#threat-intelligence (28 Repositories)
Ranked open-source repositories tagged with #threat-intelligence, scored by pull request acceptance likelihood and maintainer engagement velocity.
18.5%
28.7h
28 repositories tagged #threat-intelligence
urlvet/urlvet
Open-source phishing detection engine with explainable verdict. Self-hostable alternative to VirusTotal, CheckPhish, URLScan.io
kaifcodec/user-scanner
🕵️♂️ (2-in-1) Email & Username OSINT suite for deep data extraction just from a single Email/Username. Analyzes 440+ actively maintained scan vectors (170+ email / 270+ username) for security research, investigations, and digital footprinting.
MISP/misp-galaxy
Clusters and elements to attach to MISP events or attributes (like threat actors)
fhightower/ioc-finder
Simple, effective, and modular package for parsing observables (indicators of compromise (IOCs), network data, and other, security related information) from text. It uses grammars rather than regexes which makes it more readable, maintainable, and hackable. Explore our interactive documentation here: https://hightower.space/ioc-finder/
OpenCTI-Platform/opencti
Open Cyber Threat Intelligence Platform
MISP/misp-warninglists
Warning lists to inform users of MISP about potential false-positives or other information in indicators
OTT-Cybersecurity-LLC/lyrie-ai
Lyrie.ai — The world's first autonomous AI cybersecurity agent. Built by OTT Cybersecurity LLC.
Bert-JanP/Open-Source-Threat-Intel-Feeds
This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.
mthcht/ThreatIntel-Reports
Raw data from Threat Intelligence Reports with automatic reports collection and keyword search across thousands of reports
RansomLook/RansomLook
Yet another Ransomware gang tracker
Spacial/awesome-csirt
Awesome CSIRT is an curated list of links and resources in security and CSIRT daily activities.
vmkspv/lenspect
A lightweight security threat scanner intended to make malware detection more accessible and efficient.
lolc2/lolc2.github.io
lolC2 is a collection of C2 frameworks that leverage legitimate services to evade detection
atenreiro/opensquat
openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.
Elemental-attack/Elemental
Elemental - An ATT&CK Threat Library
MISP/misp-modules
Modules for expansion services, enrichment, import and export in MISP and other tools.
phishdestroy/namesilo-evidence
NameSilo (IANA #1479) registrar abuse investigation — 5,281,151 domains scanned, 204,460 classified IOC (122,119 HIGH), largely behind NameSilo's own PrivacyGuardian WHOIS shield. Filed with ICANN Mar 2026. Daily updated IOC feeds, SIEM CSV, operator clusters.
andreicscs/HoneyWire
HoneyWire: The Open-Source, Unlimited Deception Platform. Turn any Linux machine into an enterprise-grade canary in 60 seconds.
utkusen/baitroute
A web honeypot library to create vulnerable-looking endpoints to detect and mislead attackers
HaoY-l/threat-intel-hub
🔥 一个集成多源威胁情报的聚合平台,为安全研究人员和运维团队提供实时威胁情报查询和播报服务;集成阿里云WAF主动拦截威胁IP,钓鱼邮件实时监测,集成AI等多项常用安全类工具🔧
prodaft/cradle
CRADLE is a collaborative platform for Cyber Threat Intelligence analysts. It streamlines threat investigations with integrated note-taking, automated data linking, interactive visualizations, and robust access control. Enhance your CTI workflow from analysis to reporting—all in one secure space.
miunasu/IDA-Skill
使用skill让 AI Agent 像安全分析师一样分析恶意样本 | AI Agent skill for automated malware analysis using IDA Pro
wolffcatskyy/crowdsec-blocklist-import
10-20x more blocks for your CrowdSec bouncers — 120k+ IPs from 36 free threat feeds
phishdestroy/destroylist
Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats
gendigitalinc/ioc
Threat Intel IoCs + bits and pieces of dark matter. Published by Gen Threat Labs.
7onez/cti-expert
CTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code. 67+ commands, 35 techniques, no API keys required.
phishdestroy/nicenic-evidence
Complete zone scan of NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA #3765, China) — 376,687 domains tracked. 82,576 classified IOC (35,902 HIGH): phishing, carding, crypto drainers, malware, unlicensed gambling. IOC feeds, SIEM CSV, operator clusters. Evidence package for ICANN RAA complaint
osintbrazuca/osint-brazuca
Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.