awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to viper-framework/viper

Open-source alternatives to Viper

30 open-source projects similar to viper-framework/viper, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Viper alternative.

  • misp/mispMISP avatar

    MISP/MISP

    6,360View on GitHub↗

    MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish

    PHP
    View on GitHub↗6,360
  • alexandreborges/malwoverviewalexandreborges avatar

    alexandreborges/malwoverview

    3,882View on GitHub↗

    This project is a Python command-line security tool and malware analysis framework designed for threat intelligence aggregation and incident triage. It functions as an aggregator that orchestrates queries across multiple security services and sandboxes to analyze hashes, IP addresses, and domains. The tool distinguishes itself by incorporating an intelligence layer that uses language models to provide automated risk assessments and framework mappings. It also includes specialized capabilities for extracting indicators of compromise from unstructured text, documents, and web pages, as well as

    Pythonalienvaultcvecve-search
    View on GitHub↗3,882
  • kevoreilly/capev2kevoreilly avatar

    kevoreilly/CAPEv2

    3,284View on GitHub↗

    Malware Configuration And Payload Extraction

    Python
    View on GitHub↗3,284
  • rastrea2r/rastrea2rrastrea2r avatar

    rastrea2r/rastrea2r

    242View on GitHub↗

    Collecting & Hunting for IOCs with gusto and style

    Python
    View on GitHub↗242

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • radareorg/radare2radareorg avatar

    radareorg/radare2

    23,120View on GitHub↗

    Radare2 is a comprehensive framework for reverse engineering and analyzing compiled software. It provides a command-line environment designed for disassembling, debugging, and patching binary executables across a wide range of processor architectures and operating systems. The system distinguishes itself through a modular, plugin-based architecture that supports cross-platform analysis and automated workflows. It utilizes memory-mapped file access to enable efficient structural inspection and modification of binaries without requiring full file loads. By lifting machine instructions into a un

    Cbinary-analysisccommandline
    View on GitHub↗23,120
  • korelogicsecurity/mastiffKoreLogicSecurity avatar

    KoreLogicSecurity/mastiff

    185View on GitHub↗

    Malware static analysis framework

    Python
    View on GitHub↗185
  • inquest/threatingestorInQuest avatar

    InQuest/ThreatIngestor

    917View on GitHub↗

    Extract and aggregate threat intelligence.

    Python
    View on GitHub↗917
  • doctorwebltd/malware-iocsDoctorWebLtd avatar

    DoctorWebLtd/malware-iocs

    242View on GitHub↗
    View on GitHub↗242
  • nationalsecurityagency/ghidraNationalSecurityAgency avatar

    NationalSecurityAgency/ghidra

    69,740View on GitHub↗

    Ghidra is a software reverse engineering suite designed to analyze compiled binaries and reconstruct program logic without access to original source code. It provides an interactive environment for disassembly and decompilation, utilizing a platform-independent intermediate representation to maintain consistency across diverse hardware architectures. The framework supports automated binary analysis through programmatic routines, enabling the investigation of complex code patterns and security indicators. The platform distinguishes itself through a modular architecture that allows for extensiv

    Javadisassemblerreverse-engineeringsoftware-analysis
    View on GitHub↗69,740
  • eset/malware-ioceset avatar

    eset/malware-ioc

    1,955View on GitHub↗

    Indicators of Compromises (IOC) of our various investigations

    YARA
    View on GitHub↗1,955
  • neo23x0/lokiNeo23x0 avatar

    Neo23x0/Loki

    3,763View on GitHub↗

    Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems. The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte seq

    Python
    View on GitHub↗3,763
  • telekom-security/tpotcetelekom-security avatar

    telekom-security/tpotce

    9,298View on GitHub↗

    T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors. The system features a distributed sensor network using a hub-and-spoke architecture, allowing remote sensors to transmit logs back to a central management hub. It integrates large language models to create a dynamic deception engine capable of adaptive interactions with attackers. The

    Shelldeceptiondockerelk
    View on GitHub↗9,298
  • dtag-dev-sec/tpotcedtag-dev-sec avatar

    dtag-dev-sec/tpotce

    9,281View on GitHub↗

    T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based security sandbox to deploy and manage a collection of diverse decoy services that simulate vulnerable targets to lure attackers and record their activity. The system features a distributed sensor network where remote nodes capture attack logs and transmit them via encrypted communication to a central hub. This central hub employs an analytics stack to transform raw logs into geographic maps and interactive dashboards for adversary behavior visualization. To increase the realism of si

    Shell
    View on GitHub↗9,281
  • thehive-project/thehiveTheHive-Project avatar

    TheHive-Project/TheHive

    3,891View on GitHub↗

    TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro

    Scalaanalyzerapicortex
    View on GitHub↗3,891
  • elastic/detection-ruleselastic avatar

    elastic/detection-rules

    2,508View on GitHub↗

    This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base

    Pythonthreat-detectionthreat-hunting
    View on GitHub↗2,508
  • blacksnufkin/litterboxBlackSnufkin avatar

    BlackSnufkin/LitterBox

    1,469View on GitHub↗

    A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.

    YARAaidocker-composemalware-analysis
    View on GitHub↗1,469
  • blacklotuslabs/iocsblacklotuslabs avatar

    blacklotuslabs/IOCs

    144View on GitHub↗

    IOCs published by Black Lotus Labs

    View on GitHub↗144
  • advanced-threat-research/iocsadvanced-threat-research avatar

    advanced-threat-research/IOCs

    83View on GitHub↗

    Repository containing IOCs, CSV and MISP JSON from our blogs

    HTML
    View on GitHub↗83
  • bert-janp/open-source-threat-intel-feedsBert-JanP avatar

    Bert-JanP/Open-Source-Threat-Intel-Feeds

    773View on GitHub↗
    Pythonc2iociocfeed
    View on GitHub↗773
  • avast/iocA

    avast/ioc

    0View on GitHub↗

    Threat Intel IoCs bits and pieces of dark matter. Published by Gen Threat Labs.

    View on GitHub↗0
  • advanced-threat-research/darkside-config-extractA

    advanced-threat-research/DarkSide-Config-Extract

    0View on GitHub↗
    View on GitHub↗0
  • accidentalrebel/mbcscanA

    accidentalrebel/mbcscan

    0View on GitHub↗
    View on GitHub↗0
  • cert-polska/mwdb-coreC

    CERT-Polska/mwdb-core

    0View on GitHub↗
    View on GitHub↗0
  • certsocietegenerale/fircertsocietegenerale avatar

    certsocietegenerale/FIR

    2,009View on GitHub↗

    Fast Incident Response

    JavaScript
    View on GitHub↗2,009
  • checkpointsw/showstopperCheckPointSW avatar

    CheckPointSW/showstopper

    223View on GitHub↗

    Contributed by Check Point Software Technologies LTD. Programmed by Yaraslau Harakhavik

    C++
    View on GitHub↗223
  • circl/traceroute-circlCIRCL avatar

    CIRCL/traceroute-circl

    40View on GitHub↗

    Traceroute improved wrapper for CSIRT and CERT operators

    Perl
    View on GitHub↗40
  • cisagov/untitledgoosetoolcisagov avatar

    cisagov/untitledgoosetool

    956View on GitHub↗

    Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to run a full investigation against a customer’s Azure Active Directory (AzureAD), Azure, and M365 environments.

    Python
    View on GitHub↗956
  • cisco-talos/iocsC

    Cisco-Talos/IOCs

    0View on GitHub↗

    //////////////// ////////////////////// // //////////////////////// // /// /////// ///// /////// /////// /////// /////// //////// //////// //////// //////// //////// //////// //////// //////// //////// //////// /////// /////// /////// /////// ///// // ////// // // /////////////////////////…

    View on GitHub↗0
  • cmu-sei/cyobstractC

    cmu-sei/cyobstract

    0View on GitHub↗
    View on GitHub↗0
  • cert-polska/kartonC

    CERT-Polska/karton

    0View on GitHub↗
    View on GitHub↗0