TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro
SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati
Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive
Argus is a modular network reconnaissance framework designed for gathering network intelligence, mapping infrastructure, and assessing security postures through automated discovery tasks. It operates as a containerized security toolset that allows for the consistent execution of specialized information-gathering modules across different operating systems. The system functions as an infrastructure audit tool and a web application security scanner, performing tasks such as DNS lookups, port scanning, and the inspection of HTTP headers to detect vulnerabilities. It also serves as a threat intell
IntelOwl एक थ्रेट इंटेलिजेंस प्लेटफ़ॉर्म और सुरक्षा ऑर्केस्ट्रेशन इंजन है जिसे सुरक्षा अवलोकनों (observables) को एकत्रित, विश्लेषण और समृद्ध करने के लिए डिज़ाइन किया गया है। यह एक सुरक्षा घटना जांच टूल और थ्रेट इंटेलिजेंस एग्रीगेटर के रूप में कार्य करता है, जो विभिन्न आंतरिक और बाहरी स्रोतों से फ़ाइलों, डोमेन और IP पतों पर डेटा एकत्र करता है। सिस्टम प्लेबुक-आधारित वर्कफ़्लो ऑटोमेशन के माध्यम से अलग दिखता है, जो यूज़र्स को विश्लेषण कार्यों के पुन: प्रयोज्य अनुक्रमों को…
intelowlproject/intelowl की मुख्य विशेषताएं हैं: Analysis Playbooks, Security Operations Automation, External Intelligence Integrators, Analysis Workflow Chaining, Security Automation Workflows, Security Workflow Automators, Intelligence Enrichment, Incident Investigation Tools।
intelowlproject/intelowl के ओपन-सोर्स विकल्पों में शामिल हैं: thehive-project/thehive — TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security… smicallef/spiderfoot — SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the… security-onion-solutions/securityonion — Security Onion is a security information and event management platform and network security monitoring suite. It… jasonxtn/argus — Argus is a modular network reconnaissance framework designed for gathering network intelligence, mapping… reconurge/flowsint — Flowsint is an open-source intelligence framework and reconnaissance orchestrator used for cybersecurity… alexandreborges/malwoverview — This project is a Python command-line security tool and malware analysis framework designed for threat intelligence…