
deepdarkCTI
Collection of Cyber Threat Intelligence sources from the deep and dark web

Collection of Cyber Threat Intelligence sources from the deep and dark web

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

A Software as a Service (SaaS) log collection framework.

IoCs and YARA rules from Threatray's Threat Research

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.

Static vulnerability findings tracker with parallel search across 11 CVE databases, EPSS enrichment, CISA KEV badges, coordinated disclosure…

Aggregate, filter, and track CVEs from multiple sources with team collaboration, custom dashboards, alerts, and AI-powered analysis for vulnerability…

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…


📡 Comprehensive collection of OSINT tools for cybersecurity professionals, researchers, and bug bounty hunters. Topics: information gathering,…

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…
