awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

Self-Hosted Threat Intelligence Platforms

Ranking updated Jun 30, 2026

For a threat intelligence platform, the first results are misp/misp (MISP is purpose-built as a self-hosted threat intelligence and sharing platform with comprehensive IoC management, a REST API, distributed synchronization for feed integration, and collaboration features—exactly what the visitor needs for tracking indicators of compromise), thehive-project/thehive and opencti-platform/opencti. certtools/intelmq and offensive-security/exploitdb round out the shortlist. Compare the match explanations and check the project documentation against your requirements.

Open-source platforms for collecting, analyzing, and tracking cyber threat indicators within your own infrastructure.

Self-Hosted Threat Intelligence Platforms

Find the best repos with AI.We'll search the best matching repositories with AI.
  • misp/mispMISP avatar

    MISP/MISP

    6,360View on GitHub↗

    MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish

    MISP is purpose-built as a self-hosted threat intelligence and sharing platform with comprehensive IoC management, a REST API, distributed synchronization for feed integration, and collaboration features—exactly what the visitor needs for tracking indicators of compromise.

    PHPTAXII ExchangesThreat Indicator Correlators
    View on GitHub↗6,360
  • thehive-project/thehiveTheHive-Project avatar

    TheHive-Project/TheHive

    3,891View on GitHub↗

    TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro

    TheHive is a self-hosted security incident response and threat intelligence platform that manages observables (IoCs) with multi-tenant case management, integrates with threat feeds like MISP, exposes a REST API for automation, and provides collaboration and sharing, making it a comprehensive fit for your threat intelligence workflow.

    ScalaIncident ManagementMulti-Tenant Data ManagementAlert Triage
    View on GitHub↗3,891
  • opencti-platform/openctiOpenCTI-Platform avatar

    OpenCTI-Platform/opencti

    8,812View on GitHub↗

    OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide

    OpenCTI is a self-hosted cyber threat intelligence platform purpose-built for storing, managing, and analyzing indicators of compromise using the STIX and TAXII standards, which directly covers IoC management, threat feed integration, API automation, dashboard visualization, and sharing—exactly matching your threat intelligence workflow needs.

    TypeScriptThreat Entity Relationship GraphsThreat Intelligence PlatformsCyber Threat Intelligence Maps
    View on GitHub↗8,812
  • certtools/intelmqcerttools avatar

    certtools/intelmq

    1,114View on GitHub↗

    IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

    IntelMQ is a self-hosted threat intelligence platform that collects and processes security feeds, manages indicators of compromise, offers a web dashboard and API, and supports feed integration and team collaboration, making it a comprehensive fit for this threat intelligence workflow.

    PythonForensic FrameworksForensic FrameworksThreat Intelligence
    View on GitHub↗1,114
  • offensive-security/exploitdboffensive-security avatar

    offensive-security/exploitdb

    7,845View on GitHub↗

    ExploitDB is a curated archive of exploit code and vulnerability data designed for penetration testing and security research. It serves as an offensive security knowledge base and a repository of publicly available proof-of-concept code used to validate software flaws. The project provides a searchable collection of historical and current exploit vectors. It supports security threat intelligence by tracking public releases and aids in vulnerability research by providing a reference library for analyzing how specific systems can be compromised. The archive is managed through a curated input p

    ExploitDB is a curated archive of exploit code and vulnerability data for penetration testing, not a platform for collecting, managing, or tracking indicators of compromise in a threat intelligence workflow — it serves offensive research rather than defensive IoC management.

    Threat Intelligence Resources
    View on GitHub↗7,845
  • jasonxtn/argusjasonxtn avatar

    jasonxtn/Argus

    3,254View on GitHub↗

    Argus is a modular network reconnaissance framework designed for gathering network intelligence, mapping infrastructure, and assessing security postures through automated discovery tasks. It operates as a containerized security toolset that allows for the consistent execution of specialized information-gathering modules across different operating systems. The system functions as an infrastructure audit tool and a web application security scanner, performing tasks such as DNS lookups, port scanning, and the inspection of HTTP headers to detect vulnerabilities. It also serves as a threat intell

    Argus is a network reconnaissance and infrastructure mapping framework rather than a dedicated platform for collecting, managing, and tracking indicators of compromise, so it lacks the core IoC management and collaboration features this search requires.

    PythonThreat Intelligence Resources
    View on GitHub↗3,254
  • rstudio/shinyrstudio avatar

    rstudio/shiny

    5,608View on GitHub↗

    Shiny is a framework for building interactive web applications using R code, eliminating the need for HTML, CSS, or JavaScript. At its core, it provides a reactive programming model that automatically tracks data dependencies and re-executes only the parts of an application that depend on changed inputs. The framework handles server-side UI rendering and maintains persistent WebSocket connections between the browser and server for real-time updates without page reloads. The framework distinguishes itself through deep integration with the R ecosystem, including the ability to embed interactive

    Shiny is a framework for building interactive web applications in R, but it is not a self-hosted threat intelligence platform—it lacks built-in IoC management, threat feed integration, and collaboration features, making it a building block rather than the ready-to-use tool you need.

    ROn-Premise Deployment
    View on GitHub↗5,608
  • crowdsecurity/crowdseccrowdsecurity avatar

    crowdsecurity/crowdsec

    12,574View on GitHub↗

    CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl

    CrowdSec is a collaborative intrusion detection and prevention engine that generates and shares IP-based indicators, making it a security tool you could integrate into a threat intelligence workflow rather than a dedicated self-hosted platform for collecting, managing, and tracking IoCs with full feed integration, dashboards, and sharing features.

    GoBlocklist Aggregators
    View on GitHub↗12,574
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
misp/misp6.4KPHPAGPL-3.0Jun 17, 2026
thehive-project/thehive3.9KScalaagpl-3.0Jul 25, 2025
opencti-platform/opencti
8.8K
TypeScript
other
Feb 19, 2026
certtools/intelmq1.1KPythonAGPL-3.0Apr 28, 2026
offensive-security/exploitdb7.8K—gpl-2.0Nov 10, 2022
jasonxtn/argus3.3KPythonmitDec 10, 2025
rstudio/shiny5.6KRotherFeb 18, 2026
crowdsecurity/crowdsec12.6KGomitFeb 19, 2026

Related searches

  • an incident response platform
  • a self-hosted SIEM
  • an indicator enrichment tool
  • a self-hosted internet scanner
  • a self hosted platform for user analytics
  • an open source SIEM for log analysis
  • a self-hosted BI dashboard tool
  • a deception and decoy platform