Maltrail is a malicious traffic detection system that utilizes publicly available blacklists, static trails from various AV reports, and custom user-defined lists to detect malicious and suspicious activities such as domain names, URLs, IP addresses, and HTTP User-Agent header values. It also employs advanced heuristic mechanisms for discovering unknown threats.
FEATURES
SIMILAR TOOLS
YARA signature and IOC database for LOKI and THOR Lite scanners with high quality rules and IOCs.
Python APIs for serializing and de-serializing STIX2 JSON content with higher-level APIs for common tasks.
Tool for visualizing correspondences between YARA ruleset and samples
A threat intelligence and vulnerability monitoring platform that aggregates security alerts from trusted sources and provides customizable monitoring and notification capabilities.
Robust Python SDK and Command Line Client for interacting with IntelOwl's API.
A reference implementation for collecting events and performing CAR analytics to detect potential adversary activity.
Darkscope is an AI-powered threat intelligence platform that uses virtual personas to monitor the dark web, social media, and deep web for cyber threats and security risks targeting organizations.
The FASTEST Way to Consume Threat Intelligence and make it actionable.
Powershell Threat Hunting Module for scanning remote endpoints and collecting comprehensive information.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.