
exist
EXIST is a web application for aggregating and analyzing cyber threat intelligence.

Collection of Cyber Threat Intelligence sources from the deep and dark web

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

Web interface for Suricata ruleset management, threat hunting, and rule tuning with multi-source feed aggregation, transformation, and activity…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…


Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Automated ransomware and leak-site OSINT tracker scraping dark-web markets, monitoring victim posts, enriching actor/crypto data, and sending…

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

Automater - IP URL and MD5 OSINT Analysis

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

Gets updates from various clearnet domains and ransomware threat actor domains