Threat Open Source Projects
Browse 214 Threat open source projects, ranked by GitHub stars. Find the most popular Threat tools and libraries.
laramies/theHarvester
E-mails, subdomains and names Harvester - OSINT
Metrics details
| Stars | 16,843 |
wazuh/wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Metrics details
| Stars | 16,214 |
crowdsecurity/crowdsec
CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.
Metrics details
| Stars | 14,264 |
rshipp/awesome-malware-analysis
Defund the Police.
Metrics details
| Stars | 13,970 |
hslatman/awesome-threat-intelligence
A curated list of Awesome Threat Intelligence resources
Metrics details
| Stars | 10,464 |
OpenCTI-Platform/opencti
Open Cyber Threat Intelligence Platform
Metrics details
| Stars | 9,692 |
MISP/MISP
MISP (core software) - Open Source Threat Intelligence and Sharing Platform
Metrics details
| Stars | 6,427 |
fabacab/awesome-cybersecurity-blueteam
:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
Metrics details
| Stars | 5,469 |
lc/gau
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.
Metrics details
| Stars | 5,042 |
Security-Onion-Solutions/securityonion
Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
Metrics details
| Stars | 4,752 |
intelowlproject/IntelOwl
IntelOwl: manage your Threat Intelligence at scale
Metrics details
| Stars | 4,627 |
CyberMonitor/APT_CyberCriminal_Campagin_Collections
APT & CyberCriminal Campaign Collection
Metrics details
| Stars | 4,091 |
alexandreborges/malwoverview
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.
Metrics details
| Stars | 3,950 |
kbandla/APTnotes
Various public documents, whitepapers and articles about APT campaigns
Metrics details
| Stars | 3,664 |
Yamato-Security/hayabusa
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
Metrics details
| Stars | 3,261 |
kitabisa/teler
Real-time HTTP Intrusion Detection
Metrics details
| Stars | 3,083 |
thinkst/opencanary
Modular and decentralised honeypot
Metrics details
| Stars | 2,930 |
venomous0x/WhatsAPI
Interface to WhatsApp Messenger
Metrics details
| Stars | 2,619 |
gtworek/Priv2Admin
Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.
Metrics details
| Stars | 2,485 |
rabobank-cdc/DeTTECT
Detect Tactics, Techniques & Combat Threats
Metrics details
| Stars | 2,311 |
hahwul/DevSecOps
♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎
Metrics details
| Stars | 2,144 |
center-for-threat-informed-defense/adversary_emulation_library
An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.
Metrics details
| Stars | 2,139 |
tom0li/collection-document
Collection of quality safety articles. Awesome articles.
Metrics details
| Stars | 2,109 |
mitre/cti
Cyber Threat Intelligence Repository expressed in STIX 2.0
Metrics details
| Stars | 2,103 |
yeti-platform/yeti
Your Everyday Threat Intelligence
Metrics details
| Stars | 2,008 |
magnologan/awesome-k8s-security
A curated list for Awesome Kubernetes Security resources
Metrics details
| Stars | 2,003 |
microsoft/msticpy
Microsoft Threat Intelligence Security Tools
Metrics details
| Stars | 1,977 |
aptnotes/data
APTnotes data
Metrics details
| Stars | 1,804 |
hysnsec/awesome-threat-modelling
A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
Metrics details
| Stars | 1,773 |
tanjiti/sec_profile
爬取secwiki和xuanwu.github.io/sec.today,分析安全信息站点、安全趋势、提取安全工作者账号(twitter,weixin,github等)
Metrics details
| Stars | 1,582 |
mitchellkrogza/Phishing.Database
Phishing Domains, urls websites and threats database. We use the PyFunceble testing tool to validate the status of all known Phishing domains and provide stats to reveal how many unique domains used for Phishing are still active.
Metrics details
| Stars | 1,577 |
OWASP/threat-dragon
An open source threat modeling tool from OWASP
Metrics details
| Stars | 1,527 |
rfxn/linux-malware-detect
Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring, quarantine, and multi-channel alerting
Metrics details
| Stars | 1,469 |
airbnb/binaryalert
BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.
Metrics details
| Stars | 1,453 |
facebook/ThreatExchange
Trust & Safety tools for working together to fight digital harms.
Metrics details
| Stars | 1,358 |
mandiant/ThreatPursuit-VM
Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and hunting designed for intel and malware analysts as well as threat hunters to get up and running quickly.
Metrics details
| Stars | 1,305 |
Te-k/harpoon
CLI tool for open source and threat intelligence
Metrics details
| Stars | 1,290 |
eliasgranderubio/dagda
a tool to perform static analysis of known vulnerabilities, trojans, viruses, malware & other malicious threats in docker images/containers and to monitor the docker daemon and running docker containers for detecting anomalous activities
Metrics details
| Stars | 1,243 |
washingtonpost/data-police-shootings
The Washington Post is compiling a database of every fatal shooting in the United States by a police officer in the line of duty since 2015.
Metrics details
| Stars | 1,145 |
certtools/intelmq
IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
Metrics details
| Stars | 1,121 |
mitre/advmlthreatmatrix
Adversarial Threat Landscape for AI Systems
Metrics details
| Stars | 1,110 |
atc-project/atomic-threat-coverage
Actionable analytics designed to combat threats
Metrics details
| Stars | 1,013 |
target/strelka
Real-time, container-based file scanning at enterprise scale
Metrics details
| Stars | 996 |
sroberts/awesome-iocs
A collection of sources of indicators of compromise.
Metrics details
| Stars | 985 |
atenreiro/opensquat
The openSquat is an open-source tool for detecting domain look-alikes by searching for newly registered domains that might be impersonating legit domains and brands.
Metrics details
| Stars | 977 |
toolswatch/vFeed
The Correlated CVE Vulnerability And Threat Intelligence Database API
Metrics details
| Stars | 947 |
MHaggis/sysmon-dfir
Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
Metrics details
| Stars | 943 |
reversinglabs/reversinglabs-yara-rules
ReversingLabs YARA Rules
Metrics details
| Stars | 930 |
InQuest/ThreatIngestor
Extract and aggregate threat intelligence.
Metrics details
| Stars | 919 |
A3sal0n/CyberThreatHunting
A collection of resources for Threat Hunters
Metrics details
| Stars | 916 |
cyberark/SkyArk
SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS
Metrics details
| Stars | 911 |
crits/crits
CRITs - Collaborative Research Into Threats
Metrics details
| Stars | 909 |
nsacyber/Event-Forwarding-Guidance
Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsacyber
Metrics details
| Stars | 890 |
BushidoUK/Open-source-tools-for-CTI
Public Repository of Open Source Tools for Cyber Threat Intelligence Analysts and Researchers
Metrics details
| Stars | 810 |
scythe-io/purple-team-exercise-framework
Purple Team Exercise Framework
Metrics details
| Stars | 808 |
michenriksen/drawio-threatmodeling
Draw.io libraries for threat modeling diagrams
Metrics details
| Stars | 800 |
EONRaider/Packet-Sniffer
A Network Packet Sniffing tool developed in Python 3.
Metrics details
| Stars | 786 |
Threagile/threagile
Agile Threat Modeling Toolkit
Metrics details
| Stars | 774 |
TonyPhipps/SIEM
SIEM Tactics, Techiques, and Procedures
Metrics details
| Stars | 722 |
curiefense/curiefense
Curiefense is a unified, open source platform protecting cloud native applications.
Metrics details
| Stars | 693 |
