awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to misp/misp

Open-source alternatives to MISP

30 open-source projects similar to misp/misp, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best MISP alternative.

  • opencti-platform/openctiOpenCTI-Platform avatar

    OpenCTI-Platform/opencti

    8,812View on GitHub↗

    OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide

    TypeScriptcticybercybersecurity
    View on GitHub↗8,812
  • inquest/threatingestorInQuest avatar

    InQuest/ThreatIngestor

    917View on GitHub↗

    Extract and aggregate threat intelligence.

    Python
    View on GitHub↗917
  • alexandreborges/malwoverviewalexandreborges avatar

    alexandreborges/malwoverview

    3,882View on GitHub↗

    This project is a Python command-line security tool and malware analysis framework designed for threat intelligence aggregation and incident triage. It functions as an aggregator that orchestrates queries across multiple security services and sandboxes to analyze hashes, IP addresses, and domains. The tool distinguishes itself by incorporating an intelligence layer that uses language models to provide automated risk assessments and framework mappings. It also includes specialized capabilities for extracting indicators of compromise from unstructured text, documents, and web pages, as well as

    Pythonalienvaultcvecve-search
    View on GitHub↗3,882

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • thehive-project/thehiveTheHive-Project avatar

    TheHive-Project/TheHive

    3,891View on GitHub↗

    TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro

    Scalaanalyzerapicortex
    View on GitHub↗3,891
  • stamparm/maltrailstamparm avatar

    stamparm/maltrail

    8,498View on GitHub↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Pythonattack-detectionintrusion-detectionmalware
    View on GitHub↗8,498
  • dtag-dev-sec/tpotcedtag-dev-sec avatar

    dtag-dev-sec/tpotce

    9,281View on GitHub↗

    T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based security sandbox to deploy and manage a collection of diverse decoy services that simulate vulnerable targets to lure attackers and record their activity. The system features a distributed sensor network where remote nodes capture attack logs and transmit them via encrypted communication to a central hub. This central hub employs an analytics stack to transform raw logs into geographic maps and interactive dashboards for adversary behavior visualization. To increase the realism of si

    Shell
    View on GitHub↗9,281
  • telekom-security/tpotcetelekom-security avatar

    telekom-security/tpotce

    9,298View on GitHub↗

    T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors. The system features a distributed sensor network using a hub-and-spoke architecture, allowing remote sensors to transmit logs back to a central management hub. It integrates large language models to create a dynamic deception engine capable of adaptive interactions with attackers. The

    Shelldeceptiondockerelk
    View on GitHub↗9,298
  • crowdsecurity/crowdseccrowdsecurity avatar

    crowdsecurity/crowdsec

    12,574View on GitHub↗

    CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl

    Goattacks-preventiondetectionids
    View on GitHub↗12,574
  • usesend/usesendusesend avatar

    usesend/useSend

    4,402View on GitHub↗

    useSend is an email marketing platform and transactional delivery system built to manage bulk campaigns and individual messages using AWS SES for delivery. It provides a RESTful API, an SMTP relay gateway, and a visual management interface for designing HTML templates and coordinating email broadcasts. The platform distinguishes itself by translating legacy SMTP traffic into modern API calls and implementing an event-driven webhook system. This system pushes real-time delivery, bounce, and click notifications to external servers using HMAC-SHA256 signed payloads to ensure authenticity. The s

    TypeScriptemailhacktoberfestpostmark
    View on GitHub↗4,402
  • elastic/detection-ruleselastic avatar

    elastic/detection-rules

    2,508View on GitHub↗

    This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base

    Pythonthreat-detectionthreat-hunting
    View on GitHub↗2,508
  • sigmahq/sigmaSigmaHQ avatar

    SigmaHQ/sigma

    10,136View on GitHub↗

    Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms. The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that

    Pythonelasticsearchidslogging
    View on GitHub↗10,136
  • neo23x0/lokiNeo23x0 avatar

    Neo23x0/Loki

    3,763View on GitHub↗

    Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems. The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte seq

    Python
    View on GitHub↗3,763
  • doctorwebltd/malware-iocsDoctorWebLtd avatar

    DoctorWebLtd/malware-iocs

    242View on GitHub↗
    View on GitHub↗242
  • mlsecproject/combinemlsecproject avatar

    mlsecproject/combine

    656View on GitHub↗

    Tool to gather Threat Intelligence indicators from publicly available sources

    Python
    View on GitHub↗656
  • intelowlproject/intelowlintelowlproject avatar

    intelowlproject/IntelOwl

    4,605View on GitHub↗

    IntelOwl is a threat intelligence platform and security orchestration engine designed to aggregate, analyze, and enrich security observables. It functions as a security incident investigation tool and a threat intelligence aggregator, collecting data on files, domains, and IP addresses from diverse internal and external sources. The system differentiates itself through playbook-based workflow automation, allowing users to define reusable sequences of analysis tasks that trigger subsequent jobs based on prior outputs. It unifies disparate security data into a common schema and utilizes protoco

    Pythoncyber-securitycyber-threat-intelligencecybersecurity
    View on GitHub↗4,605
  • viper-framework/viperviper-framework avatar

    viper-framework/viper

    1,563View on GitHub↗

    Binary analysis and management framework

    Python
    View on GitHub↗1,563
  • drb-ra/c2intelfeedsdrb-ra avatar

    drb-ra/C2IntelFeeds

    726View on GitHub↗

    Automatically created C2 Feeds | Also posted via @drb_ra

    REXX
    View on GitHub↗726
  • eset/malware-ioceset avatar

    eset/malware-ioc

    1,955View on GitHub↗

    Indicators of Compromises (IOC) of our various investigations

    YARA
    View on GitHub↗1,955
  • godaddy/procfiltergodaddy avatar

    godaddy/procfilter

    398View on GitHub↗

    A YARA-integrated process denial framework for Windows

    C++
    View on GitHub↗398
  • cybercentrecanada/cccs-yaraCybercentreCanada avatar

    CybercentreCanada/CCCS-Yara

    119View on GitHub↗

    YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA

    Python
    View on GitHub↗119
  • target/halogentarget avatar

    target/halogen

    211View on GitHub↗

    Automatically create YARA rules from malicious documents.

    Python
    View on GitHub↗211
  • pwcuk-cto/rtfsigPwCUK-CTO avatar

    PwCUK-CTO/rtfsig

    28View on GitHub↗

    A tool to help malware analysts signature unique parts of RTF documents

    Rich Text Format
    View on GitHub↗28
  • aptnotes/dataaptnotes avatar

    aptnotes/data

    1,794View on GitHub↗

    APTnotes data

    View on GitHub↗1,794
  • maliceio/malicemaliceio avatar

    maliceio/malice

    1,861View on GitHub↗

    VirusTotal Wanna Be - Now with 100% more Hipster

    Go
    View on GitHub↗1,861
  • kevoreilly/capev2kevoreilly avatar

    kevoreilly/CAPEv2

    3,284View on GitHub↗

    Malware Configuration And Payload Extraction

    Python
    View on GitHub↗3,284
  • kasperskylab/klaraKasperskyLab avatar

    KasperskyLab/klara

    731View on GitHub↗

    Kaspersky's GReAT KLara

    PHP
    View on GitHub↗731
  • fireeye/iocsfireeye avatar

    fireeye/iocs

    470View on GitHub↗

    FireEye Publicly Shared Indicators of Compromise (IOCs)

    View on GitHub↗470
  • google/vxsiggoogle avatar

    google/vxsig

    289View on GitHub↗

    Automatically generate AV byte signatures from sets of similar binaries.

    C++
    View on GitHub↗289
  • efforg/yayaEFForg avatar

    EFForg/yaya

    303View on GitHub↗

    Yet Another Yara Automaton - Automatically curate open source yara rules and run scans

    Go
    View on GitHub↗303
  • inquest/python-iocextractInQuest avatar

    InQuest/python-iocextract

    580View on GitHub↗

    Defanged Indicator of Compromise (IOC) Extractor.

    Python
    View on GitHub↗580