Cortex is an open source and free software created by TheHive Project to help SOCs, CSIRTs, and security researchers analyze observables such as IP addresses, email addresses, URLs, domain names, files, or hashes at scale through a Web interface. It allows for both manual and bulk analysis, automation via the Cortex REST API, and easy creation of custom analyzers.
FEATURES
SIMILAR TOOLS
IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol, with a focus on incident handling automation and threat intelligence processing.
A nonprofit security organization that collects and shares threat data to make the Internet more secure.
A database of Tor exit nodes with their corresponding IP addresses and timestamps.
GCTI's open-source detection signatures for malware and threat detection
A daily collection of IOCs from various sources, including articles and tweets.
Threat hunting tool leveraging Windows events for identifying outliers and suspicious behavior.
Tool for dataviz and statistical analysis of threat intelligence feeds, presented in cybersecurity conferences for measuring IQ of threat intelligence feeds.
A threat intelligence dissemination layer for open-source security tools with STIX-2 support and plugin-based architecture.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.