Malstrom is a Cyber Intelligence Management Platform that serves as a repository for threat tracking, forensic artifacts, YARA rules, and investigation notes. It includes features like a dashboard, malware sample management, malware file details, threat tag cloud, and IOC extraction and storage. To install, clone the repository, input your VirusTotal API key, run bundle install, set up the database configuration, migrate the database, precompile assets, and start the server.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
An Open Source solution for management of Threat Intelligence at scale, integrating multiple analyzers and malware analysis tools.
Maldatabase is a threat intelligence platform providing malware datasets and threat intelligence feeds for malware data science and threat intelligence.
A sophisticated npm attack attributed to North Korean threat actors, targeting technology firms and their employees.
Repository with projects for photo and video hashing, content moderation, and signal exchange.
A collection of APT and cybercriminals campaigns with various resources and references.
CAPEC™ is a comprehensive dictionary of known attack patterns used by adversaries to exploit weaknesses in cyber-enabled capabilities.
A collection of YARA rules for research and hunting purposes.
A reference implementation for collecting events and performing CAR analytics to detect potential adversary activity.
A tiered cyber threat intelligence service providing detection rules from public repositories with varying levels of analysis, processing, and guidance for security teams.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.