awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to tenzir/threatbus

Open-source alternatives to Threatbus

30 open-source projects similar to tenzir/threatbus, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Threatbus alternative.

  • virustotal/yaraAvatar von VirusTotal

    VirusTotal/yara

    9,420Auf GitHub ansehen↗

    YARA is a pattern matching engine and binary analysis tool used to identify and classify malware samples. It functions as a malware research framework that allows for the definition of file descriptions and detection rules to find indicators of compromise within binaries. The system enables the creation of custom detection rules using strings, wildcards, and regular expressions. These rules use boolean logic to match textual or binary patterns, allowing for the classification of files into specific malware families and the automation of threat intelligence. The engine utilizes Aho-Corasick s

    Cyara
    Auf GitHub ansehen↗9,420
  • intelowlproject/intelowlAvatar von intelowlproject

    intelowlproject/IntelOwl

    4,605Auf GitHub ansehen↗

    IntelOwl is a threat intelligence platform and security orchestration engine designed to aggregate, analyze, and enrich security observables. It functions as a security incident investigation tool and a threat intelligence aggregator, collecting data on files, domains, and IP addresses from diverse internal and external sources. The system differentiates itself through playbook-based workflow automation, allowing users to define reusable sequences of analysis tasks that trigger subsequent jobs based on prior outputs. It unifies disparate security data into a common schema and utilizes protoco

    Pythoncyber-securitycyber-threat-intelligencecybersecurity
    Auf GitHub ansehen↗4,605
  • alexandreborges/malwoverviewAvatar von alexandreborges

    alexandreborges/malwoverview

    3,882Auf GitHub ansehen↗

    This project is a Python command-line security tool and malware analysis framework designed for threat intelligence aggregation and incident triage. It functions as an aggregator that orchestrates queries across multiple security services and sandboxes to analyze hashes, IP addresses, and domains. The tool distinguishes itself by incorporating an intelligence layer that uses language models to provide automated risk assessments and framework mappings. It also includes specialized capabilities for extracting indicators of compromise from unstructured text, documents, and web pages, as well as

    Pythonalienvaultcvecve-search
    Auf GitHub ansehen↗3,882

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Find more with AI search
  • neo23x0/lokiAvatar von Neo23x0

    Neo23x0/Loki

    3,763Auf GitHub ansehen↗

    Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems. The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte seq

    Python
    Auf GitHub ansehen↗3,763
  • dtag-dev-sec/tpotceAvatar von dtag-dev-sec

    dtag-dev-sec/tpotce

    9,281Auf GitHub ansehen↗

    T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based security sandbox to deploy and manage a collection of diverse decoy services that simulate vulnerable targets to lure attackers and record their activity. The system features a distributed sensor network where remote nodes capture attack logs and transmit them via encrypted communication to a central hub. This central hub employs an analytics stack to transform raw logs into geographic maps and interactive dashboards for adversary behavior visualization. To increase the realism of si

    Shell
    Auf GitHub ansehen↗9,281
  • thehive-project/thehiveAvatar von TheHive-Project

    TheHive-Project/TheHive

    3,891Auf GitHub ansehen↗

    TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro

    Scalaanalyzerapicortex
    Auf GitHub ansehen↗3,891
  • misp/mispAvatar von MISP

    MISP/MISP

    6,360Auf GitHub ansehen↗

    MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish

    PHP
    Auf GitHub ansehen↗6,360
  • telekom-security/tpotceAvatar von telekom-security

    telekom-security/tpotce

    9,298Auf GitHub ansehen↗

    T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors. The system features a distributed sensor network using a hub-and-spoke architecture, allowing remote sensors to transmit logs back to a central management hub. It integrates large language models to create a dynamic deception engine capable of adaptive interactions with attackers. The

    Shelldeceptiondockerelk
    Auf GitHub ansehen↗9,298
  • elastic/detection-rulesAvatar von elastic

    elastic/detection-rules

    2,508Auf GitHub ansehen↗

    This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base

    Pythonthreat-detectionthreat-hunting
    Auf GitHub ansehen↗2,508
  • blocklistproject/listsAvatar von blocklistproject

    blocklistproject/Lists

    4,641Auf GitHub ansehen↗

    Lists is a curated collection of DNS blocklists, a domain blocklist generator, and a categorized library of domains used for network content filtering. The project provides a command-line pipeline that aggregates upstream sources to build and validate blocklists used to redirect unwanted traffic to null addresses. The project distinguishes itself through a CLI-driven build pipeline that automates the fetching, validation, and daily regeneration of datasets. It organizes domains into discrete functional categories rather than a single monolithic list and exports them in multiple syntaxes, incl

    Pythonadblockadblock-listblocklist
    Auf GitHub ansehen↗4,641
  • cyb3rward0g/helkAvatar von Cyb3rWard0g

    Cyb3rWard0g/HELK

    3,926Auf GitHub ansehen↗

    HELK is a containerized security information and event management environment and threat hunting platform. It provides a security-focused deployment of the ELK stack, combining Elasticsearch, Logstash, and Kibana into a specialized platform for investigating logs and discovering hidden patterns in network and system security data. The project functions as a security data science suite, integrating interactive computational notebooks and distributed processing tools to run machine learning and graph analytics on security logs. This allows for the identification of hidden attack patterns and an

    Jupyter Notebook
    Auf GitHub ansehen↗3,926
  • corelight/zeek2esAvatar von corelight

    corelight/zeek2es

    40Auf GitHub ansehen↗

    A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!

    Python
    Auf GitHub ansehen↗40
  • cyb3rward0g/invoke-attackapiC

    Cyb3rWard0g/Invoke-ATTACKAPI

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • danielbohannon/revoke-obfuscationD

    danielbohannon/Revoke-Obfuscation

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • blacklotuslabs/iocsAvatar von blacklotuslabs

    blacklotuslabs/IOCs

    144Auf GitHub ansehen↗

    IOCs published by Black Lotus Labs

    Auf GitHub ansehen↗144
  • austin-taylor/flareA

    austin-taylor/flare

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • clong/detectionlabAvatar von clong

    clong/DetectionLab

    4,904Auf GitHub ansehen↗

    DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms. The project utilizes Ansible for the declarative installation and configuration of domain services and endpoint security tools. It incorporates a browser-based remote access interface via Apache Guacamole to manage laboratory hosts without requiring standalone remote desktop clients. The environment includes a telemetry pipeline that aggre

    HTMLansibledetectiondetectionlab
    Auf GitHub ansehen↗4,904
  • endgameinc/eqlE

    endgameinc/eql

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • elastic/labs-releasesE

    elastic/labs-releases

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • cisco-talos/iocsC

    Cisco-Talos/IOCs

    0Auf GitHub ansehen↗

    //////////////// ////////////////////// // //////////////////////// // /// /////// ///// /////// /////// /////// /////// //////// //////// //////// //////// //////// //////// //////// //////// //////// //////// /////// /////// /////// /////// ///// // ////// // // /////////////////////////…

    Auf GitHub ansehen↗0
  • endgameinc/eqllibE

    endgameinc/eqllib

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • endgameinc/varnaAvatar von endgameinc

    endgameinc/varna

    52Auf GitHub ansehen↗

    Varna: Quick & Cheap AWS CloudTrail Monitoring with Event Query Language (EQL)

    CSS
    Auf GitHub ansehen↗52
  • eset/malware-iocAvatar von eset

    eset/malware-ioc

    1,955Auf GitHub ansehen↗

    Indicators of Compromises (IOC) of our various investigations

    YARA
    Auf GitHub ansehen↗1,955
  • executemalware/malware-iocsAvatar von executemalware

    executemalware/Malware-IOCs

    508Auf GitHub ansehen↗

    This is where I'll post IOCs from malware investigations

    Auf GitHub ansehen↗508
  • fireeye/capaAvatar von fireeye

    fireeye/capa

    6,062Auf GitHub ansehen↗

    capa is a static analysis tool that scans executable files to identify what a program can do, detecting capabilities such as API calls, byte sequences, and structural patterns without executing the code. It supports multiple file formats including PE, ELF, .NET, and shellcode, and can also process runtime behavior traces from sandbox reports generated by CAPE, DRAKVUF, or VMRay. The tool integrates directly with reverse engineering environments through plugins for IDA Pro and Ghidra, allowing analysts to view capability matches and author detection rules within their disassembler of choice. C

    Python
    Auf GitHub ansehen↗6,062
  • foxio-llc/logslashF

    FoxIO-LLC/LogSlash

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • hadojae/dataAvatar von hadojae

    hadojae/DATA

    99Auf GitHub ansehen↗

    Credential Phish Analysis and Automation

    Python
    Auf GitHub ansehen↗99
  • hagezi/dns-blocklistsAvatar von hagezi

    hagezi/dns-blocklists

    20,103Auf GitHub ansehen↗

    This project is a comprehensive repository of curated domain blocklists designed for network-wide DNS filtering. It functions as a DNS sinkhole feed, providing the necessary data to intercept and block unwanted network requests at the resolution layer before they reach their destination. By returning null or loopback addresses for identified domains, it prevents connections to malicious infrastructure, advertising servers, and tracking endpoints across all devices on a network. The repository distinguishes itself through a tiered categorization logic that allows users to select protection lev

    Textadblockadguardads
    Auf GitHub ansehen↗20,103
  • harfanglab/iocsAvatar von HarfangLab

    HarfangLab/iocs

    20Auf GitHub ansehen↗

    Indicators of compromise

    YARA
    Auf GitHub ansehen↗20
  • bert-janp/open-source-threat-intel-feedsAvatar von Bert-JanP

    Bert-JanP/Open-Source-Threat-Intel-Feeds

    773Auf GitHub ansehen↗
    Pythonc2iociocfeed
    Auf GitHub ansehen↗773