For a threat intelligence platform, the first results are misp/misp (MISP is purpose-built as a self-hosted threat intelligence and sharing platform with comprehensive IoC management, a REST API, distributed synchronization for feed integration, and collaboration features—exactly what the visitor needs for tracking indicators of compromise), thehive-project/thehive and opencti-platform/opencti. certtools/intelmq and offensive-security/exploitdb round out the shortlist. Compare the match explanations and check the project documentation against your requirements.
Open-source platforms for collecting, analyzing, and tracking cyber threat indicators within your own infrastructure.
MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish
MISP is purpose-built as a self-hosted threat intelligence and sharing platform with comprehensive IoC management, a REST API, distributed synchronization for feed integration, and collaboration features—exactly what the visitor needs for tracking indicators of compromise.
TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro
TheHive is a self-hosted security incident response and threat intelligence platform that manages observables (IoCs) with multi-tenant case management, integrates with threat feeds like MISP, exposes a REST API for automation, and provides collaboration and sharing, making it a comprehensive fit for your threat intelligence workflow.
OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide
OpenCTI is a self-hosted cyber threat intelligence platform purpose-built for storing, managing, and analyzing indicators of compromise using the STIX and TAXII standards, which directly covers IoC management, threat feed integration, API automation, dashboard visualization, and sharing—exactly matching your threat intelligence workflow needs.
IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
IntelMQ is a self-hosted threat intelligence platform that collects and processes security feeds, manages indicators of compromise, offers a web dashboard and API, and supports feed integration and team collaboration, making it a comprehensive fit for this threat intelligence workflow.
ExploitDB is a curated archive of exploit code and vulnerability data designed for penetration testing and security research. It serves as an offensive security knowledge base and a repository of publicly available proof-of-concept code used to validate software flaws. The project provides a searchable collection of historical and current exploit vectors. It supports security threat intelligence by tracking public releases and aids in vulnerability research by providing a reference library for analyzing how specific systems can be compromised. The archive is managed through a curated input p
ExploitDB is a curated archive of exploit code and vulnerability data for penetration testing, not a platform for collecting, managing, or tracking indicators of compromise in a threat intelligence workflow — it serves offensive research rather than defensive IoC management.
Argus is a modular network reconnaissance framework designed for gathering network intelligence, mapping infrastructure, and assessing security postures through automated discovery tasks. It operates as a containerized security toolset that allows for the consistent execution of specialized information-gathering modules across different operating systems. The system functions as an infrastructure audit tool and a web application security scanner, performing tasks such as DNS lookups, port scanning, and the inspection of HTTP headers to detect vulnerabilities. It also serves as a threat intell
Argus is a network reconnaissance and infrastructure mapping framework rather than a dedicated platform for collecting, managing, and tracking indicators of compromise, so it lacks the core IoC management and collaboration features this search requires.
Shiny is a framework for building interactive web applications using R code, eliminating the need for HTML, CSS, or JavaScript. At its core, it provides a reactive programming model that automatically tracks data dependencies and re-executes only the parts of an application that depend on changed inputs. The framework handles server-side UI rendering and maintains persistent WebSocket connections between the browser and server for real-time updates without page reloads. The framework distinguishes itself through deep integration with the R ecosystem, including the ability to embed interactive
Shiny is a framework for building interactive web applications in R, but it is not a self-hosted threat intelligence platform—it lacks built-in IoC management, threat feed integration, and collaboration features, making it a building block rather than the ready-to-use tool you need.
CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl
CrowdSec is a collaborative intrusion detection and prevention engine that generates and shares IP-based indicators, making it a security tool you could integrate into a threat intelligence workflow rather than a dedicated self-hosted platform for collecting, managing, and tracking IoCs with full feed integration, dashboards, and sharing features.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| misp/misp | 6.4K | PHP | AGPL-3.0 | |
| thehive-project/thehive | 3.9K | Scala | agpl-3.0 | |
| opencti-platform/opencti |
| 8.8K |
| TypeScript |
| other |
| certtools/intelmq | 1.1K | Python | AGPL-3.0 |
| offensive-security/exploitdb | 7.8K | — | gpl-2.0 |
| jasonxtn/argus | 3.3K | Python | mit |
| rstudio/shiny | 5.6K | R | other |
| crowdsecurity/crowdsec | 12.6K | Go | mit |