Threat & Malware Intelligence
- ThreatFox: Malware IOCs including IPs, domains, and file hashes
- URLhaus: Database of verified malicious URLs
- MalwareBazaar: Malware samples and hash intelligence
- AlienVault OTX: Community-driven threat pulses and indicators
- SSL Blacklist: Malicious SSL certificate tracking
- Spamhaus DROP List: High-risk IPs and domains linked to spam and abuse
Detection & Correlation Intelligence
- Sigma Rules: Detection logic for log analysis and SIEM correlation
- YARA Rules: Pattern matching for file and memory scanning
- MISP Taxonomies & Galaxies: Structured threat classification and context
- MITRE ATT&CK (TAXII/STIX): Adversary tactics, techniques, and procedures
Vulnerability Intelligence
- MITRE CWE: Standardized vulnerability taxonomy and weakness catalog
- CISA KEV: Known Exploited Vulnerabilities actively used in the wild
- NVD/CVE: Comprehensive vulnerability database with severity ratings
Security Standards & Frameworks
- OWASP: Web application security standards and guidelines
- NIST: Cybersecurity frameworks and security publications
- CIS Benchmarks: Configuration hardening guidelines
