5 tools
Threat intelligence tools collect, enrich and share information about active and emerging cyber threats, from indicators of compromise (IOCs) such as malicious IPs, domains and file hashes to broader context on campaigns, malware and adversary infrastructure. Sources range from open community feeds and public GitHub monitoring to dark web scanners and curated intelligence platforms. Defenders use them to enrich alerts, hunt for threats, block known-bad infrastructure and understand the risks most relevant to their sector.
When choosing a feed, evaluate its freshness, false-positive rate, coverage of your threat model, and whether it delivers structured, machine-readable data you can operationalise. Raw indicators are only useful with context, so favour sources that explain the why behind an IOC. Validate intelligence before enforcing on it to avoid disrupting legitimate traffic. Complement these with threat actor research and explore the wider OSINT directory for adjacent tooling.
Monitor public GitHub repositories in real time. Detect secrets and sensitive information to prevent hackers from using GitHub as a backdoor to your business.
Free and open source tool for investigating the Dark Web. Its main goal is to help researchers and investigators monitor and track Dark Web sites.
Free online service and API for checking the existence of Tor hidden services (.onion address) and retrieving their associated metadata. onion-lookup relies on an private AIL instance to obtain the me
Open Threat Exchange is the neighborhood watch of the global intelligence community. It enables private companies, independent security researchers, and government agencies to openly collaborate and s
REScure is an independent threat intelligence project which we undertook to enhance our understanding of distributed systems, their integration, the nature of threat intelligence and how to efficientl
Threat intelligence is evidence-based knowledge about cyber threats, including indicators of compromise, adversary tactics, malware behaviour and campaign context. It is gathered from open feeds, commercial providers, dark web monitoring and internal telemetry, then analysed to help organisations anticipate, detect and respond to attacks more effectively than relying on generic defences alone.
A threat feed is a raw stream of data, typically indicators like malicious IPs, domains and hashes. Threat intelligence adds analysis and context, explaining who is behind activity, how they operate and why it matters to you. Feeds tell you what to block; intelligence helps you understand and prioritise, turning data into informed decisions.
Free and community feeds are valuable but vary in quality, timeliness and false-positive rates. Some indicators go stale quickly or flag shared infrastructure that also hosts legitimate services. Validate and score indicators before enforcing on them, correlate across multiple sources, and prefer feeds that provide context and confidence levels rather than bare lists of values.
Search all 1,200+ OSINT tools instantly, or run a target through the investigation console.
Open the OSINT directory →