Awesome Lists

awesome-threat-intelligence

by hslatman

awesome listpushed about 2 years ago

A curated list of Awesome Threat Intelligence resources

AI summary

Threat intel resource

A curated collection of resources and tools for gathering, analyzing, and sharing threat intelligence.

stars
8.2K
forks
1.5K
watching
568
awesome lists
10
entries
266
View on GitHub

Embed the badge

Show how many awesome lists link to your project. The count updates automatically.

Awesome Lists badge
Markdown
[![Awesome Lists Badge](https://awesome.facts.dev/shield/hslatman/awesome-threat-intelligence/links.svg)](https://awesome.facts.dev/awesome/hslatman/awesome-threat-intelligence)
HTML
<a href="https://awesome.facts.dev/awesome/hslatman/awesome-threat-intelligence"><img src="https://awesome.facts.dev/shield/hslatman/awesome-threat-intelligence/links.svg" alt="Awesome Lists Badge" /></a>
Image URL
https://awesome.facts.dev/shield/hslatman/awesome-threat-intelligence/links.svg

What's in the list

266 links in 5 sections, with live GitHub stats.activeno commit in 2y

Sources

Formats

  • here

    The Structured Threat Information eXpression (STIX) language is a standardized construct to represent cyber threat information. The STIX Language intends to convey the full range of potential cyber threat information and strives to be fully expressive, flexible, extensible, and automatable. STIX does not only allow tool-agnostic fields, but also provides so-called that provide means for embedding tool-specific elements, including OpenIOC, Yara and Snort. STIX 1.x has been archived

  • DBIR

    The Vocabulary for Event Recording and Incident Sharing (VERIS) is a set of metrics designed to provide a common language for describing security incidents in a structured and repeatable manner. VERIS is a response to one of the most critical and persistent challenges in the security industry - a lack of quality information. In addition to providing a structured format, VERIS also collects data from the community to report on breaches in the Verizon Data Breach Investigations Report ( ) and publishes this database online in a GitHub

Frameworks and Platforms

  • GitHub

    The Collective Intelligence Framework (CIF) allows you to combine known malicious threat information from many sources and use that information for IR, detection and mitigation. Code available on

  • pyintelowl

    Intel Owl is an OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API at scale. Intel Owl is composed of analyzers that can be run to retrieve data from external sources (like VirusTotal or AbuseIPDB) or to generate intel from internal analyzers (like Yara or Oletools). It can be integrated easily in your stack of security tools ( ) to automate common jobs usually performed, for instance, by SOC analysts manually

  • CERT Polska

    n6 (Network Security Incident eXchange) is a system to collect, manage and distribute security information on a large scale. Distribution is realized through a simple REST API and a web interface that authorized users can use to receive various types of data, in particular information on threats and incidents in their networks. It is developed by

  • here

    stoQ is a framework that allows cyber analysts to organize and automate repetitive, data-driven tasks. It features plugins for many other systems to interact with. One use case is the extraction of IOCs from documents, an example of which is shown , but it can also be used for deobfuscationg and decoding of content and automated scanning with YARA, for example

  • GitHub

    Facebook created ThreatExchange so that participating organizations can share threat data using a convenient, structured, and easy-to-use API that provides privacy controls to enable sharing with only desired groups. This project is still in . Reference code can be found at

  • blog post

    TypeDB Data - CTI is an open source threat intelligence platform for organisations to store and manage their cyber threat intelligence (CTI) knowledge. It enables threat intel professionals to bring together their disparate CTI information into one database and find new insights about cyber threats. This repository provides a schema that is based on STIX2, and contains MITRE ATT&CK as an example dataset to start exploring this threat intelligence platform. More in this

Tools

Research, Standards & Books

More related projects

Add a GitHub project

Missing a project or an awesome list? Paste its GitHub URL and we fetch it right away.