Threatintel

Top 23 Threatintel Open-Source Projects

  • spiderfoot

    SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

  • awesome-malware-analysis

    Defund the Police.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • MISP

    MISP (core software) - Open Source Threat Intelligence and Sharing Platform

  • Project mention: A recent abrupt change in Internet SSH brute force attacks against us | news.ycombinator.com | 2024-02-24
  • cowrie

    Cowrie SSH/Telnet Honeypot https://cowrie.readthedocs.io

  • Project mention: Brute.Fail Watch brute force attacks in real time | news.ycombinator.com | 2023-06-02

    Thanks for the reference; after some link chasing I was able to end up on the project I believe you're thinking of: https://github.com/cowrie/cowrie#features (appears to be BSD-3-Clause: https://github.com/cowrie/cowrie/blob/master/LICENSE.rst )

  • sysmon-config

    Sysmon configuration file template with default high-quality event tracing

  • Project mention: Software Hardening Tools for System Defense | dev.to | 2024-04-30

    cd c:\sysmon git clone https://github.com/SwiftOnSecurity/sysmon-config sysmon -accepteula -i sysmon-config/sysmon-config.xml

  • IntelOwl

    IntelOwl: manage your Threat Intelligence at scale

  • Project mention: Monthly Security Checklist | /r/msp | 2023-06-25
  • yeti

    Your Everyday Threat Intelligence

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
  • SysmonTools

    Utilities for Sysmon

  • harpoon

    CLI tool for open source and threat intelligence (by Te-k)

  • ThreatIngestor

    Extract and aggregate threat intelligence.

  • sysmon-config

    Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events. (by ion-storm)

  • ransomwatch

    the transparent ransomware claim tracker πŸ₯·πŸΌπŸ§…πŸ–₯️

  • Project mention: Las Vegas | news.ycombinator.com | 2023-09-16

    I don’t want to endorse this practice at all but because it is public knowledge,

    https://ransomwatch.telemetry.ltd

    I trust you will be able to figure out the rest.

  • iocextract

    Defanged Indicator of Compromise (IOC) Extractor.

  • awesome-intelligence-writing

    Awesome collection of great and useful resources concerning intelligence writing such as manuals/guides, standards, books, and articles

  • C2IntelFeeds

    Automatically created C2 Feeds

  • PyMISP

    Python library using the MISP Rest API

  • Project mention: FLaNK Stack Weekly for 13 November 2023 | dev.to | 2023-11-13
  • misp-training

    MISP trainings, threat intel and information sharing training materials with source code

  • Zeek-Intelligence-Feeds

    Zeek-Formatted Threat Intelligence Feeds

  • kestrel-lang

    Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.

  • threatbus

    🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.

  • CloudIntel

    This repo contains IOC, malware and malware analysis associated with Public cloud

  • Project mention: A list of SaaS, PaaS and IaaS offerings that have free tiers of interest to devops and infradev | dev.to | 2024-02-05

    Public Cloud Threat Intelligence β€” High confidence Indicator of Compromise(IOC) targeting public cloud infrastructure, A portion is available on github (https://github.com/unknownhad/AWSAttacks). Full list is available via API

  • malware-ioc

    This repository contains indicators of compromise (IOCs) of our various investigations. (by prodaft)

  • Project mention: PTI-257 Group Indicators of Compromise (IOCs) - PTI-257 consists of former Wizard Spider actors who are publicly known for the various malware variants they use (Ryuk, Trickbot, and Conti, among others) | /r/blueteamsec | 2023-09-14
  • Log4Shell-IOCs

    A collection of intelligence about Log4Shell and its exploitation activity.

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Threatintel related posts

  • Software Hardening Tools for System Defense

    1 project | dev.to | 30 Apr 2024
  • A recent abrupt change in Internet SSH brute force attacks against us

    1 project | news.ycombinator.com | 24 Feb 2024
  • Las Vegas

    1 project | news.ycombinator.com | 16 Sep 2023
  • Troubleshooting Intermittent Slowness on Network Share

    1 project | /r/msp | 7 Jul 2023
  • Sysmon not reading our config.xml-file

    1 project | /r/sysadmin | 21 Jun 2023
  • Cheap, Fast, Good and Simple Remote Monitoring for Small Environments

    1 project | /r/msp | 31 May 2023
  • How do I exclude specific event IDs in Sysmon?

    1 project | /r/sysadmin | 15 Apr 2023
  • A note from our sponsor - SaaSHub
    www.saashub.com | 4 May 2024
    SaaSHub helps you find the best software and product alternatives Learn more β†’

Index

What are some of the best open-source Threatintel projects? This list will help you:

Project Stars
1 spiderfoot 11,768
2 awesome-malware-analysis 11,071
3 MISP 4,998
4 cowrie 4,910
5 sysmon-config 4,580
6 IntelOwl 3,114
7 yeti 1,633
8 SysmonTools 1,449
9 harpoon 1,134
10 ThreatIngestor 786
11 sysmon-config 750
12 ransomwatch 747
13 iocextract 486
14 awesome-intelligence-writing 463
15 C2IntelFeeds 438
16 PyMISP 422
17 misp-training 357
18 Zeek-Intelligence-Feeds 314
19 kestrel-lang 274
20 threatbus 254
21 CloudIntel 220
22 malware-ioc 197
23 Log4Shell-IOCs 184

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com