
drovorub-hunt
A tool to assist with network-based hunting for GRU's Drovorub malware c2

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

Clusters and elements to attach to MISP events or attributes (like threat actors)

Automater - IP URL and MD5 OSINT Analysis


Passive hostname, domain and IP lookup tool for non-robots

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

DShield Sensor Log Collection with ELK

Trust & Safety tools for working together to fight digital harms.

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

EXIST is a web application for aggregating and analyzing cyber threat intelligence.

PatrowlHears - Vulnerability Intelligence Center / Exploits

Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional…

Dynamically generated Suricata rules from real-time threat feeds

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project