alienvault Web
AlienVault OTX community intel
How to use it
Search IPs, domains, hashes for community 'pulses' of related indicators; free account unlocks API.
Threat-intelligence platforms and malware sandboxes. Check whether an IP, domain, file or URL is malicious, and detonate suspicious samples safely in the cloud.
AlienVault OTX community intel
Search IPs, domains, hashes for community 'pulses' of related indicators; free account unlocks API.
Threat-intel aggregation
Look up IOCs and pivot across linked indicators; free tier with API.
Threat-intel data mining
Search domains, IPs, hashes, SSL certs and pivot through related indicators.
IP abuse reports
Check if an IP is reported for brute-force/spam, and report abusive IPs you observe.
Cisco Talos reputation center
Look up IP/domain reputation and read Talos threat research.
Abuse.ch platforms hub
Gateway to ThreatFox (IOCs), URLhaus (malware URLs), MalwareBazaar (samples) and more — all free, no signup.
Abuse.ch platforms hub
Gateway to ThreatFox (IOCs), URLhaus (malware URLs), MalwareBazaar (samples) and more — all free, no signup.
Abuse.ch platforms hub
Gateway to ThreatFox (IOCs), URLhaus (malware URLs), MalwareBazaar (samples) and more — all free, no signup.
Abuse.ch platforms hub
Gateway to ThreatFox (IOCs), URLhaus (malware URLs), MalwareBazaar (samples) and more — all free, no signup.
Abuse.ch platforms hub
Gateway to ThreatFox (IOCs), URLhaus (malware URLs), MalwareBazaar (samples) and more — all free, no signup.
Abuse.ch platforms hub
Gateway to ThreatFox (IOCs), URLhaus (malware URLs), MalwareBazaar (samples) and more — all free, no signup.
MISP threat-sharing platform
Self-host a MISP instance to store, correlate and share IOCs with communities via feeds.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
IntelOwl docs
Deploy the IntelOwl Docker stack to run dozens of analyzers (VT, AbuseIPDB...) on files and observables from one API.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Multi-engine malware scanner
Upload a file or paste a URL/hash to get verdicts from 70+ antivirus engines plus behavior reports. Don't upload confidential files — uploads are shared.
Multi-engine malware scanner
Upload a file or paste a URL/hash to get verdicts from 70+ antivirus engines plus behavior reports. Don't upload confidential files — uploads are shared.
Free malware sandbox
Upload a suspicious file or URL to get a full behavior report: network traffic, dropped files, screenshots.
Interactive malware sandbox
Submit samples and interact with the live VM during analysis; detailed behavior reports with a free account.
Deep malware analysis sandbox
Upload samples for deep behavior analysis with detailed reports; free community tier.
Interactive cloud sandbox
Detonate a file or link in a live Windows VM you can click through in the browser — great for phishing triage.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Phishing feed
Use the free community feed of detected phishing URLs for blocklists and verification.
Community phishing database
Verify and report phishing URLs; free API for checking links.
URL reputation checker
Check a domain against 30+ blocklist engines plus WHOIS/DNS info.
Website malware scanner
Scan a site for malware, blacklisting and outdated software.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
YARA documentation
Learn YARA rule syntax to classify malware by pattern; test rules against samples locally.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
yeti-platform — Threat Intelligence resource
Open the site, use its search or query interface with the identifier you have (name, number, domain or keyword depending on the tool), then export or record the results for your research notes.
TheHive incident-response platform
Self-host TheHive + Cortex to manage alerts, cases and automated analyzers as a SOC team.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Most entries here are GitHub projects — clone the repository and follow the README's install steps (pip, npm, go or cargo). A Kali Linux VM gives you many of them pre-installed.
Public-record lookups and defensive/research use are generally lawful, but rules vary by country and tool. Only test systems you own or have written authorization to test, respect each site's terms of service, and never use personal data unlawfully.
Start with the web-based tools at the top of the list — they need no setup. Read each card's “How to use it” panel, run one real query, and only then move to installable tools.