Back to Topics Directory
Topic Hub

#threat-intelligence (28 Repositories)

Ranked open-source repositories tagged with #threat-intelligence, scored by pull request acceptance likelihood and maintainer engagement velocity.

Topic Avg Merge Rate

18.5%

Avg Review Latency

28.7h

Filter by language

28 repositories tagged #threat-intelligence

B TierGo 102 1 GFIs

urlvet/urlvet

Open-source phishing detection engine with explainable verdict. Self-hostable alternative to VirusTotal, CheckPhish, URLScan.io

100.0%
Merge Rate
<1h
First Review
100%
1st-Timers
1
Maintainers
A TierPython 3.3k

kaifcodec/user-scanner

🕵️‍♂️ (2-in-1) Email & Username OSINT suite for deep data extraction just from a single Email/Username. Analyzes 440+ actively maintained scan vectors (170+ email / 270+ username) for security research, investigations, and digital footprinting.

84.4%
Merge Rate
13h
First Review
59%
1st-Timers
17
Maintainers
A TierPython 636

MISP/misp-galaxy

Clusters and elements to attach to MISP events or attributes (like threat actors)

96.3%
Merge Rate
12d
First Review
100%
1st-Timers
2
Maintainers
B TierPython 184

fhightower/ioc-finder

Simple, effective, and modular package for parsing observables (indicators of compromise (IOCs), network data, and other, security related information) from text. It uses grammars rather than regexes which makes it more readable, maintainable, and hackable. Explore our interactive documentation here: https://hightower.space/ioc-finder/

83.3%
Merge Rate
7d
First Review
100%
1st-Timers
1
Maintainers
A TierTypeScript 9.9k 1 GFIs

OpenCTI-Platform/opencti

Open Cyber Threat Intelligence Platform

76.2%
Merge Rate
4d
First Review
69%
1st-Timers
37
Maintainers
B TierPython 648

MISP/misp-warninglists

Warning lists to inform users of MISP about potential false-positives or other information in indicators

40.0%
Merge Rate
3h
First Review
50%
1st-Timers
2
Maintainers
B TierTypeScript 324

OTT-Cybersecurity-LLC/lyrie-ai

Lyrie.ai — The world's first autonomous AI cybersecurity agent. Built by OTT Cybersecurity LLC.

38.5%
Merge Rate
<1h
First Review
0%
1st-Timers
1
Maintainers
D TierPython 869

Bert-JanP/Open-Source-Threat-Intel-Feeds

This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.

0.0%
Merge Rate
9d
First Review
0%
1st-Timers
1
Maintainers
D TierPython 170

mthcht/ThreatIntel-Reports

Raw data from Threat Intelligence Reports with automatic reports collection and keyword search across thousands of reports

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 660

RansomLook/RansomLook

Yet another Ransomware gang tracker

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierC 647

Spacial/awesome-csirt

Awesome CSIRT is an curated list of links and resources in security and CSIRT daily activities.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 197

vmkspv/lenspect

A lightweight security threat scanner intended to make malware detection more accessible and efficient.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierHTML 338

lolc2/lolc2.github.io

lolC2 is a collection of C2 frameworks that leverage legitimate services to evade detection

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 983

atenreiro/opensquat

openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierHTML 318

Elemental-attack/Elemental

Elemental - An ATT&CK Threat Library

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 376

MISP/misp-modules

Modules for expansion services, enrichment, import and export in MISP and other tools.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierHTML 128

phishdestroy/namesilo-evidence

NameSilo (IANA #1479) registrar abuse investigation — 5,281,151 domains scanned, 204,460 classified IOC (122,119 HIGH), largely behind NameSilo's own PrivacyGuardian WHOIS shield. Filed with ICANN Mar 2026. Daily updated IOC feeds, SIEM CSV, operator clusters.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierGo 103

andreicscs/HoneyWire

HoneyWire: The Open-Source, Unlimited Deception Platform. Turn any Linux machine into an enterprise-grade canary in 60 seconds.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierGo 440

utkusen/baitroute

A web honeypot library to create vulnerable-looking endpoints to detect and mislead attackers

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierVUVue 255

HaoY-l/threat-intel-hub

🔥 一个集成多源威胁情报的聚合平台,为安全研究人员和运维团队提供实时威胁情报查询和播报服务;集成阿里云WAF主动拦截威胁IP,钓鱼邮件实时监测,集成AI等多项常用安全类工具🔧

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierJavaScript 344

prodaft/cradle

CRADLE is a collaborative platform for Cyber Threat Intelligence analysts. It streamlines threat investigations with integrated note-taking, automated data linking, interactive visualizations, and robust access control. Enhance your CTI workflow from analysis to reporting—all in one secure space.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 222

miunasu/IDA-Skill

使用skill让 AI Agent 像安全分析师一样分析恶意样本 | AI Agent skill for automated malware analysis using IDA Pro

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 342

wolffcatskyy/crowdsec-blocklist-import

10-20x more blocks for your CrowdSec bouncers — 120k+ IPs from 36 free threat feeds

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierHTML 1.6k

phishdestroy/destroylist

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierC 458

gendigitalinc/ioc

Threat Intel IoCs + bits and pieces of dark matter. Published by Gen Threat Labs.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 569

7onez/cti-expert

CTI Expert — Cyber Threat Intelligence & OSINT analysis skill for Claude Code. 67+ commands, 35 techniques, no API keys required.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 107

phishdestroy/nicenic-evidence

Complete zone scan of NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA #3765, China) — 376,687 domains tracked. 82,576 classified IOC (35,902 HIGH): phishing, carding, crypto drainers, malware, unlicensed gambling. IOC feeds, SIEM CSV, operator clusters. Evidence package for ICANN RAA complaint

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 2.7k

osintbrazuca/osint-brazuca

Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
Best Threat-intelligence Open Source Repositories & C-Rank™ | GetMerged