OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide
This project is a Python command-line security tool and malware analysis framework designed for threat intelligence aggregation and incident triage. It functions as an aggregator that orchestrates queries across multiple security services and sandboxes to analyze hashes, IP addresses, and domains. The tool distinguishes itself by incorporating an intelligence layer that uses language models to provide automated risk assessments and framework mappings. It also includes specialized capabilities for extracting indicators of compromise from unstructured text, documents, and web pages, as well as
TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro
MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for…
Las características principales de misp/misp son: Threat Intelligence Platforms, Distribution Controls, Programmatic Threat Intelligence Interfaces, REST APIs, Threat Intelligence, Correlation Engines, Threat Object Models, Granular Content Sharing.
Las alternativas de código abierto para misp/misp incluyen: opencti-platform/opencti — OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical… inquest/threatingestor — Extract and aggregate threat intelligence. alexandreborges/malwoverview — This project is a Python command-line security tool and malware analysis framework designed for threat intelligence… thehive-project/thehive — TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security… stamparm/maltrail — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network… dtag-dev-sec/tpotce — T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based…