Category 09 · 39 resources

Threat Intelligence / Malware / Phishing / Sandbox

Threat-intelligence platforms and malware sandboxes. Check whether an IP, domain, file or URL is malicious, and detonate suspicious samples safely in the cloud.

alienvault Web

https://otx.alienvault.com/

AlienVault OTX community intel

How to use it

Search IPs, domains, hashes for community 'pulses' of related indicators; free account unlocks API.

Open resource →

pulsedive Web

https://pulsedive.com/

Threat-intel aggregation

How to use it

Look up IOCs and pivot across linked indicators; free tier with API.

Open resource →

threatminer Web

https://www.threatminer.org/

Threat-intel data mining

How to use it

Search domains, IPs, hashes, SSL certs and pivot through related indicators.

Open resource →

abuseipdb Web

https://www.abuseipdb.com/

IP abuse reports

How to use it

Check if an IP is reported for brute-force/spam, and report abusive IPs you observe.

Open resource →

talosintelligence Web

https://talosintelligence.com/

Cisco Talos reputation center

How to use it

Look up IP/domain reputation and read Talos threat research.

Open resource →

abuse Web

https://abuse.ch/

Abuse.ch platforms hub

How to use it

Gateway to ThreatFox (IOCs), URLhaus (malware URLs), MalwareBazaar (samples) and more — all free, no signup.

Open resource →

abuse Web

https://threatfox.abuse.ch/

Abuse.ch platforms hub

How to use it

Gateway to ThreatFox (IOCs), URLhaus (malware URLs), MalwareBazaar (samples) and more — all free, no signup.

Open resource →

abuse Web

https://urlhaus.abuse.ch/

Abuse.ch platforms hub

How to use it

Gateway to ThreatFox (IOCs), URLhaus (malware URLs), MalwareBazaar (samples) and more — all free, no signup.

Open resource →

abuse Web

https://bazaar.abuse.ch/

Abuse.ch platforms hub

How to use it

Gateway to ThreatFox (IOCs), URLhaus (malware URLs), MalwareBazaar (samples) and more — all free, no signup.

Open resource →

abuse Web

https://feodotracker.abuse.ch/

Abuse.ch platforms hub

How to use it

Gateway to ThreatFox (IOCs), URLhaus (malware URLs), MalwareBazaar (samples) and more — all free, no signup.

Open resource →

abuse Web

https://sslbl.abuse.ch/

Abuse.ch platforms hub

How to use it

Gateway to ThreatFox (IOCs), URLhaus (malware URLs), MalwareBazaar (samples) and more — all free, no signup.

Open resource →

misp-project Web

https://www.misp-project.org/

MISP threat-sharing platform

How to use it

Self-host a MISP instance to store, correlate and share IOCs with communities via feeds.

Open resource →

MISP GitHub

https://github.com/MISP/MISP/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

opencti GitHub

https://github.com/opencti-platform/opencti/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

IntelOwl GitHub

https://github.com/intelowlproject/IntelOwl/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

github Web

https://intelowlproject.github.io/

IntelOwl docs

How to use it

Deploy the IntelOwl Docker stack to run dozens of analyzers (VT, AbuseIPDB...) on files and observables from one API.

Open resource →

assemblyline GitHub

https://github.com/CybercentreCanada/assemblyline/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

virustotal Web

https://www.virustotal.com/gui/home/search/

Multi-engine malware scanner

How to use it

Upload a file or paste a URL/hash to get verdicts from 70+ antivirus engines plus behavior reports. Don't upload confidential files — uploads are shared.

Open resource →

virustotal Web

https://www.virustotal.com/gui/home/upload/

Multi-engine malware scanner

How to use it

Upload a file or paste a URL/hash to get verdicts from 70+ antivirus engines plus behavior reports. Don't upload confidential files — uploads are shared.

Open resource →

hybrid-analysis Web

https://www.hybrid-analysis.com/

Free malware sandbox

How to use it

Upload a suspicious file or URL to get a full behavior report: network traffic, dropped files, screenshots.

Open resource →

tria Web

https://tria.ge/

Interactive malware sandbox

How to use it

Submit samples and interact with the live VM during analysis; detailed behavior reports with a free account.

Open resource →

joesandbox Web

https://www.joesandbox.com/

Deep malware analysis sandbox

How to use it

Upload samples for deep behavior analysis with detailed reports; free community tier.

Open resource →

any Web

https://any.run/

Interactive cloud sandbox

How to use it

Detonate a file or link in a live Windows VM you can click through in the browser — great for phishing triage.

Open resource →

CAPEv2 GitHub

https://github.com/kevoreilly/CAPEv2/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

openphish Web

https://openphish.com/

Phishing feed

How to use it

Use the free community feed of detected phishing URLs for blocklists and verification.

Open resource →

phishtank Web

https://www.phishtank.com/

Community phishing database

How to use it

Verify and report phishing URLs; free API for checking links.

Open resource →

urlvoid Web

https://www.urlvoid.com/

URL reputation checker

How to use it

Check a domain against 30+ blocklist engines plus WHOIS/DNS info.

Open resource →

sucuri Web

https://sitecheck.sucuri.net/

Website malware scanner

How to use it

Scan a site for malware, blacklisting and outdated software.

Open resource →

capa GitHub

https://github.com/mandiant/capa/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

stringsifter GitHub

https://github.com/mandiant/stringsifter/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

rules GitHub

https://github.com/Yara-Rules/rules/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

github Web

https://virustotal.github.io/yara/

YARA documentation

How to use it

Learn YARA rule syntax to classify malware by pattern; test rules against samples locally.

Open resource →

yara GitHub

https://github.com/VirusTotal/yara/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

yeti GitHub

https://github.com/yeti-platform/yeti/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

yeti-platform Web

https://yeti-platform.io/

yeti-platform — Threat Intelligence resource

How to use it

Open the site, use its search or query interface with the identifier you have (name, number, domain or keyword depending on the tool), then export or record the results for your research notes.

Open resource →

thehive-project Web

https://thehive-project.org/

TheHive incident-response platform

How to use it

Self-host TheHive + Cortex to manage alerts, cases and automated analyzers as a SOC team.

Open resource →

TheHive GitHub

https://github.com/TheHive-Project/TheHive/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

Cortex GitHub

https://github.com/TheHive-Project/Cortex/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

awesome-threat-intelligence GitHub

https://github.com/hslatman/awesome-threat-intelligence/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

Frequently asked questions

Do I need to install anything for these 09 tools?

Most entries here are GitHub projects — clone the repository and follow the README's install steps (pip, npm, go or cargo). A Kali Linux VM gives you many of them pre-installed.

Is it legal to use these resources?

Public-record lookups and defensive/research use are generally lawful, but rules vary by country and tool. Only test systems you own or have written authorization to test, respect each site's terms of service, and never use personal data unlawfully.

Where should a beginner start in this category?

Start with the web-based tools at the top of the list — they need no setup. Read each card's “How to use it” panel, run one real query, and only then move to installable tools.