
inquisitor
Opinionated organisation-centric OSINT footprinting inspired from recon-ng and Maltego

Opinionated organisation-centric OSINT footprinting inspired from recon-ng and Maltego

A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

A YARA rules repository continuously updated for monitoring the old and new threats from articles, incidents responses ...

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT

Browser extension for OSINT that searches threat intelligence and reconnaissance data from selected IOCs (IP, domain, URL, hash, SNS) via multiple…

Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Group

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

Extract indicators of compromise from text, including "escaped" ones.

Generates unique fingerprints of malware HTTP requests from pcap files using Tshark, enabling identification and grouping of malware families through…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Collects static files from target domains to discover related domains and IPv4 addresses for threat intelligence and IOC enrichment.

Check if a IP is from tor or is a malicious proxy

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

Tool to predict attacker groups from the techniques and software used

IoCs and YARA rules from Threatray's Threat Research