
Malcolm
Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such…

Sophos-originated indicators-of-compromise from published reports

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.

ThePhish: an automated phishing email analysis tool

Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional…

STIX 2.1 collections of the MITRE ATT&CK knowledge base, providing adversary tactics and techniques for enterprise, mobile, and ICS threat…

Automated vulnerability data aggregator that collects advisories from NVD, OSV, Alpine, Red Hat, and 20+ other sources into a unified parsable format…


This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.

Threat Intel IoCs + bits and pieces of dark matter. Published by Gen Threat Labs.

Signatures and IoCs from public Volexity blog posts.

Scan files or process memory for CobaltStrike beacons and parse their configuration

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

Simple, effective, and modular package for parsing observables (indicators of compromise (IOCs), network data, and other, security related…