Extract and aggregate threat intelligence.
-
Updated
May 26, 2026 - Python
Extract and aggregate threat intelligence.
10-20x more blocks for your CrowdSec bouncers — 120k+ IPs from 32 free threat feeds
本项目致力于收集网上公开来源的威胁情报,主要关注信誉类威胁情报(如IP/域名等),以及事件类威胁情报。
Threat feeds designed to extract adversarial TTPs and IOCs, using: ✨AI✨
AI-Powered Security Feed in Real Time
Scripts for importing threat feeds and CTI articles, blogs, and reports into MISP.
Threat-feed IP block automation for Linux and macOS firewalls (iptables, nftables, pf) with cron-ready updates, dry-run previews, and package releases.
Automated IPv4 threat intelligence: combined blacklist from 100+ feeds with confidence scoring. Updated every 3h.
Automated threat intelligence collector built with Python and GitHub Actions — fetches recent IOCs from open sources, normalizes and enriches them (IP, URL, hash, CVE), and publishes ready-to-use feeds in CSV, JSON, and STIX formats.
🦅 Use fingerprinting to actively hunt for Command and Control servers on Shodan. Process threat feeds from Abuse.ch services to create a local database of C2 servers.
Scrapes a list of Payload Domains, IOC's & C2 IPs from from various feeds for easy blacklisting.
Easily manage blocking any external threat across all your FortiGate firewalls within a minute.
Automatically created C2 Feeds for Fortigate
Your daily summary of tracked changes for Webamon campaigns and emerging clusters seen across the web.
Automated phishing threat intelligence feed with URLs, IPs, domains, and IOC data.
Automated CVE ingestion, enrichment, and prioritization pipeline with real-time threat feeds | Built by Kirov Dynamics Team
Deterministic, category-split threat-intelligence IP feeds (botnet C2, proxies, Tor, scanners, brute force) for OpenShield-XDP and any XDP/firewall consumer. Auto-rebuilt every 3 hours.
Automated Human-in-the-Loop Threat Intelligence Pipeline leveraging LLMs for security data classification across 27 domains with built-in data poisoning mitigation.
On-prem threat intelligence aggregator: normalize, dedupe, and score threat feeds into confidence tiers served as URLs your firewall polls.
A lightweight Cyber Threat Intelligence (CTI) platform that aggregates open-source threat feeds, stores them in SQLite, analyzes Indicators of Compromise (IOCs), and presents actionable threat intelligence through a Flask web dashboard.
To associate your repository with the threat-feeds topic, visit your repo's landing page and select "manage topics."