threat-intelligence-feeds
Here are 19 public repositories matching this topic...
Open-source cyber threat intelligence workstation for OSINT triage, Threat Actor Profiles, AI-assisted analysis, and hunt-query generation.
-
Updated
Jul 28, 2026 - TypeScript
Automated IP blacklist aggregator from 23 threat intelligence sources - updated hourly via GitHub Actions
-
Updated
Sep 19, 2026 - Python
A nonprofit, open-source vulnerability disclosure platform built for security researchers.
-
Updated
Jun 23, 2026 - Python
A public, research-focused dataset of expired, and recently dropped domains curated for cybersecurity analysis, brand monitoring, threat intelligence, and market research.
-
Updated
Sep 19, 2026
Open-source Python CTI pipeline that collects and enriches IoCs from five feeds, generates a Plotly dashboard and CSV export, and forecasts seven-day threat trends for SOC analysts.
-
Updated
Jul 6, 2026 - Python
A Python Flask web dashboard that aggregates and displays the latest cybersecurity news from multiple RSS feeds, organized by category. Quickly see titles, summaries, and publication dates of top threat intelligence sources.
-
Updated
Aug 8, 2026 - Python
🛡️ Curated collection of 300+ free, open-source and some commercial Threat Intelligence feeds – IP, DNS, URL, hashes, CVEs, MISP and more with auto-validated and status-checked daily via GitHub Actions.
-
Updated
Sep 19, 2026 - Python
APT infrastructure intelligence and IOC tracking platform
-
Updated
Sep 19, 2026 - Python
threatXmanager is an open source SDK by CorreaCyberLabsLTD for cyber threat intelligence management and incident response. Built on a STIX2 schema, it centralizes observables analysis and integrates with tools like MISP, TheHive, and MITRE ATT&CK.
-
Updated
May 1, 2026 - Python
Threat Intelligence is a branch of cybersecurrity that involves gathering information about adversaries, their infrastructure, motives, TTPs, and history. This project covers an investigation into "Nexus Zeta", following an uptick in cyber attacks across Europe targeting government sectors and critical infrastructure.
-
Updated
May 3, 2026
Talos - The Automaton Engine: Building ML Shields for Modern Threat Detection.
-
Updated
Jan 31, 2026 - Python
Full teardown of the Kyber ransomware Windows encryptor. Six corrections to public reporting, each independently verifiable. Includes analysis tooling, detection content, and incident response guidance.
-
Updated
Aug 13, 2026 - Python
Self-hosted CTI pipeline: 20+ RSS feeds, Claude AI triage, relevance scoring. n8n + Docker + AWS. Under $12/month.
-
Updated
Jun 22, 2026
AI-powered Cyber Threat Intelligence Platform for real-time threat detection, log analysis, anomaly detection, and SOC dashboard monitoring.
-
Updated
Jul 2, 2026 - TypeScript
Evaluation of 5 free public threat intelligence feeds (URLhaus, Feodo Tracker, AlienVault OTX, Emerging Threats Open, CISA KEV) against MISP and Microsoft Sentinel integration criteria, with data-backed prioritization.
-
Updated
Jul 3, 2026
First-hand technical intelligence on the Orova data-extortion group. Four Tor services (two previously unreported), full extortion lifecycle with dates, 36-victim dataset, operator tradecraft analysis, and Sigma rules. Includes two reusable methods: CUID leak-site timeline reconstruction and C2PA provenance in ransomware branding.
-
Updated
Aug 25, 2026
Automated CTI aggregator producing validated, deduplicated and firewall-ready IP, hash and URL threat feeds every hour.
-
Updated
Sep 19, 2026 - Python
Add this topic to your repo
To associate your repository with the threat-intelligence-feeds topic, visit your repo's landing page and select "manage topics."