Threat Open Source Projects

Browse 214 Threat open source projects, ranked by GitHub stars. Find the most popular Threat tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 214 projects
16,843 stars

laramies/theHarvester

E-mails, subdomains and names Harvester - OSINT

Metrics details
Stars16,843
16,214 stars

wazuh/wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Metrics details
Stars16,214
14,264 stars

crowdsecurity/crowdsec

CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.

Metrics details
Stars14,264
13,970 stars

rshipp/awesome-malware-analysis

Defund the Police.

Metrics details
Stars13,970
10,464 stars

hslatman/awesome-threat-intelligence

A curated list of Awesome Threat Intelligence resources

Metrics details
Stars10,464
9,692 stars

OpenCTI-Platform/opencti

Open Cyber Threat Intelligence Platform

Metrics details
Stars9,692
6,427 stars

MISP/MISP

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

Metrics details
Stars6,427
5,469 stars

fabacab/awesome-cybersecurity-blueteam

:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

Metrics details
Stars5,469
5,042 stars

lc/gau

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

Metrics details
Stars5,042
4,752 stars

Security-Onion-Solutions/securityonion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.

Metrics details
Stars4,752
4,627 stars

intelowlproject/IntelOwl

IntelOwl: manage your Threat Intelligence at scale

Metrics details
Stars4,627
4,091 stars

CyberMonitor/APT_CyberCriminal_Campagin_Collections

APT & CyberCriminal Campaign Collection

Metrics details
Stars4,091
3,950 stars

alexandreborges/malwoverview

Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.

Metrics details
Stars3,950
3,664 stars

kbandla/APTnotes

Various public documents, whitepapers and articles about APT campaigns

Metrics details
Stars3,664
3,261 stars

Yamato-Security/hayabusa

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

Metrics details
Stars3,261
3,083 stars

kitabisa/teler

Real-time HTTP Intrusion Detection

Metrics details
Stars3,083
2,930 stars

thinkst/opencanary

Modular and decentralised honeypot

Metrics details
Stars2,930
2,619 stars

venomous0x/WhatsAPI

Interface to WhatsApp Messenger

Metrics details
Stars2,619
2,485 stars

gtworek/Priv2Admin

Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.

Metrics details
Stars2,485
2,311 stars

rabobank-cdc/DeTTECT

Detect Tactics, Techniques & Combat Threats

Metrics details
Stars2,311
2,144 stars

hahwul/DevSecOps

♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎

Metrics details
Stars2,144
2,139 stars

center-for-threat-informed-defense/adversary_emulation_library

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

Metrics details
Stars2,139
2,109 stars

tom0li/collection-document

Collection of quality safety articles. Awesome articles.

Metrics details
Stars2,109
2,103 stars

mitre/cti

Cyber Threat Intelligence Repository expressed in STIX 2.0

Metrics details
Stars2,103
2,008 stars

yeti-platform/yeti

Your Everyday Threat Intelligence

Metrics details
Stars2,008
2,003 stars

magnologan/awesome-k8s-security

A curated list for Awesome Kubernetes Security resources

Metrics details
Stars2,003
1,977 stars

microsoft/msticpy

Microsoft Threat Intelligence Security Tools

Metrics details
Stars1,977
1,804 stars

aptnotes/data

APTnotes data

Metrics details
Stars1,804
1,773 stars

hysnsec/awesome-threat-modelling

A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.

Metrics details
Stars1,773
1,582 stars

tanjiti/sec_profile

爬取secwiki和xuanwu.github.io/sec.today,分析安全信息站点、安全趋势、提取安全工作者账号(twitter,weixin,github等)

Metrics details
Stars1,582
1,577 stars

mitchellkrogza/Phishing.Database

Phishing Domains, urls websites and threats database. We use the PyFunceble testing tool to validate the status of all known Phishing domains and provide stats to reveal how many unique domains used for Phishing are still active.

Metrics details
Stars1,577
1,527 stars

OWASP/threat-dragon

An open source threat modeling tool from OWASP

Metrics details
Stars1,527
1,469 stars

rfxn/linux-malware-detect

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring, quarantine, and multi-channel alerting

Metrics details
Stars1,469
1,453 stars

airbnb/binaryalert

BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.

Metrics details
Stars1,453
1,358 stars

facebook/ThreatExchange

Trust & Safety tools for working together to fight digital harms.

Metrics details
Stars1,358
1,305 stars

mandiant/ThreatPursuit-VM

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and hunting designed for intel and malware analysts as well as threat hunters to get up and running quickly.

Metrics details
Stars1,305
1,290 stars

Te-k/harpoon

CLI tool for open source and threat intelligence

Metrics details
Stars1,290
1,243 stars

eliasgranderubio/dagda

a tool to perform static analysis of known vulnerabilities, trojans, viruses, malware & other malicious threats in docker images/containers and to monitor the docker daemon and running docker containers for detecting anomalous activities

Metrics details
Stars1,243
1,145 stars

washingtonpost/data-police-shootings

The Washington Post is compiling a database of every fatal shooting in the United States by a police officer in the line of duty since 2015.

Metrics details
Stars1,145
1,121 stars

certtools/intelmq

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Metrics details
Stars1,121
1,110 stars

mitre/advmlthreatmatrix

Adversarial Threat Landscape for AI Systems

Metrics details
Stars1,110
1,013 stars

atc-project/atomic-threat-coverage

Actionable analytics designed to combat threats

Metrics details
Stars1,013
996 stars

target/strelka

Real-time, container-based file scanning at enterprise scale

Metrics details
Stars996
985 stars

sroberts/awesome-iocs

A collection of sources of indicators of compromise.

Metrics details
Stars985
977 stars

atenreiro/opensquat

The openSquat is an open-source tool for detecting domain look-alikes by searching for newly registered domains that might be impersonating legit domains and brands.

Metrics details
Stars977
947 stars

toolswatch/vFeed

The Correlated CVE Vulnerability And Threat Intelligence Database API

Metrics details
Stars947
943 stars

MHaggis/sysmon-dfir

Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.

Metrics details
Stars943
930 stars

reversinglabs/reversinglabs-yara-rules

ReversingLabs YARA Rules

Metrics details
Stars930
919 stars

InQuest/ThreatIngestor

Extract and aggregate threat intelligence.

Metrics details
Stars919
916 stars

A3sal0n/CyberThreatHunting

A collection of resources for Threat Hunters

Metrics details
Stars916
911 stars

cyberark/SkyArk

SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

Metrics details
Stars911
909 stars

crits/crits

CRITs - Collaborative Research Into Threats

Metrics details
Stars909
890 stars

nsacyber/Event-Forwarding-Guidance

Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsacyber

Metrics details
Stars890
810 stars

BushidoUK/Open-source-tools-for-CTI

Public Repository of Open Source Tools for Cyber Threat Intelligence Analysts and Researchers

Metrics details
Stars810
808 stars

scythe-io/purple-team-exercise-framework

Purple Team Exercise Framework

Metrics details
Stars808
800 stars

michenriksen/drawio-threatmodeling

Draw.io libraries for threat modeling diagrams

Metrics details
Stars800
786 stars

EONRaider/Packet-Sniffer

A Network Packet Sniffing tool developed in Python 3.

Metrics details
Stars786
774 stars

Threagile/threagile

Agile Threat Modeling Toolkit

Metrics details
Stars774
722 stars

TonyPhipps/SIEM

SIEM Tactics, Techiques, and Procedures

Metrics details
Stars722
693 stars

curiefense/curiefense

Curiefense is a unified, open source platform protecting cloud native applications.

Metrics details
Stars693
1-60 of 214 projects
Get A Weekly Email With Trending Threat Projects
Stay updated on Threat plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.