Rapid7 Threat Command is a digital risk protection platform that monitors external threats across clear, deep, and dark web environments. The platform tracks organizational digital footprints across multiple online channels including social media platforms, code repositories, file-sharing sites, and underground forums. It automatically correlates threat actor intelligence with specific organizational assets to identify potential attack vectors and vulnerabilities. The monitoring capabilities include detection of phishing campaigns, brand impersonation attempts, credential leaks, data breaches, malicious mobile applications, and other external threats. Dynamic asset mapping functionality tracks evolving digital footprints and identifies new potential attack surfaces. Threat Command includes dedicated remediation services with expert teams that handle takedown requests for malicious campaigns, phishing websites, and impersonating applications. The service manages the complete takedown process including prerequisite gathering, legal coordination, and workflow management. The platform provides contextualized alerts with threat prioritization capabilities to enable rapid response and investigation. It includes IOC management and enrichment features, along with integration options for existing security workflows and SIEM platforms. Expert threat detection teams with experience in threat actor communities provide additional intelligence and support. The platform maintains a threat library and offers automation capabilities for monitoring and response operations.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A project sharing malicious URLs used for malware distribution to help protect networks.
A free software that calculates the security ranking of Internet Service Providers to detect malicious activities.
A tracker that detects and logs SYN packets with a specific signature generated by the Mirai malware, providing real-time information on Mirai-based campaigns.
A platform providing real-time threat intelligence streams and reports on internet-exposed assets to help organizations monitor and secure their attack surface.
ThreatMiner is a threat intelligence portal that aggregates data from various sources and provides contextual information related to indicators of compromise (IOCs).
An all-in-one email outreach platform for finding and connecting with professionals, with features for lead discovery, email verification, and cold email campaigns.
The Trystero Project is a threat intelligence platform that measures email security efficacy and provides various tools and resources, while VMware Carbon Black offers endpoint protection and workload security solutions.
A project that detects malicious SSL connections by identifying and blacklisting SSL certificates used by botnet C&C servers and identifying JA3 fingerprints to detect and block malware botnet C&C communication.
VirusTotal API v3 is a threat intelligence platform for scanning files, URLs, and IP addresses, and retrieving reports on threat reputation and context.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.