threat-intelligence
Tracked open-source repos tagged threat-intelligence, sorted by stars.
- #31★ 1,370+0Star change over the last 7 days
- #32
Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
★ 1,367+0Star change over the last 7 days - #33★ 1,289+0Star change over the last 7 days
- #34
AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK framework. The tool generates tailored incident response scenarios based on user-selected threat actor groups and your organisation's details.
★ 1,239+0Star change over the last 7 days - #35
A curated list of annual cyber security reports
★ 1,190+0Star change over the last 7 days - #36
Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess
★ 1,182+0Star change over the last 7 days - #37
🚀🚀 This is a 🎇🔥 REAL WORLD🔥 🎇 Malware Collection I have Compiled & analysed by researchers🔥 to understand more about Malware threats😈, analysis and mitigation🧐.
★ 1,182+0Star change over the last 7 days - #38
Repositório criado com intuito de reunir expressões regulares dentro do contexto Brasil
★ 1,012+6Star change over the last 7 days - #39
openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.
★ 985+3Star change over the last 7 days - #40
This Repository is a collection of different ethical hacking tools and malware's for penetration testing and research purpose written in python, ruby, rust, c++, go and c.
★ 977+39Star change over the last 7 days - #41★ 942+0Star change over the last 7 days
- #42
This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.
★ 942+6Star change over the last 7 days - #43
Open source platform for cyber security analysts with many features for threat intelligence and detection engineering.
★ 941+4Star change over the last 7 days - #44
Extract and aggregate threat intelligence.
★ 925-1Star change over the last 7 days - #45
A collection of resources for Threat Hunters
★ 918+1Star change over the last 7 days - #46
Comprehensive 2026 OSINT guide — 450+ tools, AI intelligence, methodologies & ethics across 35 sections for investigation & threat intel.
★ 909+20Star change over the last 7 days - #47
The Big Brother V6.0 is a weaponized OSINT platform featuring username enumeration (473+ platforms), quad-vector visual intelligence, Sky Radar tracking, crypto wallet analysis, SSL intelligence, digital footprint reconstruction, EXIF extraction, advanced dorking, and network reconnaissance.
★ 758+3Star change over the last 7 days - #48
Automatically created C2 Feeds
★ 741-1Star change over the last 7 days - #49★ 728+0Star change over the last 7 days
- #50
Collection of knowledge about information security
★ 704+1Star change over the last 7 days - #51
Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and Flare.
★ 687+11Star change over the last 7 days - #52
A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.
★ 686+2Star change over the last 7 days - #53
Awesome list of keywords and artifacts for Threat Hunting sessions
★ 673+0Star change over the last 7 days - #54
Yet another Ransomware gang tracker
★ 669+4Star change over the last 7 days - #55
Warning lists to inform users of MISP about potential false-positives or other information in indicators
★ 649+0Star change over the last 7 days - #56
Awesome CSIRT is an curated list of links and resources in security and CSIRT daily activities.
★ 648+1Star change over the last 7 days - #57
Real-time OSINT command center for the Iran/Israel and Russia/Ukraine theaters — 50+ live open-source intelligence sources (news, Telegram, military aircraft & naval tracking, missile alerts, prediction & defense markets) in one dashboard. No API keys. Free. Next.js + TypeScript.
★ 640+13Star change over the last 7 days - #58
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
★ 639+5Star change over the last 7 days - #59
PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform
★ 638+0Star change over the last 7 days - #60
Clusters and elements to attach to MISP events or attributes (like threat actors)
★ 637-1Star change over the last 7 days