Proofpoint - Emerging Threats - Threat Research tools + publicly shared intel and documentation
☆88May 12, 2026Updated 2 months ago
Alternatives and similar repositories for threatresearch
Users that are interested in threatresearch are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Script to pull newly-registered domains and check for similarity against a provided word list.☆13Aug 2, 2020Updated 5 years ago
- ☆22Dec 22, 2020Updated 5 years ago
- BSidesLV 2015 Exploit Kit Analysis Workshop Files☆27Aug 5, 2015Updated 10 years ago
- Repository for scripts and tips for "Yara Scan Service"☆20Feb 19, 2023Updated 3 years ago
- Simple IP enrichment service and API wrapping PyASN and MaxMind GeoIP.☆71Dec 8, 2022Updated 3 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A Golang API for TheHive☆13Sep 3, 2020Updated 5 years ago
- A collection of YARA signatures that I have found around the web.☆11Apr 29, 2016Updated 10 years ago
- 进程内优雅地拦截SPI/LSP模块。 Manage SPI/LSP in a graceful way within private process.☆11Dec 28, 2017Updated 8 years ago
- Yara rules☆21Mar 27, 2023Updated 3 years ago
- Malware Configuration And Payload Extraction☆762Nov 22, 2024Updated last year
- ☆16Mar 20, 2026Updated 4 months ago
- Is this IP a C2 server?☆28Apr 21, 2020Updated 6 years ago
- DC3 Malware Configuration Parser (DC3-MWCP) is a framework for parsing configuration information from malware. The information extracted …☆349Jul 17, 2026Updated last week
- Enables dynamic translation of structured data between formats☆14Jul 9, 2026Updated 2 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆52Sep 5, 2018Updated 7 years ago
- Malware Sinkhole List in various formats☆106May 25, 2026Updated 2 months ago
- ☆28Dec 28, 2017Updated 8 years ago
- Kippo configured to be a backdoored netscreen☆11Dec 22, 2015Updated 10 years ago
- Volatility plugin for extracts configuration data of known malware☆498Dec 22, 2023Updated 2 years ago
- Cerebrate is an open-source platform meant to act as a trusted contact information provider and interconnection orchestrator for other se…☆92Jun 17, 2026Updated last month
- Automatically created C2 Feeds☆737Updated this week
- Useful Windows and AD tools☆15Feb 20, 2022Updated 4 years ago
- ☆11Apr 25, 2021Updated 5 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆150Sep 22, 2023Updated 2 years ago
- IOCs for various malware families☆11Jul 18, 2024Updated 2 years ago
- Unpack MIME attachments from a file and check them against virustotal.com☆44Mar 11, 2016Updated 10 years ago
- Tools for playing w/ CobaltStrike config - extractin, detection, processing, etc...☆28Apr 13, 2023Updated 3 years ago
- Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research☆53Mar 16, 2018Updated 8 years ago
- Programmatically access a TLS certificate chain in C++ and C#☆12Oct 27, 2018Updated 7 years ago
- A golang implementation of a prefetch parser.☆20Oct 27, 2025Updated 9 months ago
- The Purpose of this research tool is to provide a Python client into RiskIQ API services.☆22Feb 4, 2021Updated 5 years ago
- Automatically create YARA rules from malicious documents.☆211May 16, 2022Updated 4 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Manage VT Alerts☆62Oct 4, 2016Updated 9 years ago
- A dotnet executable to get an Entra token in an authenticated runtime☆17Oct 30, 2024Updated last year
- Network sinkhole for isolated malware analysis☆40Mar 5, 2018Updated 8 years ago
- ☆17Dec 5, 2023Updated 2 years ago
- A Vim syntax highlighting for YARA and YARA-X rules☆31Apr 19, 2026Updated 3 months ago
- ☆25Mar 17, 2024Updated 2 years ago
- simple YARA-based IOC scanner☆181Mar 17, 2026Updated 4 months ago