
capa
Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Rust-based pattern matching engine for malware researchers. Create YARA rules with textual/binary patterns, wildcards, and regex to identify and…

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Passive hostname, domain and IP lookup tool for non-robots

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Modular OSINT analysis tool automating lookups of IP addresses, URLs, and MD5 hashes across multiple sources, with configurable XML-based source…

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

PowerShell-based guided hunting tool for Microsoft 365 Defender that automates alert triage, entity enrichment, and IOC lookups across email and…

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

Clusters and elements to attach to MISP events or attributes (like threat actors)

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.