Threat Intelligence
A curated, offline-documented collection of threat intelligence resources for SOC analysts and researchers: IOC feeds and platforms like VirusTotal and AlienVault OTX, malware sandboxes for detonating suspicious samples, OSINT and recon tools, malware sample repositories, and detection frameworks including MITRE ATT&CK and Sigma. A searchable APT group reference table covers major threat actors with known aliases, targets, and attributed activity. Every entry explains what the source is for and who it's useful to, so you can build out a threat intel workflow without hunting down each tool's documentation separately. Source links open externally only when you're online and choose to click them.
IOC Feeds & Threat Platforms
Real-time and historical feeds of malicious IPs, domains, hashes, and URLs
Sandboxes & Malware Analysis
Dynamic and static analysis platforms for suspicious files and URLs
OSINT & Recon Tools
Open-source intelligence gathering and internet-wide scanning databases
Malware Repositories & Hunting
Sample repositories, YARA rule sets, and malware family trackers
Frameworks & Knowledge Bases
TTP databases, attack frameworks, and defensive knowledge bases
APT Group Reference
Major Advanced Persistent Threat groups with origin, aliases, and known targets