Signature-Base is the YARA signature and IOC database for our scanners LOKI and THOR Lite. It provides high quality YARA rules and IOCs with minimal false positives, clear structure, consistent rule format, and external variables in YARA rules. The database includes directories for IOC files, YARA rules, threat intelligence API receiver, and other input files.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Provides breach and attack simulation products for security control validation, offering three different products to meet the needs of organizations of various sizes and maturity levels.
IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol, with a focus on incident handling automation and threat intelligence processing.
Aggregator of FireHOL IP lists with HTTP-based API service and Python client package.
Dataplane.org is a nonprofit organization providing free data, tools, and analysis to increase awareness of Internet trends, anomalies, threats, and misconfigurations.
Home for rules used by Elastic Security with code for unit testing, Kibana integration, and Red Team Automation.
Intelligence feeds for cybersecurity professionals to stay informed about emerging threats and trends.
A modular malware collection and processing framework with support for various threat intelligence feeds.
Python APIs for serializing and de-serializing STIX2 JSON content with higher-level APIs for common tasks.
A system for collecting, managing, and distributing security information on a large scale, developed by CERT Polska.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.