Intel Owl Logo

Intel Owl

0
Free
Visit Website

IntelOwl is an Open Source solution for management of Threat Intelligence at scale. It integrates a number of analyzers available online and a lot of cutting-edge malware analysis tools. Features: * Enrichment of Threat Intel for files as well as observables (IP, Domain, URL, hash, etc). * A Fully-fledged REST APIs written in Django and Python. * An easy way to be integrated in your stack of security tools to automate common jobs usually performed, for instance, by SOC analysts manually. * (Thanks to the official libraries pyintelowl and go-intelowl) * A built-in GUI: provides features such as dashboard, visualizations of analysis data, easy to use forms for requesting new analysis, etc. * A framework composed of modular components called Plugins: analyzers that can be run to either retrieve data from external sources (like VirusTotal or AbuseIPDB) or to generate intel from scratch.

FEATURES

ALTERNATIVES

Python-based client for IBM XForce Exchange with an improved version available.

A threat intelligence platform that monitors, analyzes, and provides detailed information about threat actors targeting non-human identities across various industries.

In-depth threat intelligence reports and services providing insights into real-world intrusions, malware analysis, and threat briefs.

Sigma is a generic and open signature format for SIEM systems and other security tools to detect and respond to threats.

A Python library for interacting with TAXII servers

A curated collection of Sigma & Yara rules and Indicators of Compromise (IOCs) for threat detection and malware identification.

Proof-of-concept implementation of TAXII services for developers and non-developers.

AbuseIPDB offers tools and APIs to report and check abusive IPs, enhancing network security.