ThreatMiner is a threat intelligence portal designed to enable analysts to research under a single interface. It aggregates data from various open source feeds and provides contextual information related to indicators of compromise (IOCs). The portal allows analysts to research, pivot, and enrich data, and also provides links to external resources for additional information. ThreatMiner relies on various open source tools and data feeds, including IOCParser, APTNotes, CIRCL, VirusTotal, Malwr.com, Hybrid-Analysis, Alienvault OTX, ipinfo, Robtex, CleanMX, VirusShare, and Sinica. It also performs native DNS enrichment via native applications. The portal aims to free analysts from data collection and provide a single interface for carrying out tasks, from reading reports to pivoting and data enrichment.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A threat intelligence and vulnerability monitoring platform that aggregates security alerts from trusted sources and provides customizable monitoring and notification capabilities.
ProcFilter is a process filtering system for Windows with built-in YARA integration, designed for malware analysts to create YARA signatures for Windows environments.
A comprehensive Continuous Threat Exposure Management platform that combines AI-driven vulnerability assessment, penetration testing, and attack surface management to help organizations discover, prioritize, and remediate security vulnerabilities.
A simple, self-contained modular host-based IOC scanner for incident responders.
Knowledge base workflow management dashboard for YARA rules and C2 artifacts.
CRITs is an open source malware and threat repository for collaborative threat defense and analysis.
Open Source Threat Intelligence Collector with plugin-oriented framework.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.