Python threat-intelligence

Open-source Python projects categorized as threat-intelligence

Top 23 Python threat-intelligence Projects

  • spiderfoot

    SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

  • dnstwist

    Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

  • Project mention: Have I Been Squatted? | news.ycombinator.com | 2023-11-27
  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • IntelOwl

    IntelOwl: manage your Threat Intelligence at scale

  • Project mention: Monthly Security Checklist | /r/msp | 2023-06-25
  • Digital-Forensics-Guide

    Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

  • Project mention: Most used DFIR tools | /r/cybersecurity | 2023-12-10

    If you're looking to learn on your own, try mikeroyal's digital forensics guide on Github. There's a lot of recommended resources there that'll speed you up. https://github.com/mikeroyal/Digital-Forensics-Guide

  • harpoon

    CLI tool for open source and threat intelligence (by Te-k)

  • ThePhish

    ThePhish: an automated phishing email analysis tool

  • Project mention: How do you deal with phising emails at your company? | /r/cybersecurity | 2023-05-14
  • Watcher

    Watcher - Open Source Cybersecurity Threat Hunting Platform. Developed with Django & React JS. (by Felix83000)

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • CyberThreatHunting

    A collection of resources for Threat Hunters - Sponsored by Falcon Guard

  • ThreatIngestor

    Extract and aggregate threat intelligence.

  • opensquat

    The openSquat is an open-source tool for detecting domain look-alikes by searching for newly registered domains that might be impersonating legit domains.

  • Project mention: Have I Been Squatted? | news.ycombinator.com | 2023-11-27

    A different solution that runs locally is opensquat.

    https://github.com/atenreiro/opensquat

  • Scrummage

    The Ultimate OSINT and Threat Hunting Framework

  • iocextract

    Defanged Indicator of Compromise (IOC) Extractor.

  • misp-galaxy

    Clusters and elements to attach to MISP events or attributes (like threat actors)

  • Project mention: Foreign Travel Risks | /r/cybersecurity | 2023-04-26

    MISP Threat Actor Galaxy

  • misp-warninglists

    Warning lists to inform users of MISP about potential false-positives or other information in indicators

  • Project mention: Lists | news.ycombinator.com | 2023-04-27
  • misp-modules

    Modules for expansion services, enrichment, import and export in MISP and other tools. (by MISP)

  • connectors

    OpenCTI Connectors (by OpenCTI-Platform)

  • Project mention: How to integrate openCTI with Splunk? | /r/threatintel | 2023-07-12

    Connector on GitHub - https://github.com/OpenCTI-Platform/connectors/tree/master/stream/splunk

  • kestrel-lang

    Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.

  • threatbus

    🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.

  • malware-ioc

    This repository contains indicators of compromise (IOCs) of our various investigations. (by prodaft)

  • Project mention: PTI-257 Group Indicators of Compromise (IOCs) - PTI-257 consists of former Wizard Spider actors who are publicly known for the various malware variants they use (Ryuk, Trickbot, and Conti, among others) | /r/blueteamsec | 2023-09-14
  • MISP-maltego

    Set of Maltego transforms to inferface with a MISP Threat Sharing instance, and also to explore the whole MITRE ATT&CK dataset.

  • TwiTi

    This is a project of "#Twiti: Social Listening for Threat Intelligence" (TheWebConf 2021)

  • kc7

    A cybersecurity game in Azure Data Explorer

  • TypeDB CTI

    Open Source Threat Intelligence Platform

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Python threat-intelligence related posts

Index

What are some of the best open-source threat-intelligence projects in Python? This list will help you:

Project Stars
1 spiderfoot 11,723
2 dnstwist 4,535
3 IntelOwl 3,103
4 Digital-Forensics-Guide 1,335
5 harpoon 1,133
6 ThePhish 1,005
7 Watcher 795
8 CyberThreatHunting 792
9 ThreatIngestor 781
10 opensquat 648
11 Scrummage 488
12 iocextract 485
13 misp-galaxy 480
14 misp-warninglists 475
15 misp-modules 324
16 connectors 324
17 kestrel-lang 273
18 threatbus 254
19 malware-ioc 196
20 MISP-maltego 165
21 TwiTi 163
22 kc7 156
23 TypeDB CTI 134

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com