Skip to content

Latest commit

 

History

History
245 lines (163 loc) · 7.87 KB

File metadata and controls

245 lines (163 loc) · 7.87 KB

Threat Intelligence Resources

A curated list of open-source tools, datasets, sandboxes, scanning engines, and OSINT resources for cyber threat hunters, incident responders, DFIR analysts, and researchers.

This collection is designed to make investigation work easier by keeping high-value, free or community-driven resources in one place.

Awesome


Table of Contents


Network Scanning & Exposure Mapping

Tools that help identify exposed services, discover internet-facing infrastructure, and pivot across assets.


IP, ASN & Geolocation Intelligence

Helpful for attribution, routing analysis, enrichment, and network-level context.


Malware Analysis & Sandboxes

Detonation platforms for behavioral analysis, static inspection, and threat classification.


Threat Feeds & IOC Sources

Community-driven IOC collections for malware C2s, botnets, ransomware, and malicious infrastructure.


DNS & Domain Intelligence

Resolve infrastructure changes, pivot on DNS records, and explore domain history.


Threat Actor Profiles & Frameworks


OSINT & Digital Footprinting

Useful for identity research, infrastructure mapping, and investigations.


Routing, Certificates & Infrastructure Mapping

Tools for BGP, TLS fingerprinting, CT logs, and network-level pivoting.


Dark Web & Leak Monitoring

Some free, OSINT-safe resources exist for monitoring leaked data and Tor infrastructure.

  • dark.failhttps://dark.fail
    Tor service status and verified links.

  • Public BreachForum mirrors
    Mirrors used for OSINT on leaked data (avoid criminal sites).


Tools & Utilities


Contributing

Suggestions, PRs, and new tool recommendations are welcome!
Feel free to submit improvements or new resources.