
auditd-attack
A Linux Auditd rule set mapped to MITRE's Attack Framework

A Linux Auditd rule set mapped to MITRE's Attack Framework

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

Curated JSON object templates that define MISP attributes and relationship types for structured threat intelligence sharing and interoperable IOC…

Pulled Pork for Snort and Suricata rule management (from Google code)

Cyber Threat Defense World Modeling


Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Gets updates from various clearnet domains and ransomware threat actor domains

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

Reproducible SOC lab for CVE-2024-4577 detection and response

Malicious Extension Database

Curated collection of cybersecurity resources, labs, and training materials covering ethical hacking, penetration testing, exploit development,…

Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational…

Collection of Cyber Threat Intelligence sources from the deep and dark web

Curated directory of threat intelligence sources, feeds, frameworks, tools, and research for SOC/CTI teams—covering IOCs, STIX/TAXII formats, and…

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…