated ransomware and leak-site OSINT tracker scraping dark-web markets, monitoring victim posts, enriching actor/crypto data, and sending…

Threat hunting framework that scans websites for malicious objects using Yara rules, URLhaus feeds, TLSH hashing, and deep object extraction, with…