awesome-threat-intelligence
by hslatman
A curated list of Awesome Threat Intelligence resources
AI summary
Threat intel resource
A curated collection of resources and tools for gathering, analyzing, and sharing threat intelligence.
- stars
- 8.2K
- forks
- 1.5K
- watching
- 568
- awesome lists
- 10
- entries
- 266
What's in the list
266 links in 5 sections, with live GitHub stats.activeno commit in 2y
Sources
- whitelist
The top 1 Million sites from Amazon(Alexa). Never use this as a
- http://danger.rulez.sk/projects/bruteforceblocker/blist.php
BruteForceBlocker is a perl script that monitors a server's sshd logs and identifies brute force attacks, which it then uses to automatically configure firewall blocking rules and submit those IPs back to the project site,
- CINS Score
A subset of the commercial list, focused on poorly rated IPs that are not currently present on other threatlists
- CrowdSec
The largest crowd-sourced CTI, updated in near real-time, thanks to CrowdSec a next-gen, open-source, free, and collaborative IDS/IPS software. is able to analyze visitor behavior & provide an adapted response to all kinds of attacks. Users can share their alerts about threats with the community and benefit from the network effect. The IP addresses are collected from real attacks and are not coming exclusively from a honeypot network
- documentation
Cyber Cure offers free cyber threat intelligence feeds with lists of IP addresses that are currently infected and attacking on the internet. There are list of urls used by malware and list of hash files of known malware that is currently spreading. CyberCure is using sensors to collect intelligence with a very low false positive rate. Detailed is available as well
- documentation
Focsec.com provides a API for detecting VPNs, Proxys, Bots and TOR requests. Always up-to-date data helps with detecting suspicious logins, fraud and abuse. Code examples can be found in the
- STIX2
Contains sets of Open Source Cyber Threat Intelligence indicators, mostly based on malware analysis and compromised URLs, IPs and domains. The purpose of this project is to develop and test new ways to hunt, analyze, collect and share relevants IoCs to be used by SOC/CSIRT/CERT/individuals with minimun effort. Reports are shared in three ways: , and . Reports are published also in the
- IP and domain intelligence API available
Free intelligence source for current and historical DNS information, WHOIS information, finding other websites associated with certain IPs, subdomain knowledge and technologies. There is a as well
- abuse.ch
The Feodo Tracker tracks the Feodo trojan
HoneyPy
HoneyDB provides real time data of honeypot activity. This data comes from honeypots deployed on the Internet using the honeypot. In addition, HoneyDB provides API access to collected honeypot activity, which also includes aggregated data from various honeypot Twitter feeds
- collection and analysis
Malware samples , and more. Created and managed by CERT-PA
- Miroslav Stampar
IPsum is a threat intelligence feed based on 30+ different publicly available lists of suspicious and/or malicious IP addresses. All lists are automatically retrieved and parsed on a daily (24h) basis and the final result is pushed to this repository. List is made of IP addresses together with a total number of (black)list occurrence (for each). Created and managed by
- blog
Probable Whitelist of the top 1 million web sites, as ranked by Majestic. Sites are ordered by the number of referring subnets. More about the ranking can be found on their
- SANS ICS
The Suspicious Domains Threat Lists by tracks suspicious domains. It offers 3 lists categorized as either , or sensitivity, where the high sensitivity list has fewer false positives, whereas the low sensitivity list with more false positives. There is also an of domains. Finally, there is a suggested from
- observable's reputation
Cisco Talos Intelligence Group is one of the largest commercial threat intelligence teams in the world, comprised of world-class researchers, analysts and engineers. These teams are supported by unrivaled telemetry and sophisticated systems to create accurate, rapid and actionable threat intelligence for Cisco customers, products and services. Talos defends Cisco customers against known and emerging threats, discovers new vulnerabilities in common software, and interdicts threats in the wild before they can further harm the internet at large. Talos maintains the official rule sets of Snort.org, ClamAV, and SpamCop, in addition to releasing many open-source research and analysis tools. Talos provides an easy to use web UI to check an
- Indicators of Compromise
This source is being populated with the content from over 90 open source, security blogs. IOCs ( ) are parsed out of each blog and the content of the blog is formatted in markdown
Formats
- here
The Structured Threat Information eXpression (STIX) language is a standardized construct to represent cyber threat information. The STIX Language intends to convey the full range of potential cyber threat information and strives to be fully expressive, flexible, extensible, and automatable. STIX does not only allow tool-agnostic fields, but also provides so-called that provide means for embedding tool-specific elements, including OpenIOC, Yara and Snort. STIX 1.x has been archived
- DBIR
The Vocabulary for Event Recording and Incident Sharing (VERIS) is a set of metrics designed to provide a common language for describing security incidents in a structured and repeatable manner. VERIS is a response to one of the most critical and persistent challenges in the security industry - a lack of quality information. In addition to providing a structured format, VERIS also collects data from the community to report on breaches in the Verizon Data Breach Investigations Report ( ) and publishes this database online in a GitHub
Frameworks and Platforms
GitHub
The Collective Intelligence Framework (CIF) allows you to combine known malicious threat information from many sources and use that information for IR, detection and mitigation. Code available on
pyintelowl
Intel Owl is an OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API at scale. Intel Owl is composed of analyzers that can be run to retrieve data from external sources (like VirusTotal or AbuseIPDB) or to generate intel from internal analyzers (like Yara or Oletools). It can be integrated easily in your stack of security tools ( ) to automate common jobs usually performed, for instance, by SOC analysts manually
- CERT Polska
n6 (Network Security Incident eXchange) is a system to collect, manage and distribute security information on a large scale. Distribution is realized through a simple REST API and a web interface that authorized users can use to receive various types of data, in particular information on threats and incidents in their networks. It is developed by
- here
stoQ is a framework that allows cyber analysts to organize and automate repetitive, data-driven tasks. It features plugins for many other systems to interact with. One use case is the extraction of IOCs from documents, an example of which is shown , but it can also be used for deobfuscationg and decoding of content and automated scanning with YARA, for example
GitHub
Facebook created ThreatExchange so that participating organizations can share threat data using a convenient, structured, and easy-to-use API that provides privacy controls to enable sharing with only desired groups. This project is still in . Reference code can be found at
- blog post
TypeDB Data - CTI is an open source threat intelligence platform for organisations to store and manage their cyber threat intelligence (CTI) knowledge. It enables threat intel professionals to bring together their disparate CTI information into one database and find new insights about cyber threats. This repository provides a schema that is based on STIX2, and contains MITRE ATT&CK as an example dataset to start exploring this threat intelligence platform. More in this
Tools
GitHub
ActorTrackr is an open source web application for storing/searching/linking actor related data. The primary sources are from users and various public repositories. Source available on
blocklist-ipsets
Application for keeping feeds from FireHOL with IP addresses appearance history. HTTP-based API service is developed for search requests
- this
APT Groups, Operations and Malware Search Engine. The sources used for this Google Custom Search are listed on GitHub gist
Research, Standards & Books
- Cyber Threat Intelligence Capability Maturity Model (CTI-CMM)
A new using a stakeholder-first approach and aligned with the to empower your team and create lasting value
Nothing in this list matches your filter.
Featured in 10 awesome lists
Each link jumps to the spot where the list mentions awesome-threat-intelligence.