ENNAENNA
🧠

Threat Intelligence

13 tools indexed

Threat intelligence platforms, incident response case management, and IOC sharing tools. These platforms help SOCs, CSIRTs, and threat analysts collect, correlate, and distribute indicators of compromise, manage security incidents collaboratively, and build structured knowledge bases of threat actors and campaigns.

MISP

PHP/Python

Open-source threat intelligence and sharing platform. Structured IOC management, feeds, correlation, and STIX/TAXII export.

threat-inteliocsharingstix
6.3k1.6k23d ago

OpenCTI

TypeScript/Python

Cyber threat intelligence platform. Knowledge management for threat data with STIX2 native storage and graph visualization.

threat-intelstix2knowledge-graphneo4j
9.2k1.3k23d ago

TheHive

Scala/JavaScript

Incident response case management platform. Collaborative investigation with observable analysis, playbooks, and MISP integration.

incident-responsecase-managementsoccsirt
3.9k68910mo ago

GRR Rapid Response

Python

Remote live forensics framework by Google. Deploy agents across thousands of endpoints for artifact collection and analysis.

dfirremote-forensicsendpointartifact-collection
5.1k7971mo ago

KAPE

C#

Kroll Artifact Parser and Extractor. Fast triage collection and parsing of forensic artifacts from Windows, macOS, and Linux.

dfirtriageartifact-collectionparsing

Cortex

Scala/Python

Observable analysis and active response engine. Analyze IOCs at scale with 100+ analyzers for IPs, hashes, URLs, and domains.

ioc-analysisobservableenrichmentautomation
1.6k2601mo ago

osquery

C++

SQL-powered endpoint visibility. Query operating system state as a relational database for security monitoring and compliance.

endpoint-visibilitysqlfleet-managementcompliance
23.2k2.6k24d ago

Wazuh

C/Python

Open-source SIEM and XDR platform. Endpoint detection, log analysis, vulnerability scanning, and compliance monitoring.

siemxdrendpoint-detectionlog-analysis
15.4k2.3k23d ago

Sigma

Python/YAML

Generic detection rule format. Write once, convert to Splunk, Elasticsearch, QRadar, and 30+ SIEM backends.

detection-rulessiemyamlsplunk
10.4k2.6k23d ago

IntelOwl

Python

Threat intelligence management platform integrating 100+ analyzers for enriching observables and malware samples.

threat-inteliocmalware-analysissoar
4.6k63724d ago

CrowdSec

Go

Collaborative open-source IPS with crowd-sourced threat intelligence sharing.

idsipscollaborativethreat-intel
13.2k61024d ago

Snort3

C++

Next-generation open-source intrusion detection and prevention system.

idsipsnetworkdetection
3.3k66727d ago

IntelMQ

Python

Automated security feed processing framework. Collects, normalizes, and distributes threat intelligence from hundreds of sources.

threat-intelligencefeed-processingautomationcert
1.1k31427d ago