
capa
Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…


Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Passive hostname, domain and IP lookup tool for non-robots

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Clusters and elements to attach to MISP events or attributes (like threat actors)

Automater - IP URL and MD5 OSINT Analysis