All resources
Topic

threat-intel

6 resources across 3 kinds

Tools

  1. MIT-licensed MCP server that gives AI agents access to CrowdStrike Falcon — detections, threat intel, hosts, vulnerabilities, NG-SIEM queries — with a read-only mode and tool allow/deny lists; needs Falcon API credentials.

    Open ↗

Frameworks & agents

  1. Claude Code RE Toolkitactivehigh-risk

    Claude Code skill pack wrapping Ghidra, YARA, CAPA, Frida, FakeNet and an 18-service threat-intel client behind Docker and VMware isolation, for static, dynamic and web-forensic malware analysis on Windows.

    Open ↗
  2. Six Claude Code plugins (27 skills, MIT) for pre-merge security review, STRIDE threat modelling, opengrep/semgrep rule generation, tiered CTI search across 595 curated domains, and security-first PRD writing.

    Open ↗

References

  1. A community-maintained database of malicious Chrome/Edge extension indicators of compromise, cataloguing credential stealers, browser hijackers, supply-chain compromises, and ad-fraud campaigns. It publishes in plain-text blocklist, JSON, Sigma, STIX 2.1, and MISP formats with a multi-stage verification protocol.

    Open ↗
  2. Curated list of threat-intelligence resources organized into sources (100+ feeds like AbuseIPDB, GreyNoise, URLhaus), exchange formats (STIX/TAXII/MAEC), frameworks/platforms (MISP, OpenCTI, IntelMQ), analysis tools, and research/standards (MITRE ATT&CK, Diamond Model). ~10.5k stars.

    Open ↗
  3. LOLC2dual-usehigh-risk

    A curated catalogue of command-and-control (C2) frameworks that abuse legitimate services (cloud APIs, messaging platforms) to evade detection, tracking abused services, open-source C2 projects, and associated detection rules with network/file/behavioral IOCs.

    Open ↗