Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Threat Intelligence

Threat Intelligence

106 projects

Showing 27 of 99 projects

CIFv2
CIFv2Perl

A deprecated threat intelligence platform for collecting, processing, and sharing security indicators.

#security-automation#open-source-intel#ioc-management
Stars230
Forks60
Last commit8 years ago
crowdsec-blocklist-import
crowdsec-blocklist-importPython

Import 28+ threat intelligence feeds into CrowdSec with automatic deduplication, normalization, and real-time sync.

#self-hosted-security#security-automation#tor-exit-nodes
Stars227
Forks9
Last commit
hpfeeds
hpfeedsPython

A lightweight authenticated publish-subscribe protocol for binary data feeds, commonly used for security data sharing.

#security-data#binary-protocol#asyncio
Stars218
Forks105
Last commit2 years ago
ioc_writer
ioc_writerPython

Python library for creating, editing, and managing OpenIOC objects for threat intelligence indicators.

#python-library#security-automation#ioc-management
Stars208
Forks60
Last commit3 years ago
EVM Security
EVM Security

A curated list of resources for understanding and securing the Ethereum Virtual Machine (EVM) ecosystem.

#vulnerability-database#mev#smart-contract-auditing
Stars197
Forks15
Last commit4 years ago
Elastic honey
Elastic honeyGo

A honeypot designed to detect and log attacks targeting Elasticsearch remote code execution vulnerabilities.

#honeypot#attack-logging#threat-intelligence
Stars191
Forks53
Last commit11 years ago
Malware Persistence
Malware Persistence

A curated collection of information and tools for detecting, analyzing, and hunting malware persistence mechanisms across operating systems.

#windows-security#malware-detection#macos-security
Stars188
Forks16
Last commit2 months ago
ADBHoney
ADBHoneyPython

A low-interaction honeypot that mimics Android Debug Bridge (ADB) over TCP/IP to capture malware targeting exposed port 5555.

#honeypot#tcp-ip#android-security
Stars179
Forks35
Last commit1 year ago
TIQ-test
TIQ-testR

A tool for data visualization and statistical analysis of threat intelligence indicator feeds to measure their quality and effectiveness.

#statistical-analysis#security-analytics#data-science
Stars178
Forks44
Last commit10 years ago
Forager
ForagerPython

A Python-based multithreaded threat intelligence gathering tool that collects, stores, and serves indicators of compromise from various sources.

#feed-management#ioc-extraction#carbonblack-integration
Stars177
Forks29
Last commit8 years ago
SpiderFoot
SpiderFootPython

SpiderFoot is an open-source intelligence (OSINT) automation platform that integrates with 309+ data sources for threat intelligence and attack surface mapping.

#fastapi#osint#graphql
Stars170
Forks27
Last commit2 days ago
TypeDB OSI - Cyber Threat Intelligence
TypeDB OSI - Cyber Threat IntelligencePython

A TypeDB schema for representing STIX 2.1 cyber threat intelligence data, enabling structured querying of threat actors, malware, and infrastructure.

#security-data-modeling#cyber#cyber-threat-intelligence
Stars168
Forks20
Last commit
Hontel
HontelPython

A Python-based Telnet honeypot that emulates a Telnet service inside a chroot environment to capture malicious activity.

#honeypot#python-2#python
Stars163
Forks44
Last commit7 years ago
Trapster Commmunity
Trapster CommmunityPython

A low-interaction honeypot that mimics network services and clones websites with AI-powered responses to detect intruders.

#ai#deceptive#honeypot
Stars160
Forks17
Last commit3 days ago
Aleph
AlephCSS

An open-source malware analysis pipeline system that automates sample collection, processing, and JSON-based artifact storage.

#sample-processing#security-automation#python
Stars158
Forks55
Last commit5 years ago
Shiva
ShivaPython

A Python-based spam honeypot that acts as an SMTP server to collect, analyze, and track spam campaigns for threat intelligence.

#email-analysis#campaign-tracking#phishing-detection
Stars140
Forks41
Last commit1 year ago
Masscanned
MasscannedRust

A low-interaction honeypot that responds to network scanners and bots across multiple protocols, designed for self-hosted threat intelligence.

#hacktoberfest#honeypot#protocol-emulation
Stars139
Forks19
Last commit1 day ago
AbuseHelper
AbuseHelperPython

An open-source framework for receiving, processing, and redistributing abuse feeds and threat intelligence.

#feed-distribution#open-source-framework#abuse-feeds
Stars125
Forks19
Last commit6 years ago
Posh-VirusTotal
Posh-VirusTotalPowerShell

A PowerShell module for interacting with VirusTotal's API to analyze suspicious files, URLs, domains, and IP addresses.

#security-automation#file-scanning#malware-analysis
Stars124
Forks29
Last commit6 years ago
Fileintel
FileintelPython

A modular Python tool that collects threat intelligence from multiple sources for files identified by their hash.

#nsrl#virustotal#threatcrowd
Stars123
Forks24
Last commit5 years ago
Anvilogic Detection Armory
Anvilogic Detection Armory

An open-source repository of cybersecurity detection rules and threat identifiers for security teams to enhance threat detection capabilities.

#security-analytics#splunk#mitre-attack
Stars119
Forks7
Last commit2 months ago
Madrolyzer
MadrolyzerPython

A simple framework to extract actionable data like C&C servers and phone numbers from Android malware samples.

#androguard#apk-analysis#malware-analysis-framework
Stars113
Forks29
Last commit11 years ago
honeydet
honeydetGo

A signature-based, multi-threaded honeypot detection tool written in Go that identifies emulated services via crafted requests.

#honeypot#honeypots#cyber-threat-intelligence
Stars111
Forks8
Last commit1 year ago
MalPipe
MalPipePython

A modular malware and IOC ingestion framework that collects, enriches, and exports threat intelligence from multiple feeds.

#security-automation#security-tools#malware-analysis
Stars110
Forks22
Last commit7 years ago
sshsyrup
sshsyrupGo

A low-to-medium interaction SSH honeypot written in Go that captures terminal sessions and logs attacker activity.

#honeypot#ssh-honeypot#ssh-server
Stars99
Forks10
Last commit7 years ago
CrowdSec
CrowdSecDockerfile

A Home Assistant add-on that installs Crowdsec, an open-source IPS for analyzing visitor behavior and blocking attacks.

#self-hosted-security#ips#home-automation-security
Stars94
Forks16
Last commit23 days ago
MaltegoVT
MaltegoVTPython

A set of Maltego transforms for VirusTotal Public API v2.0 with daily query caching to speed up resolutions.

#digital-forensics#osint#security-analysis
Stars82
Forks21
Last commit10 years ago
PreviousPage 3 of 3

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
19 days ago
4 months ago
#Cybersecurity64
#Malware Analysis43
#Incident Response35
#Python29
#Network Security23
#Honeypot22
#Security20
#Security Automation19
#Security Tools17
#Security Research17
#Threat Hunting16
#Docker15