id name topics description
4165675 spiderfoot
  • attack-surface
  • attacksurface
  • cti
  • cybersecurity
  • footprinting
  • hacking
  • information-gathering
  • infosec
  • intelligence-gathering
  • osint
  • osint-framework
  • osint-reconnaissance
  • osint-tool
  • pentest
  • pentesting
  • python
  • reconnaissance
  • security-tools
  • threat-intelligence
  • threatintel
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
48368290 awesome-threat-intelligence
  • awesome
  • hacktoberfest
  • security
A curated list of Awesome Threat Intelligence resources
8077402 MISP
  • cti
  • cybersecurity
  • fraud-detection
  • fraud-management
  • fraud-prevention
  • information-exchange
  • information-security
  • information-sharing
  • intelligence
  • malware-analysis
  • misp
  • security
  • stix
  • threat-analysis
  • threat-hunting
  • threat-intel
  • threat-intelligence
  • threat-intelligence-platform
  • threat-sharing
  • threatintel
MISP (core software) - Open Source Threat Intelligence and Sharing Platform
162200234 opencti
  • cti
  • cyber
  • cybersecurity
  • intelligence
  • osint
  • security
  • threat-intelligence
Open Cyber Threat Intelligence Platform
69111161 rita
  • analysis
  • analytics
  • beacon
  • beacon-sniffer
  • bhis
  • blueteam
  • bro-ids
  • dga
  • dns
  • dns-tunneling
  • logs
  • network-traffic
  • offensive-countermeasures
  • rita
  • scanning
  • security
  • threat
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
47927876 yeti
  • dfir
  • enrichment
  • infosec
  • intelligence
  • threat-hunting
  • threat-sharing
  • threatintel
Your Everyday Threat Intelligence
93423332 cti
  • attack
  • cti
  • cyber-threat-intelligence
  • stix
Cyber Threat Intelligence Repository expressed in STIX 2.0
296104714 ThreatPursuit-VM
  • analytics
  • cyber
  • data-science
  • fireeye
  • intelligence
  • intelligence-analysis
  • malware
  • mandiant
  • threat
  • threathunting
  • threatintelligence
  • virtual-machine
Threat Pursuit Virtual Machine (VM): A fully customizable. open-sourced Windows-based distribution focused on threat intelligence analysis and hunting designed for intel and malware analysts as well as threat hunters to get up and running quickly.
104700494 harpoon
  • osint
  • osint-framework
  • threat-intelligence
  • threatintel
CLI tool for open source and threat intelligence
10179504 vFeed
  • capec
  • common-vulnerability-exposure
  • cve
  • cwe
  • exploits
  • intelligence-gathering
  • oval
  • python
  • scap
  • threat
  • threat-intelligence
  • threat-intelligence-database
  • threatintel
  • vfeed
  • vulnerability
  • vulnerability-database-entry
  • vulnerability-databases
  • vulnerability-detection
  • vulnerability-identification
  • vulnerability-scanners
The Correlated CVE Vulnerability And Threat Intelligence Database API
171915396 msticpy
Microsoft Threat Intelligence Security Tools
463648576 Ukraine-Cyber-Operations
  • cti
  • iocs
  • malware
  • osint
  • threat-hunting
  • threat-intelligence
  • ukraine
  • yara
Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional free threat intelligence. Slava Ukraini. Glory to Ukraine.
21160389 intelmq
  • alerts
  • automation
  • cert
  • csirt
  • cybersecurity
  • feeds
  • handling
  • ihap
  • incident
  • incident-response
  • intelligence
  • ioc
  • malware
  • phishing
  • python
  • threat
IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
17064089 combine
Tool to gather Threat Intelligence indicators from publicly available sources
372053381 deepdarkCTI
  • cti
  • cyberhunter
  • darkweb
  • deepweb
  • threat-intelligence
Collection of Cyber Threat Intelligence sources from the deep and dark web
346247042 tig
Threat Intelligence Gathering 威胁情报收集,旨在提高蓝队拿到攻击 IP 后对其进行威胁情报信息收集的效率。
102033255 ThreatIngestor
  • dfir
  • fraud-detection
  • indicators-of-compromise
  • intelligence-gathering
  • ioc
  • malware-research
  • misp
  • osint
  • security-tools
  • soar
  • threat-analysis
  • threat-feeds
  • threat-hunting
  • threat-intelligence
  • threat-intelligence-platform
  • threat-sharing
  • threatintel
  • yara
Extract and aggregate threat intelligence.
187063664 awesome_Threat-Hunting
A curated list of the most important and useful resources about Threat Detection.Hunting and Intelligence.
97925391 threat-intelligence
收集的一些国外能提供提供威胁情报的公司,涵盖网络安全、工控安全、终端安全、移动安全等领域
31442410 malsub
  • api-client
  • cybersecurity
  • malware
  • malware-analysis
  • python
  • restful
  • restful-client
  • virustotal
A Python RESTful API framework for online malware analysis and threat intelligence services.
99188653 CyBot
Open Source Threat Intelligence Chat Bot
75892080 Threat-Intelligence-Analyst
威胁情报,恶意样本分析,开源Malware代码收集
30200955 threat_intel
Threat Intelligence APIs
378575559 ARTIF
An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.
168499203 threatbus
  • cif
  • cif3
  • ids
  • misp
  • opencti
  • opencti-connector
  • sightings
  • threat-bus
  • threat-hunting
  • threat-intelligence
  • threat-intelligence-data
  • threatintel
  • zeek
🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.
24228422 bearded-avenger
  • cif
  • cifv3
  • security
  • threat-hunting
  • threat-sharing
  • threatintel
CIF v3 -- the fastest way to consume threat intelligence
108266113 misp-dashboard
  • cyber-security
  • cybersecurity
  • dashboard
  • misp
  • threat-intelligence
  • threatintel
A dashboard for a real-time overview of threat intelligence from MISP instances
18271023 tiq-test
Threat Intelligence Quotient Test - Dataviz and Statistical Analysis of TI feeds
17264589 Forager
  • carbonblack
  • python
  • threatintel
Multithreaded threat Intelligence gathering built with Python3
173667523 exist
EXIST is a web application for aggregating and analyzing cyber threat intelligence.
93520200 act-platform
Open platform for collection and exchange of threat intelligence information
68172388 graylog-plugin-threatintel
  • abuse
  • graylog
  • graylog-plugin
  • otx
  • spamhaus
  • threat
  • threat-analysis
  • threat-score
  • threatintel
  • whois
  • whois-information
  • whois-lookup
Graylog Processing Pipeline functions to enrich log messages with IoC information from threat intelligence databases
246581488 jeopardize
a low(zero) cost threat intelligence&response tool against phishing domains
41807769 Threat-Intelligence-Hunter
TIH is an intelligence tool that helps you in searching for IOCs across multiple openly available security feeds and some well known APIs. The idea behind the tool is to facilitate searching and storing of frequently added IOCs for creating your own local database of indicators.
20443662 Threatelligence
Threatelligence is a simple cyber threat intelligence feed collector. using Elasticsearch. Kibana and Python to automatically collect intelligence from custom or public sources. Automatically updates feeds and tries to further enhance data for dashboards.
289010287 Zeek-Intelligence-Feeds
  • threat-intelligence
  • threatintel
Zeek-Formatted Threat Intelligence Feeds
463563798 russia-ukraine_IOCs
Russia / Ukraine 2022 conflict related IOCs from CERT Orange Cyberdefense Threat Intelligence Datalake
50126380 goatrider
GoatRider is a simple tool that will dynamically pull down Artillery Threat Intelligence Feeds. TOR. AlienVaults OTX. and the Alexa top 1 million websites and do a comparison to a hostname file or IP file.
235067960 PatrowlHears
  • api
  • automation
  • cpe
  • cve
  • cvss
  • cybersecurity
  • exploits
  • exploits-scripts
  • patrowl
  • secops
  • soc
  • threat
  • threat-hunting
  • threat-intelligence
  • threatintel
  • vulnerabilities
  • vulnerability-detection
  • vulnerability-identification
  • vulnerability-intelligence
  • vulnerability-scanning
PatrowlHears - Vulnerability Intelligence Center / Exploits
434564586 RITA-J
  • cybersecurity
  • data-science
  • dfir
  • jupyter-notebook
  • threat-hunting
Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.
40135809 TARDIS
Threat Analysis. Reconnaissance. and Data Intelligence System
297733895 tram
  • ctid
  • cyber-threat-intelligence
  • cybersecurity
  • mitre-attack
  • threat-informed-defense
TRAM is an open-source platform designed to advance research into automating the mapping of cyber threat intelligence reports to MITRE ATT&CK®.
234384059 Open-source-tools-for-CTI
  • cti
  • cybersecurity
  • infosec
  • malware
  • osint
  • threatintel
Public Repository of Open Source Tools for Cyber Threat Intelligence Analysts and Researchers
73500884 Threat_Intelligence
Threat-Intelligence Feeds & Tools & Frameworks
260504175 threatnote
threatnote.io | Cyber Threat Intelligence Notebook
337266798 TwiTi
  • threat-intelligence
This is a project of "#Twiti: Social Listening for Threat Intelligence" (TheWebConf 2021)
53153004 QRadio
QRadio ~ Best Threat Intelligence Radio ~ Tune In!
106653507 ioc2rpz
  • blacklist
  • dns
  • dns-firewall
  • dns-server
  • ioc
  • malware-protection
  • rpz
  • rpz-feed
  • threat-intelligence
ioc2rpz is a place where threat intelligence meets DNS.
33993053 tic
Bit9 + Carbon Black Threat Intelligence
138835471 blockchain-threat-intelligence
  • blockchain
  • hacking
  • honeypot
  • security
  • threat-intelligence
Blockchain Threat Intelligence Sharing Platform(区块链威胁情报共享平台)