Python Threatintel

Open-source Python projects categorized as Threatintel

Top 15 Python Threatintel Projects

  • spiderfoot

    SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

  • cowrie

    Cowrie SSH/Telnet Honeypot https://cowrie.readthedocs.io

  • Project mention: Brute.Fail Watch brute force attacks in real time | news.ycombinator.com | 2023-06-02

    Thanks for the reference; after some link chasing I was able to end up on the project I believe you're thinking of: https://github.com/cowrie/cowrie#features (appears to be BSD-3-Clause: https://github.com/cowrie/cowrie/blob/master/LICENSE.rst )

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • IntelOwl

    IntelOwl: manage your Threat Intelligence at scale

  • Project mention: Monthly Security Checklist | /r/msp | 2023-06-25
  • yeti

    Your Everyday Threat Intelligence

  • harpoon

    CLI tool for open source and threat intelligence (by Te-k)

  • ThreatIngestor

    Extract and aggregate threat intelligence.

  • iocextract

    Defanged Indicator of Compromise (IOC) Extractor.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • PyMISP

    Python library using the MISP Rest API

  • Project mention: FLaNK Stack Weekly for 13 November 2023 | dev.to | 2023-11-13
  • kestrel-lang

    Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.

  • threatbus

    🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.

  • malware-ioc

    This repository contains indicators of compromise (IOCs) of our various investigations. (by prodaft)

  • Project mention: PTI-257 Group Indicators of Compromise (IOCs) - PTI-257 consists of former Wizard Spider actors who are publicly known for the various malware variants they use (Ryuk, Trickbot, and Conti, among others) | /r/blueteamsec | 2023-09-14
  • Log4Shell-IOCs

    A collection of intelligence about Log4Shell and its exploitation activity.

  • MurMurHash

    This little tool is to calculate a MurmurHash value of a favicon to hunt phishing websites on the Shodan platform.

  • MISP-QRadar-Integration

    The Project can be used to integrate QRadar with MISP Threat Sharing Platform

  • MISP-tools

    Import CrowdStrike Threat Intelligence into your instance of MISP

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Python Threatintel related posts

Index

What are some of the best open-source Threatintel projects in Python? This list will help you:

Project Stars
1 spiderfoot 11,670
2 cowrie 4,904
3 IntelOwl 3,103
4 yeti 1,626
5 harpoon 1,133
6 ThreatIngestor 781
7 iocextract 485
8 PyMISP 418
9 kestrel-lang 273
10 threatbus 254
11 malware-ioc 196
12 Log4Shell-IOCs 184
13 MurMurHash 109
14 MISP-QRadar-Integration 36
15 MISP-tools 31

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com