
ThreatExchange
Trust & Safety tools for working together to fight digital harms.

Trust & Safety tools for working together to fight digital harms.

Open-source Android client for VirusTotal. Scan files, URLs, and installed apps against 70+ antivirus engines. View detailed reports with hashes,…

Online hash checker for Virustotal and other services

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Advanced Static malware analyzer that reveals 8 injection techniques, critical API calls, hidden strings, exports PE sections (.text, .rdata) as…

Active TLS server fingerprinting tool that sends crafted Client Hello packets to generate unique JARM hashes for identifying server configurations,…

Hashes and shim versions for the UEFI Secure Boot shims affected by CVE-2026-8863

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

Recursively scan folders with VirusTotal API to detect malware. Features hash lookup, CSV export, real-time progress, and rate-limit handling for…

A Pythonic interface and command line tool for interacting with the InQuest Labs API.


Open YARA scan- and search engine

Curated collection of indicators of compromise extracted from real-world malware investigations, including hashes, domains, and IPs for threat…

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.