CIRCL OSINT Feed
CIRCL's public MISP feed of indicators from open-source reporting, ready to subscribe to from a MISP instance.
Curated sources of indicators of compromise, detection signatures and IOC tools.
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
CIRCL's public MISP feed of indicators from open-source reporting, ready to subscribe to from a MISP instance.
IOCs from Cisco Talos.
Vendor-operated REST API that puts active IOCs from public feeds (AlienVault OTX, Abuse.ch URLhaus, ThreatFox, CISA KEV, Tor exit nodes, OpenPhish) behind one query interface; free tier requires an API key.
IOCs from DomainTools for malware and scams.
IOCs from DomainTools for nation-state threats.
Vendor-operated database of malicious browser extensions and packages across 12 ecosystems (Chrome, Firefox, VS Code, npm, PyPI, WordPress and others), aggregated from OSV, OpenSSF and vendor feeds, for checking software supply-chain exposure; free web lookup and JSON endpoint.
YARA rules and IOCs behind the LOKI and THOR Lite scanners, curated for a low false-positive rate and updated frequently.
IOCs and supporting data for Palo Alto Networks Unit 42 threat research articles, so indicators can be traced back to their write-up.
Vendor-operated feed of indicators extracted from clustered public reporting, available as TXT, CSV and JSON.
Free daily blocklists of malicious IPs, domains, URLs and file hashes, plus a C2 hunt feed of command-and-control servers with beacon configs; included in MISP's default feed list.
Index of public reports on APT campaigns sorted by year, useful for tracing indicators back to the original vendor reporting.
Network indicators from reports on the targeting of civil society, published as CSV, JSON and generated Snort rules.
Indicators from Citizen Lab investigations into targeted attacks on civil society, one directory per report.
Fingerprints of infostealer log formats (banner strings, field signatures, YARA rules) for 30+ families including RedLine, Vidar, Lumma and StealC, for identifying which stealer produced a leaked log.
Indicators from ESET research publications, one directory per report and actively updated.
IOCs, CSV context and YARA rules from HvS-Consulting incident response work, organized by threat actor or campaign for threat hunting.
APT indicators that carry the actor they belong to, its MITRE ATT&CK group ID, when they first appeared and the report that published them.
IOCs from Volexity public threat research blog posts, organized by year and post.
Free Proofpoint Emerging Threats ruleset for Snort and Suricata, a common baseline for network intrusion detection.
Official Snort rule sets, many of which also work with Suricata.
YARA rules from InQuest research, intended for hunting rather than production detection; many are referenced from the InQuest blog.
Community-compiled YARA ruleset classified by threat type, a broad starting point for hunting.
YARA rules that accompany Trellix Advanced Threat Research (formerly McAfee ATR) blog posts and investigations.
YARA rules and EQL behavior rules used by Elastic Security for endpoint, with coverage mapped to MITRE ATT&CK.
YARA rules from Intezer malware research.
Detection-focused YARA rules from ReversingLabs threat analysts, written with the stated aim of zero false positives.
YARA signatures for identifying packers, compilers and crypto constants, useful during reverse engineering.
Generates YARA rules from malware samples while filtering out strings common in goodware.
Browser extension that looks up a selected IOC across many OSINT and scanning services from the context menu.
Extendable framework that extracts and aggregates IOCs from threat feeds and passes them to other tools.
Extracts IOCs from text, including defanged URLs, IP addresses and hashes.
Specifications for the MISP core format and related formats, used to exchange indicators between MISP and other platforms.
Schema for encoding malware behaviors, capabilities and attributes.
A structured language and serialization format for exchanging cyber threat intelligence.
Pattern-matching language and tool for identifying and classifying malware, used by most signature collections in this list.
VoltAgent/awesome-openclaw-skills
The awesome collection of OpenClaw skills. 5,400+ skills filtered and categorized from the official OpenClaw Skills Registry.🦞
awesome-dsh-plugin/awesome-dsh-plugin
A curated list of plugins for DeepSeek Harness (dsh) · DeepSeek Harness 插件精选列表
Kristories/awesome-guidelines
Programming style, best practices, and coding conventions.
sindresorhus/awesome
😎 Awesome lists about all kinds of interesting topics [NOTE: Pull requests are temporarily disabled until I have a chance to catch up with the existing ones]
ai-boost/awesome-prompts
Curated list of chatgpt prompts from the top-rated GPTs in the GPTs Store. Prompt Engineering, prompt attack & prompt protect. Advanced Prompt Engineering papers.
matiassingers/awesome-readme
A curated list of awesome READMEs