
TekDefense-Automater
Automater - IP URL and MD5 OSINT Analysis

Automater - IP URL and MD5 OSINT Analysis

A tool to assist with network-based hunting for GRU's Drovorub malware c2


Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Analysis and Representation of Graphs of Suspicious Operations (Analyse et Représentation des Graphes des Opérations Suspectes)

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

CLI client for abuse.ch

Live Feed of C2 servers, tools, and botnets

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

A repo to hold KQL queries as part of my 100 days of KQL effort.

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.

A collection of IOCs for CVE-2021-44228 also known as Log4Shell

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Passive hostname, domain and IP lookup tool for non-robots