183 off-site sources I cross-reference: dashboards, OSINT directories, training labs, malware samples, and research portfolios. Filter by kind or search across name and description.External sites change ownership and quality over time. Verify a specific link before relying on it.
Community-curated hub of AI-security resources - adversarial ML, LLM red-teaming, model/data exfiltration, prompt-injection catalogues, governance frameworks, and AI-CTI tooling. Useful as a discovery surface when triaging AI-system risks or scoping AI red-team engagements.
why: Centralised AI-security starting point I cross-reference when scoping AI risk assessments or building detection content for LLM-adjacent threats.
Curated start.me page by Syberseeker aggregating free certification tracks - security, cloud, networking, and blue-team paths from vendors, universities, and community programs. Mirrored in-platform at /threatintel/osint/certs with a daily auto-sync.
why: The single best free-cert starting point I have found. Direct mirror on the platform means the same link list is searchable, deep-linkable, and survives start.me outages.
Internet asset search engine in the Shodan/Censys/FOFA family. Fingerprints 500+ network protocols across 2,000+ products with country, SSL-certificate, and subdomain filters. Free daily quota; paid plans for higher throughput.
Open Source Vulnerabilities database - Google-backed, API-first vulnerability feed covering PyPI, npm, Go, Maven, and other ecosystems with ecosystem-agnostic schema.
Upstream stats dashboard for bitwire-it/ipblocklist - live counters, growth history and source attribution. Pairs with the in-platform mirror at /threatintel/bitwire-blocklist.
Comprehensive insider threat framework covering indicators, detection methods, mitigation strategies, and case studies across personas and attack vectors.
OSINT and cyber threat intelligence platform - unified search across multiple data sources for indicators, threat actors, and infrastructure discovery.
Security research blog from RedHunt Labs - attack surface management insights, vulnerability disclosures, and adversary infrastructure tracking write-ups.
Legal reference platform for cybersecurity regulations worldwide - GDPR, CCPA, HIPAA, DPDP, and cross-border data protection frameworks with jurisdictional analysis.
Interactive Sigma rule browser - search, filter, and explore Sigma detection rules with SIEM conversion previews for Splunk, Elastic, QRadar, and more.
APT28 (Fancy Bear) victimology dashboard - tracks known targets, campaigns, and infrastructure attribution for the Russian state-sponsored threat actor.
Free DMARC RUA report analyzer - privacy-first, in-memory XML parsing with IP enrichment, SPF/DKIM/DMARC alignment per sender. See also /dfir/dmarc-analyzer on this site.
Telegram search and analytics platform - search channels, messages, groups, and media across Telegram's public surface. Built for OSINT analysts and threat hunters.
Telegram intelligence and search platform - advanced search across channels, messages, and media. Designed for OSINT researchers, investigators, and threat analysts.
Telegram analytics and statistics platform - channel rankings, subscriber growth, engagement metrics, and content search across millions of public Telegram channels.
Telegram database and directory - browse and search public Telegram channels, groups, and bots. Categorized index for OSINT discovery and channel enumeration.
The largest collection of malware source code, samples, and papers on the internet. Curated corpus spanning decades of malware families, APT tools, and reverse-engineering research.
abuse.ch project - crowdsourced malware sample repository. Upload and download samples, search by hash/tag/family, API access. Integrated into this platform's IOC checker.
Malware sample repository maintained by VirusTotal contributor. 40M+ samples available for download. Free registration required. Password-protected ZIP archives.
Free malware sample repository with REST API. 1000+ daily samples from 30+ sources. Search by hash, file type, or keyword. API key available with free registration. Integrated into this platform's IOC checker.
Open-source live malware repository on GitHub. Curated samples organized by family with encrypted archives. CLI tool for downloading and analysing samples. Educational purpose.
Malware research lab - IOC database, YARA rule repository, retrohunt, and sample analysis. Free tier with API access. Specialises in document-based malware (Office, PDF, LNK).
abuse.ch IOC sharing platform - community-submitted IOCs (IPs, domains, URLs, hashes) mapped to malware families. Searchable database with API. Integrated into this platform's live IOCs feed.
abuse.ch URL tracking - community-submitted malicious URLs serving malware payloads. Searchable database with API and downloadable blocklists. Integrated into this platform's live IOCs feed.
Interactive malware sandbox - real-time behavioural analysis with Windows VMs. Free tier with public submissions. Process tree, network captures, MITRE ATT&CK mapping.
The definitive malware and IOC analysis platform. 70+ AV engine scan, behavioural sandbox, YARA search, graph analysis, community comments. Free API with rate limits.
Open Threat Exchange - community-driven threat intelligence. IOC pulses, reputation data, endpoint telemetry. Free API. Integrated into this platform's IOC checker.
Automated C2 infrastructure feeds - IP and domain lists for Cobalt Strike, Sliver, Brute Ratel, and other C2 frameworks. Updated daily via GitHub. Integrated into this platform's live IOCs feed.
Automated phishing intelligence - real-time phishing URL feed. Community feed is free; premium adds targeted brand analysis. Integrated into this platform's live IOCs feed.
Open-source visual intelligence platform for OSINT link analysis and graph-based investigation workflows. Investigate entities, map relationships, and run graph-native transforms. Features username search, domain-to-IP pivoting, email-to-domain extraction, and HTTP header analysis.
Crowd-sourced threat intelligence API. IP reputation, attack categories, behaviors, and community trust scores. Free tier: 1000 lookups/month. Integrated into this platform's IOC checker.
VPN, proxy, and residential IP detection service. Identifies anonymization services and their providers. Free community endpoint available. Integrated into this platform's IP enrichment.
Free, keyless IP intelligence API from Shodan. Returns open ports, CVEs, hostnames, and tags for any IP address. Unlimited lookups. Integrated into this platform's IOC checker.
Phishing URL statistics and reputation data. Score, first/last seen, target brand, hosting country. Free API, no authentication required. Integrated into this platform's IOC checker.
Free threat intelligence feeds on GitHub - malware URLs, phishing URLs, C2 domains, and file hashes. Updated regularly. Integrated into this platform's IOC checker.
Open-source threat intelligence platform for sharing, storing and correlating IOCs. 200+ default feeds from public sources. STIX/TAXII support, feed system, API, and MISP taxii server integration. De facto standard for CTI sharing.
Python framework by CERT Austria for collecting, processing, and correlating threat intelligence feeds. Modular bots (collectors, parsers, experts, outputs). Handles 200+ feed formats at scale.
CSV catalog of 145+ free threat intelligence feeds organized by type (IP, DNS, URL, MD5, SHA256, CVE, JA3) with vendor metadata. Reference directory for discovering new feed sources.
Curated list of YARA rules, tools, and resources - rule repositories, testing frameworks, IDE plugins, and learning materials for YARA-based detection engineering.
Massive collection of detection rules across YARA, SIGMA, KQL, SPL, and EQL formats. Categorised by MITRE ATT&CK technique. Curated from multiple open-source rule repositories.
Per-malware-family IoC directories with YARA rules and indicators. Organized by malware name with IPs, domains, hashes, and rule files for each family.
Curated malware sample collection organized by family. Includes analysis notes, configuration extractors, and references to original sources. Regularly updated with new campaigns.
Curated list of digital forensics resources - forensic tools, analysis frameworks, artifact collections, CTF challenges, and educational materials for DFIR practitioners.
Curated collection of OSINT data collectors - web scraping templates, API wrappers, and data extraction scripts for open-source intelligence gathering across platforms.
Per-country OSINT resource directory - 1,500+ curated tools and data sources across 247 countries. Covers government registries, news, maps, people search, social media, transportation, utilities, and crime data. Powers the interactive country OSINT map on this platform.
Official AWS incident response playbook samples - CloudFormation templates, Lambda functions, and runbooks for automating IR workflows in AWS. Pre-built response actions for common scenarios.
This platform's TAXII 2.1 server for automated threat intelligence sharing. Compatible with MISP, OpenCTI, Splunk SOAR, and other TAXII clients. Collections: IOCs, actors, malware, vulnerabilities, briefings.
French open-source intelligence platform - real-time aggregation across geopolitics, cyber, and military domains. Multi-source dashboard surfacing breaking events with structured metadata for analysts tracking hybrid threats.
OPSEC techniques and procedures reference - tactic → technique → sub-technique → procedure hierarchy modeled after MITRE ATT&CK but scoped to operational-security tradecraft. Useful for blue teams mapping counter-surveillance controls and red teams modelling adversary OPSEC gaps.
Tor hidden-service scanner that probes .onion operators for opsec leaks and misconfiguration that could deanonymize them. Reports on exposed server banners, EXIF in page assets, open ports, Apache mod_status leaks, and other metadata that has historically been used to identify Silk Road-style operators. MIT, Go, s-rah/onionscan.
Lightweight Python CLI for auditing Tor hidden services for clearnet dependencies, metadata leaks, fingerprinting indicators, and basic de-anonymization risks. Modern (2026) alternative to OnionScan, pip-installable.
Android encrypted overlay filesystem using gocryptfs (and CryFS). Mounts volumes as virtual disks without root, keeping data invisible to other apps and media scanners. AGPL-3.0, on F-Droid. Critical for mobile OpSec - encrypted photo capture, internal file viewer, fingerprint unlock, auto-lock on background.
Python Linux MAC changer with random / spoof / anti-fingerprint modes. Bundles log clearing, hostname spoofing, DNS cache flushing, and Bluetooth MAC rotation - all-in-one L2 fingerprint erasure. MIT, requires root. (Small but free and works.)
Go-based anti-censorship proxy that bypasses Deep Packet Inspection without root/admin by modifying the length of the first packets in the TLS handshake, defeating packet-based DPI used by ISPs to censor the web. Apache-2.0, 4.6k, install via Homebrew or single binary from GitHub releases.
Keystroke and mouse anti-fingerprinting tool. Emulates an average typing rhythm by randomizing inter-key intervals + speed, defeating keystroke-biometric identification. Also obfuscates mouse path/timing. BSD-3-Clause, Wayland-native, ships in Whonix / Tails. Original vmonaco/kloak archived; Whonix fork is the active branch.
LD_PRELOAD hook that routes any dynamically-linked program's TCP traffic through a proxy cascade. Fork of the classic proxychains adding IPv6 support, mixed SOCKS4/5 + HTTP/HTTPS chaining, and automatic failover to live nodes. GPL-2.0, available in apt/brew/Arch.
DIY Bitcoin + Lightning full node on a Raspberry Pi with integrated Tor, Electrum server, and physical-key HD wallet isolation. Self-sovereign hardware node with zero cloud dependence. MIT, but the hardware (Pi 4/5 + 1-2 TB SSD + PSU) costs ~$200-400 - software is free, the appliance isn't.
754 structured cybersecurity skills for AI agents across 26 security domains. Mapped to 5 frameworks: MITRE ATT&CK v19.1, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF. Works with Claude Code, Copilot, Codex CLI, Cursor, Gemini CLI, and 20+ platforms. 14,000+ GitHub stars.
Collection of 1,400+ AI agent skills from official dev teams (Anthropic, Google, Vercel, Stripe, Cloudflare, Trail of Bits) and the community. Compatible with Claude Code, Codex, Gemini CLI, Cursor, and agentskills.io standard. 24,000+ GitHub stars.
Curated list of AI security resources - frameworks, standards, red teaming tools, LLM attack techniques, agentic AI security, MCP security, adversarial ML, and AI governance. 1,000+ GitHub stars.
AI-powered OSINT agent with interactive REPL, CLI, MCP server, and Web UI. 16 tools for email, username, breach, WHOIS, IP, subdomain, Shodan, VirusTotal, Censys, and DNS intelligence. Supports Claude, GPT-4, and local Ollama models. Apache 2.0.
Version-controlled CTI methodology with 8 structured training assignments covering reactive, proactive, and full-cycle intelligence. Docker Compose lab stack (OpenCTI, TheHive, Cortex, Elastic SIEM). Evidence-traced analysis with deployable Sigma rule output.
why: Practitioner-grade CTI training that treats investigations like software engineering - version-controlled, template-driven, evidence-traced, and reproducible.
CIA-style real-time geopolitical news monitoring platform - live map visualization, news crawler, facilities database, and Neo4j network graph explorer. MENA region focus with interactive map overlays and dark/light mode.
Geospatial intelligence platform - real-time 3D globe with live data feeds, entity filters, and infrastructure tracking. AI-powered news aggregation, geopolitical monitoring, and infrastructure visualization.
Comprehensive YARA rules and IOC signatures by Florian Roth. 1,000+ rules covering APT groups, malware families, web shells, and exploitation tools. Updated regularly. MIT licensed.
Detection logic mapped to MITRE ATT&CK - Jupyter notebooks with Sigma rules, Splunk queries, and threat-hunting methodologies for each technique. Community-driven, regularly updated.
Ransomware group monitoring - tracks 100+ ransomware operations, scrapes leak sites, and publishes structured JSON of new victim posts. MIT licensed. Integrated into this platform's live IOCs feed.
Open knowledge base of threat actor clusters, malware, ransomware, tools, and ATT&CK matrices. 200+ clusters covering threat actors, backdoors, bankers, exploit kits, ransomware, RATs, and surveillance vendors. CC0-licensed - importable into any threat intelligence platform.
why: Definitive open-source repository of structured threat intelligence clusters - the reference for actor naming, tool tracking, and cross-platform STIX-compatible sharing.
Complete OSINT platform with 4,577+ verified public records sources across all 50 US states, multi-search launcher (80+ platforms), Google dork generator, report composer, bookmarklet library (60+ one-click tools), and investigation notebook. All browser-based, no registration required.
why: The OSINT Grid (4,577 public records sources) is a unique structured dataset. Multi-search launcher and dork generator complement our existing /dfir/google-dorks and /dfir/osint-map tools.
why: Bridges the gap between civilian CTI and military OSINT. The GPS jamming overlay, time-machine replay, and UKMTO maritime incident feed are unique capabilities not found in other open dashboards. Strong complement to our GlobalPulse war-room and aircraft layers.
AWS IAM privilege escalation attack paths and hands-on labs by Datadog Security Labs. Comprehensive library of IAM escalation techniques with exploitation guides, detection coverage maps, and deployable lab scenarios (Stratus Red Team meets IAM Vulnerable).
why: The only open-source resource mapping complete AWS IAM privilege escalation chains with both offensive and defensive coverage. Essential for cloud security assessments and detection engineering.
Open-source Palantir alternative - 3D globe tracking 10,000+ aircraft (ADS-B), 2,000+ satellites, and worldwide CCTV. Built-in browser tools: Nmap, DNS, WHOIS, SSL cert, BGP/ASN lookups, IP reputation. 20+ live feeds (earthquakes, wildfires, nuclear facilities, cyber threats, conflicts, GPS jamming).
why: Unifies the OSINT + CTI + GEOINT experience into a single browser dashboard - closest open-source analogue to commercial intelligence platforms. Strong complement to our GlobalPulse war-room and our aircraft/satellite layers.
Lissy93's curated checklist of 300+ tips for protecting digital security and privacy - 21k+ stars on GitHub. Structured as a YAML knowledge base with categories covering accounts, devices, networks, communications, physical, and OPSEC. CC0-licensed.
why: The de-facto open-source personal security checklist. The structured YAML makes it a natural complement to a local interactive checklist implementation.
Bitwire-it/ipblocklist - 338-star GitHub repo aggregating 30+ IP blocklists (AbuseIPDB, FireHOL, ipsum, ThreatFox, Spamhaus DROP, Binary Defense, SANS, CINSscore) into two curated feeds updated every 2h. inbound.txt (~2M IPs) for WAN-IN drops, outbound.txt (~150K IPs) for LAN-OUT blocks. CC BY-NC-SA 4.0.
why: Best open-source single-source-of-truth for compiled malicious IP feeds. Reflected in /threatintel/bitwire-blocklist (in-platform dashboard), /dfir/blocklists (consolidated pfSense/iptables/Suricata) and /api/v1/feeds/ioc-summary?source=bitwire-inbound|bitwire.
Minimal "what is my IP" service with JSON / plain-text / user-agent / port-aware endpoints. Useful as a sanity check during egress filtering tests, IP-reputation triage, and to confirm whether a VPN / proxy / Tor exit is in use.
Comprehensive browser-fingerprint demo from Gonzosint. Loads ThumbmarkJS, ImprintJS and 8+ other fingerprinting libraries side-by-side so analysts can see what each library leaks: canvas hash, audio context, WebGL renderer, font enumeration, hardware concurrency, etc.
why: Side-by-side comparison of every major fingerprint library is unique - useful for /dfir/privacy-hub follow-up: see exactly what your own browser is leaking and which library would be the most effective adversary tool.
Curated GitBook catalog of OSINT tools maintained by the OSINT Newsletter community. Grouped by category (people search, geolocation, social, infra) with one-page summaries, screenshots, and quick links. A more editorial / human-curated alternative to the OSINT Framework.
Free public URL sandbox - 100 scans/day without auth. Captures screenshot, rendered DOM, network requests, TLS chain, and verdicts for any submitted URL. Used by /api/v1/url-preview and as enrichment in /dfir/phishing.
Free community API classifies IPs as benign / malicious / unknown by tracking internet-wide scanner/mass-exploitation traffic. Tag-based filter lets analysts separate targeted from opportunistic noise. Strong complement to AbuseIPDB.
Open search engine for exposed services and leaked credentials. Free public API. Used by /api/v1/breach/leakix to surface internet-exposed hosts with CVE / version context.
Internet-wide device / service / banner search engine. Free tier exposes the most popular queries. Used in the platform's enrichment providers for service fingerprinting and CVE/CPE lookup.
Open-source APT groups and operations database - tracks 411 groups across 9 regions with aliases, attributed malware, known operations, and country-level mapping. CC BY 4.0 licensed, compiled from public threat intelligence sources.
Threat intelligence and cybercrime news blog - deep-dive investigations into organized crime, crypto heists, infostealers, piracy takedowns, and underground markets. Ghost-powered, CC BY 4.0.
Operational cyber defense platform with 20+ live tools across 7 domains: Threat Exchange (VERDIKT, X-VERDIKT, PARSE-X, DNSCOPE, MAILSCOPE), AI-powered runbooks (INSIGHT-AI, QUERYCRAFT-AI, FPLENS-AI, ATTMAP-AI, CHRONO-AI, MALBRIEF-AI, PROMPTVAULT, VERDIKT-AI), Detection Engineering (TRACERULES), Threat Hunting (HYPOS, PIVEX, TRACEPULSE), SOC Ops (QUICKTRACE, PHISHOPS, SHIFTLOG), Digital Forensics (REGSCOPE, MALBRIEF-AI), and IR (PHISHBOOK).
why: Comprehensive platform with tools across the full kill chain. Several tools are directly integrated into this platform (FPLENS, QUERYCRAFT, CHRONO, MALBRIEF, VERDIKT, PHISHOPS, PIVEX, TRACEPULSE, QUICKTRACE, PHISHBOOK).
Interactive MITRE ATT&CK navigation dashboard - browse techniques, sub-techniques, and mitigations across all ATT&CK domains (Enterprise, Mobile, ICS) with a clean card-based UI. Useful for rapid technique lookup and kill-chain mapping during threat-intel analysis.
Detection engineering and SOC automation cookbook by mr-r3b00t. Collection of Sigma rules, YARA signatures, Splunk / KQL searches, and incident-response runbooks. Practical recipes for detection engineers building out their SIEM content library.
IBM threat-intel sharing platform (threat reports, collections). Reaching end-of-life in 2026 with paid-tier-only API — kept as a research archive reference, not a live feed. Migrate X-Force workflows to OTX / ThreatFox / Malpedia.
Verified onion-service directory, unmaintained since 2022. Kept as a historical reference only — use dark.fail for uptime/phishing verification, Ahmia for hidden-service search, and OnionWatch for live monitoring.
Lightweight self-hosted TIP for IoC/TTP storage (Yeti). No SaaS API to integrate — run your own instance alongside MISP/OpenCTI; export via its API into StixBuilder for correlation here.
Onion search engine with a safety-rated directory (Verified / Unrated / Suspicious / Dangerous), ransomware-activity and Telegram monitoring, marketplace trends, and free checkers for fake shops, scam messages, phishing mail and crypto sanctions addresses. Operated by NexVision Lab.
why: No public API — API access sits behind a paid Pro tier, and the free crawl is Tor-only, which Workers cannot reach (the same constraint that makes OnionWatch reachability probes unavailable here). Its directory and ransomware-victim content would also duplicate the darknetlist and breach-watch verticals already running. robots.txt additionally disallows /previews/ and /api/preview/.
Ranks CVEs by attention and momentum rather than CVSS — mention volume and trend across researchers, advisories, exploit references and community discussion, with vendor/product (CPE) scoping and exploitation / PoC / patch indicators.
why: Redundant with the CISA KEV + NVD pipeline already synced into public/data/threat-intel. Its headline ranked CVEs (e.g. CVE-2026-87902, CVE-2025-39682, CVE-2026-85046, CVE-2026-88771, CVE-2026-85706) are all already present in the local KEV feed, and the underlying data is "AI-classified social media analysis" of the same advisory sources. Its robots.txt also carries explicit content-signal licensing conditions.
Independent search engine prioritising non-commercial and long-tail web content — useful for finding overlooked blogs, personal research pages and legacy sites that commercial engines bury. Open source (AGPL), no AI in the ranking, and its crawler and index software are public.
why: robots.txt disallows /search, /explore, /site, /links and /wiki — effectively the whole product surface — and there is no public API without a key, so there is no compliant way to replicate results. Worth using manually for OSINT; not integrable here.
Threat-intelligence and cyber-risk monitoring dashboard (client-side SPA, purple-branded) surfaced during a source-evaluation sweep on 2026-09-30.
why: No reachable data surface: the app is a JavaScript SPA whose page body renders empty without a browser, it returns an HTML page rather than a robots.txt at /robots.txt (so no published crawl policy), and no API or licence is advertised. Nothing can be replicated or verified programmatically.
Demonstrates the Unicode tag-character vector: mapping each ASCII character to U+E0000+codePoint produces text that renders blank to a human but decodes back to the original instruction for any model or tokenizer reading it. Survives copy-paste through most editors, terminals and chat clients.
why: Not replicated as data — the technique is a published Unicode mechanism, so it is implemented locally instead. See src/lib/invisible-prompt.ts: decode/strip/scan for the U+E0000 block, zero-width characters and bidi overrides, with detection wired into the Web Server Log Analyzer. Use the live tool to confirm behaviour; use ours to defend.