The latest iteration of Poortego is a completely new code-base, utilizing neo4j for data traversal and management, with a command interface built on Python cmd2 and py2neo for neo4j REST communication. It is designed for cyber threat indicators but can be used for other data points as well. The roadmap includes additional argument support for commands, transforms for data interaction, scheduled transforms, document retrieval, and raw document/file storage.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
InSights by InQuest is a threat intelligence platform that delivers curated feeds of IOCs and C2 information to help security teams detect and respond to emerging threats.
HoneyDB is a honeypot-based threat intelligence platform that provides real-time insights into attacker behavior and malicious activity on networks.
The Cybersecurity and Infrastructure Security Agency (CISA) is a government agency that provides alerts, advisories, and resources to help protect the United States' critical infrastructure from cyber threats.
Cortex is a tool for analyzing observables at scale and automating threat intelligence, digital forensics, and incident response.
A visualization tool for threat analysis that organizes APT campaign information and visualizes relations of IOC.
Converts OpenIOC v1.0 XML files into STIX Indicators, generating STIX v1.2 and CybOX v2.1 content.
A minimalistic Java library for representing threat model data in a normalized way and automating threat intelligence extraction.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.