CRITs is an open source malware and threat repository that provides a unified tool for analysts and security experts engaged in threat defense. It allows for flexible and collaborative analysis of threat data, and can be installed locally or shared among trusted organizations. CRITs provides a platform for the security community to quickly adapt to an ever-changing threat landscape. The platform offers a global developer network, a threat defense think tank, and collaborative defense features, enabling community-driven threat research and analysis. Users can join the community by signing up for mailing lists, joining IRC, or contributing to the project on Github.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A free threat intelligence feed and banlist feed of known malicious IP addresses for public use only.
A sophisticated npm attack attributed to North Korean threat actors, targeting technology firms and their employees.
A minimalistic Java library for representing threat model data in a normalized way and automating threat intelligence extraction.
RiskAnalytics Solutions offers community projects for cyber threat intelligence sharing and collaboration.
Hippocampe is a threat feed aggregator with configurable confidence levels and a Hipposcore for determining maliciousness.
PolySwarm is a malware intelligence marketplace that aggregates threat detection engines to provide early detection, unique samples, and higher accuracy.
Globally-accessible knowledge base of adversary tactics and techniques for cybersecurity.
Check the reputation of an IP address to identify potential threats.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.