threat-intel
6 resources across 3 kinds
Tools
- Open ↗
MIT-licensed MCP server that gives AI agents access to CrowdStrike Falcon — detections, threat intel, hosts, vulnerabilities, NG-SIEM queries — with a read-only mode and tool allow/deny lists; needs Falcon API credentials.
Frameworks & agents
- Open ↗Claude Code RE Toolkitactivehigh-risk
Claude Code skill pack wrapping Ghidra, YARA, CAPA, Frida, FakeNet and an 18-service threat-intel client behind Docker and VMware isolation, for static, dynamic and web-forensic malware analysis on Windows.
- Open ↗Phoenix Security Skillscloud cost
Six Claude Code plugins (27 skills, MIT) for pre-merge security review, STRIDE threat modelling, opengrep/semgrep rule generation, tiered CTI search across 595 curated domains, and security-first PRD writing.
References
- Open ↗chrome-mal-idspassive
A community-maintained database of malicious Chrome/Edge extension indicators of compromise, cataloguing credential stealers, browser hijackers, supply-chain compromises, and ad-fraud campaigns. It publishes in plain-text blocklist, JSON, Sigma, STIX 2.1, and MISP formats with a multi-stage verification protocol.
- Open ↗
Curated list of threat-intelligence resources organized into sources (100+ feeds like AbuseIPDB, GreyNoise, URLhaus), exchange formats (STIX/TAXII/MAEC), frameworks/platforms (MISP, OpenCTI, IntelMQ), analysis tools, and research/standards (MITRE ATT&CK, Diamond Model). ~10.5k stars.