A repository to help CTI teams tackle the challenges around collection and research by providing guidance from experienced practitioners
☆122Oct 29, 2024Updated last year
Alternatives and similar repositories for The-CTI-Research-Guide
Users that are interested in The-CTI-Research-Guide are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A collection of papers, blogs, and resources that make up the quintessential aspects of cyber threat intelligence☆730Apr 25, 2026Updated 3 months ago
- An analytical challenge created to test junior analysts looking to try performing proactive and reactive cyber threat intelligence.☆203Jul 3, 2024Updated 2 years ago
- The Threat Actor Profile Guide for CTI Analysts☆121Jul 15, 2023Updated 3 years ago
- A collection of CVEs weaponized by ransomware operators☆149Jun 28, 2026Updated last month
- Cyber threat intelligence tool suite.☆41Apr 3, 2025Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- A package to create HTML MISP reports, including volume of trending events and attributes, evens received from key organisations and targ…☆12Aug 14, 2025Updated last year
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.☆54Oct 23, 2024Updated last year
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated 11 months ago
- 🐻❄️ 🏹 Threat hunting with Polars and flaws.cloud AWS CloudTrail datasets.☆14May 22, 2024Updated 2 years ago
- A curated list of Awesome Threat Intelligence Blogs☆555Jun 12, 2026Updated 2 months ago
- A collection of methods to learn who the owner of an IP address is.☆240Sep 29, 2025Updated 10 months ago
- Live Feed of C2 servers, tools, and botnets☆776Apr 13, 2026Updated 4 months ago
- Hundred Days of Yara Challenge☆12Jun 21, 2022Updated 4 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World☆188May 2, 2026Updated 3 months ago
- This guide describes a process for developing Cyber Threat Intelligence Priority Intelligence Requirements☆128Dec 5, 2023Updated 2 years ago
- CTI Blueprints is a free suite of templates and tools that helps Cyber Threat Intelligence analysts create high-quality, actionable repor…☆294Mar 20, 2025Updated last year
- Storage for the IOCs I collect☆11Apr 3, 2026Updated 4 months ago
- A curated list of Ransomware resources☆40May 11, 2026Updated 3 months ago
- Awesome list of keywords and artifacts for Threat Hunting sessions☆671Aug 4, 2025Updated last year
- A collection of companies that disclose adversary TTPs after they have been breached☆305Jun 7, 2026Updated 2 months ago
- Extract the Procedures (TTP) from CTI reports☆18Dec 13, 2025Updated 8 months ago
- A resource containing all the tools each ransomware gangs uses☆1,429Jul 25, 2026Updated 2 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups …☆409Jan 29, 2026Updated 6 months ago
- DFIQ is a collection of investigative questions and the approaches for answering them☆311Mar 10, 2026Updated 5 months ago
- ☆83Feb 19, 2026Updated 5 months ago
- PowerShell tools to help defenders hunt smarter, hunt harder.☆488Oct 29, 2025Updated 9 months ago
- Documentation and scripts to properly enable Windows event logs.☆719Oct 3, 2025Updated 10 months ago
- A list of Per-Reviewed Journals, Books and Blogs on intelligence and Cybersecurity☆27Apr 1, 2024Updated 2 years ago
- Get started using Synapse Open-Source to start a Cortex and perform analysis within your area of expertise.☆51May 16, 2022Updated 4 years ago
- Dictionary of CTI-related acronyms, terms, and jargon☆150Nov 27, 2025Updated 8 months ago
- An introduction to detection engineering☆14Jan 3, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A collection of various SIEM rules relating to malware family groups.☆69Jun 18, 2024Updated 2 years ago
- ☆36Jan 11, 2023Updated 3 years ago
- Adversarial Interception Mission Oriented Discovery and Disruption Framework, or AIMOD2, is a structured threat hunting approach to proac…☆91Sep 16, 2023Updated 2 years ago
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆151Sep 21, 2024Updated last year
- These FLARE-VM configuration files are designed to be help setup a purpose-built installation, remove unnecessary packages to help stream…☆16Apr 10, 2024Updated 2 years ago
- Raw data from Threat Intelligence Reports with automatic reports collection and keyword search across thousands of reports☆169Updated this week
- AIL framework - Analysis Information Leak framework☆993Updated this week