awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
intelowlproject avatar

intelowlproject/IntelOwl

0
View on GitHub↗
4,605 stars·647 forks·Python·AGPL-3.0·34 viewsintelowlproject.github.io↗

IntelOwl

IntelOwl is a threat intelligence platform and security orchestration engine designed to aggregate, analyze, and enrich security observables. It functions as a security incident investigation tool and a threat intelligence aggregator, collecting data on files, domains, and IP addresses from diverse internal and external sources.

The system differentiates itself through playbook-based workflow automation, allowing users to define reusable sequences of analysis tasks that trigger subsequent jobs based on prior outputs. It unifies disparate security data into a common schema and utilizes protocol-level access controls to restrict the execution of analyzers based on data sensitivity.

The platform covers a broad range of capabilities, including event-driven indicator ingestion, automated security operations center workflows, and intelligence enrichment. It provides tools for investigation organization and the visualization of analysis results through dashboards to correlate findings.

The project is implemented in Python.

Features

  • Analysis Playbooks - Defines reusable sequences of analysis tasks that trigger subsequent jobs based on the output of previous steps.
  • Security Operations Automation - Implements a workflow engine that executes repeatable playbooks to automate manual security operations center tasks.
  • External Intelligence Integrators - Coordinates requests across a variety of internal tools and external APIs to enrich security observables.
  • Analysis Workflow Chaining - Triggers subsequent analysis jobs based on the results of previous tasks to automate complex investigation paths.
  • Security Automation Workflows - Executes repeatable playbooks and integrates libraries to replace manual security analyst tasks with automated processes.
  • Security Workflow Automators - Replaces manual security analyst tasks with repeatable playbooks and automated workflows to process threat observables.
  • Intelligence Enrichment - Aggregates data for malware and observables from multiple external and internal sources to increase context.
  • Incident Investigation Tools - Provides a workspace for grouping related analysis jobs and notes to identify security threats and correlate data.
  • Investigation Case Management - Groups related analysis jobs and notes into a single entity to track findings and correlate information.
  • Observable Analyzers - Extracts intelligence from files, IPs, and domains using static analysis and external API integrations.
  • Threat Intelligence Aggregation - Aggregates data on malware, IPs, and domains from multiple external analyzers via a single request to unify security research.
  • Threat Observable Analysis - Extracts intelligence from files and network indicators using static analysis tools and external API integrations.
  • Threat Intelligence Management - Organizes security investigations and tracks analyzed artifacts to correlate findings across diverse threat reports.
  • Threat Intelligence Platforms - Functions as a centralized system for aggregating, analyzing, and enriching security observables from internal and external sources.
  • Analysis Tool Grouping - Saves combinations of analyzers and connectors as reusable playbooks to standardize recurring investigation tasks.
  • Technical Indicator Tracking - Maintains unique entities for observables to link multiple analysis jobs and metadata to a single artifact.
  • Investigation Dashboards - Renders threat data through dashboards and visualizers to correlate findings and track investigation progress.
  • Indicator Feed Ingestion - Automatically triggers analysis playbooks when new observables are imported from external threat streams.
  • Stream Ingestion - Imports streams of observables or files automatically for immediate processing and analysis.
  • Observable Artifact Tracking - Maintains unique objects for observables to link multiple analysis jobs to a single file or indicator.
  • Data Privacy Controls - Controls the execution of analyzers and connectors based on protocol levels to prevent sensitive data leakage.
  • Analyzer Access Controls - Restricts the execution of specific analyzers and connectors based on data sensitivity levels to prevent information leakage.
  • Reliability Scoring - Combines analyzer data models with user reports to produce reliability and evaluation scores for observables.
  • Schema-Based Aggregation - Unifies diverse security data from multiple external analyzers into a common data model for consistent evaluation.
  • Threat Intelligence - Scalable management of threat intelligence data.
  • Detection and Hunting Tools - OSINT solution for gathering threat intelligence at scale.
  • Open Source Intelligence - Analyzes files and domains using multiple intelligence sources.
  • Threat Intelligence - Automated OSINT analysis for files, IPs, and domains.

Star history

Star history chart for intelowlproject/intelowlStar history chart for intelowlproject/intelowl

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with IntelOwl

These projects share indexed features with IntelOwl. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • thehive-project/thehiveTheHive-Project avatar

    TheHive-Project/TheHive

    3,891View on GitHub↗

    TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro

    Scalaanalyzerapicortex
    View on GitHub↗3,891
  • smicallef/spiderfootsmicallef avatar

    smicallef/spiderfoot

    18,189View on GitHub↗

    SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati

    Pythonattacksurfacecticybersecurity
    View on GitHub↗18,189
  • security-onion-solutions/securityonionSecurity-Onion-Solutions avatar

    Security-Onion-Solutions/securityonion

    4,661View on GitHub↗

    Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive

    Shell
    View on GitHub↗4,661
  • jasonxtn/argusjasonxtn avatar

    jasonxtn/Argus

    3,254View on GitHub↗

    Argus is a modular network reconnaissance framework designed for gathering network intelligence, mapping infrastructure, and assessing security postures through automated discovery tasks. It operates as a containerized security toolset that allows for the consistent execution of specialized information-gathering modules across different operating systems. The system functions as an infrastructure audit tool and a web application security scanner, performing tasks such as DNS lookups, port scanning, and the inspection of HTTP headers to detect vulnerabilities. It also serves as a threat intell

    Pythoncms-detectiondirectory-finderdns-lookup
    View on GitHub↗3,254
Compare all 30 related projects→

Frequently asked questions

What does intelowlproject/intelowl do?

IntelOwl is a threat intelligence platform and security orchestration engine designed to aggregate, analyze, and enrich security observables. It functions as a security incident investigation tool and a threat intelligence aggregator, collecting data on files, domains, and IP addresses from diverse internal and external sources.

What are the main features of intelowlproject/intelowl?

The main features of intelowlproject/intelowl are: Analysis Playbooks, Security Operations Automation, External Intelligence Integrators, Analysis Workflow Chaining, Security Automation Workflows, Security Workflow Automators, Intelligence Enrichment, Incident Investigation Tools.

Which projects share features with intelowlproject/intelowl?

Projects with overlapping indexed features include: thehive-project/thehive — TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security… smicallef/spiderfoot — SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the… security-onion-solutions/securityonion — Security Onion is a security information and event management platform and network security monitoring suite. It… jasonxtn/argus — Argus is a modular network reconnaissance framework designed for gathering network intelligence, mapping… reconurge/flowsint — Flowsint is an open-source intelligence framework and reconnaissance orchestrator used for cybersecurity… alexandreborges/malwoverview — This project is a Python command-line security tool and malware analysis framework designed for threat intelligence…