awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to executemalware/malware-iocs

Open-source alternatives to Malware IOCs

30 open-source projects similar to executemalware/malware-iocs, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Malware IOCs alternative.

  • thehive-project/thehiveTheHive-Project avatar

    TheHive-Project/TheHive

    3,891View on GitHub↗

    TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro

    Scalaanalyzerapicortex
    View on GitHub↗3,891
  • misp/mispMISP avatar

    MISP/MISP

    6,360View on GitHub↗

    MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish

    PHP
    View on GitHub↗6,360
  • alexandreborges/malwoverviewalexandreborges avatar

    alexandreborges/malwoverview

    3,882View on GitHub↗

    This project is a Python command-line security tool and malware analysis framework designed for threat intelligence aggregation and incident triage. It functions as an aggregator that orchestrates queries across multiple security services and sandboxes to analyze hashes, IP addresses, and domains. The tool distinguishes itself by incorporating an intelligence layer that uses language models to provide automated risk assessments and framework mappings. It also includes specialized capabilities for extracting indicators of compromise from unstructured text, documents, and web pages, as well as

    Pythonalienvaultcvecve-search
    View on GitHub↗3,882

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • telekom-security/tpotcetelekom-security avatar

    telekom-security/tpotce

    9,298View on GitHub↗

    T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors. The system features a distributed sensor network using a hub-and-spoke architecture, allowing remote sensors to transmit logs back to a central management hub. It integrates large language models to create a dynamic deception engine capable of adaptive interactions with attackers. The

    Shelldeceptiondockerelk
    View on GitHub↗9,298
  • dtag-dev-sec/tpotcedtag-dev-sec avatar

    dtag-dev-sec/tpotce

    9,281View on GitHub↗

    T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based security sandbox to deploy and manage a collection of diverse decoy services that simulate vulnerable targets to lure attackers and record their activity. The system features a distributed sensor network where remote nodes capture attack logs and transmit them via encrypted communication to a central hub. This central hub employs an analytics stack to transform raw logs into geographic maps and interactive dashboards for adversary behavior visualization. To increase the realism of si

    Shell
    View on GitHub↗9,281
  • neo23x0/lokiNeo23x0 avatar

    Neo23x0/Loki

    3,763View on GitHub↗

    Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems. The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte seq

    Python
    View on GitHub↗3,763
  • elastic/detection-ruleselastic avatar

    elastic/detection-rules

    2,508View on GitHub↗

    This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base

    Pythonthreat-detectionthreat-hunting
    View on GitHub↗2,508
  • doctorwebltd/malware-iocsDoctorWebLtd avatar

    DoctorWebLtd/malware-iocs

    242View on GitHub↗
    View on GitHub↗242
  • cisco-talos/iocsC

    Cisco-Talos/IOCs

    0View on GitHub↗

    //////////////// ////////////////////// // //////////////////////// // /// /////// ///// /////// /////// /////// /////// //////// //////// //////// //////// //////// //////// //////// //////// //////// //////// /////// /////// /////// /////// ///// // ////// // // /////////////////////////…

    View on GitHub↗0
  • bert-janp/open-source-threat-intel-feedsBert-JanP avatar

    Bert-JanP/Open-Source-Threat-Intel-Feeds

    773View on GitHub↗
    Pythonc2iociocfeed
    View on GitHub↗773
  • eset/malware-ioceset avatar

    eset/malware-ioc

    1,955View on GitHub↗

    Indicators of Compromises (IOC) of our various investigations

    YARA
    View on GitHub↗1,955
  • hadojae/datahadojae avatar

    hadojae/DATA

    99View on GitHub↗

    Credential Phish Analysis and Automation

    Python
    View on GitHub↗99
  • hagezi/dns-blocklistshagezi avatar

    hagezi/dns-blocklists

    20,103View on GitHub↗

    This project is a comprehensive repository of curated domain blocklists designed for network-wide DNS filtering. It functions as a DNS sinkhole feed, providing the necessary data to intercept and block unwanted network requests at the resolution layer before they reach their destination. By returning null or loopback addresses for identified domains, it prevents connections to malicious infrastructure, advertising servers, and tracking endpoints across all devices on a network. The repository distinguishes itself through a tiered categorization logic that allows users to select protection lev

    Textadblockadguardads
    View on GitHub↗20,103
  • harfanglab/iocsHarfangLab avatar

    HarfangLab/iocs

    20View on GitHub↗

    Indicators of compromise

    YARA
    View on GitHub↗20
  • elastic/labs-releasesE

    elastic/labs-releases

    0View on GitHub↗
    View on GitHub↗0
  • mlsecproject/combinemlsecproject avatar

    mlsecproject/combine

    656View on GitHub↗

    Tool to gather Threat Intelligence indicators from publicly available sources

    Python
    View on GitHub↗656
  • blocklistproject/listsblocklistproject avatar

    blocklistproject/Lists

    4,641View on GitHub↗

    Lists is a curated collection of DNS blocklists, a domain blocklist generator, and a categorized library of domains used for network content filtering. The project provides a command-line pipeline that aggregates upstream sources to build and validate blocklists used to redirect unwanted traffic to null addresses. The project distinguishes itself through a CLI-driven build pipeline that automates the fetching, validation, and daily regeneration of datasets. It organizes domains into discrete functional categories rather than a single monolithic list and exports them in multiple syntaxes, incl

    Pythonadblockadblock-listblocklist
    View on GitHub↗4,641
  • jekil/awesome-hackingjekil avatar

    jekil/awesome-hacking

    3,746View on GitHub↗

    This project is a curated, version-controlled directory of software and resources designed for cybersecurity professionals and researchers. It functions as a centralized knowledge base that aggregates and organizes external security utilities into a structured taxonomy to facilitate discovery and access for specialized research and testing tasks. The repository distinguishes itself through a community-driven model where external resource locations are verified and maintained by contributors. By leveraging a distributed version control system, the project ensures the historical integrity and c

    Pythoncurated-listforensicshacking
    View on GitHub↗3,746
  • jarelllama/scam-blocklistjarelllama avatar

    jarelllama/Scam-Blocklist

    106View on GitHub↗

    Blocklist for newly created scam, phishing, and other malicious domains automatically retrieved daily using Google Search API, automated detection, and public databases.

    Shell
    View on GitHub↗106
  • intelowlproject/intelowlintelowlproject avatar

    intelowlproject/IntelOwl

    4,605View on GitHub↗

    IntelOwl is a threat intelligence platform and security orchestration engine designed to aggregate, analyze, and enrich security observables. It functions as a security incident investigation tool and a threat intelligence aggregator, collecting data on files, domains, and IP addresses from diverse internal and external sources. The system differentiates itself through playbook-based workflow automation, allowing users to define reusable sequences of analysis tasks that trigger subsequent jobs based on prior outputs. It unifies disparate security data into a common schema and utilizes protoco

    Pythoncyber-securitycyber-threat-intelligencecybersecurity
    View on GitHub↗4,605
  • montysecurity/c2-trackermontysecurity avatar

    montysecurity/C2-Tracker

    774View on GitHub↗

    C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan ~~and Censys~~ searches to collect IP addresses of known malware/botnet/C2 infrastructure.

    Python
    View on GitHub↗774
  • mthcht/iocsmthcht avatar

    mthcht/iocs

    5View on GitHub↗

    This repository contains indicators related to Unit 42 Public Reports.

    View on GitHub↗5
  • mthcht/threatintel-reportsmthcht avatar

    mthcht/ThreatIntel-Reports

    166View on GitHub↗

    A repository of extracted content from thousands of threat intelligence reports, with an automatic extraction of reports from various feeds !

    Python
    View on GitHub↗166
  • inquest/threatingestorInQuest avatar

    InQuest/ThreatIngestor

    917View on GitHub↗

    Extract and aggregate threat intelligence.

    Python
    View on GitHub↗917
  • neo23x0/sigmaNeo23x0 avatar

    Neo23x0/sigma

    10,591View on GitHub↗

    Sigma is a generic SIEM signature format and log event pattern standard used to describe malicious activity. It provides a vendor-neutral system for defining security event patterns in YAML, ensuring that detection logic remains portable across different monitoring platforms. The project maintains a curated library of peer-reviewed detection rules that identify threats and compliance violations. This standardized approach allows for the exchange of threat hunting logic and the translation of generic signatures into specific queries for various security information and event management systems

    Python
    View on GitHub↗10,591
  • nsacyber/grassmarlinnsacyber avatar

    nsacyber/GRASSMARLIN

    1,059View on GitHub↗

    Provides situational awareness of Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) networks in support of network security assessments. #nsacyber

    Java
    View on GitHub↗1,059
  • opensourcesec/forageropensourcesec avatar

    opensourcesec/Forager

    177View on GitHub↗

    Multithreaded threat Intelligence gathering built with Python3

    Python
    View on GitHub↗177
  • oseasfr/search-abuseipdbO

    oseasfr/search-abuseipdb

    0View on GitHub↗
    View on GitHub↗0
  • paloaltonetworks/unit42-threat-intelligence-article-informationPaloAltoNetworks avatar

    PaloAltoNetworks/Unit42-Threat-Intelligence-Article-Information

    117View on GitHub↗

    This is the repository for indicators of compromise (IOCs) and other data supporting threat intelligence articles posted on the Palo Alto Networks Unit 42 website.

    Python
    View on GitHub↗117
  • drb-ra/c2intelfeedsdrb-ra avatar

    drb-ra/C2IntelFeeds

    726View on GitHub↗

    Automatically created C2 Feeds | Also posted via @drb_ra

    REXX
    View on GitHub↗726