Awesome OSINT Threat Intelligence
- Threat Actor Usernames https://threatactorusernames.com/ - search through 2M+ threat actor username records and discover where they operate online and post.
- defend.network https://defend.network - Free, no-login cyber threat intelligence publishing daily threat briefings and weekly vulnerability reports, with every CVE cross-checked against NVD and the CISA KEV catalog. Content is structured by threat type, industry, and severity, with remediation guidance. RSS feed at defend.network/feed.xml.
- DFIR Platform https://platform.dfir-lab.ch - Threat intelligence platform with multi-source IOC enrichment, phishing email analysis, exposure scanning, and domain reputation scoring. Free tier available.
- Dropbase https://dropbase.fun - a fast breach, malware log, and OSINT search workspace with daily credits, map tools, and live community chat.
- GitGuardian - Public GitHub Monitoring https://www.gitguardian.com/monitor-public-github-for-secrets - Monitor public GitHub repositories in real time. Detect secrets and sensitive information to prevent hackers from using GitHub as a backdoor to your business.
- onion-lookup https://onion.ail-project.org/ - Free online service and API for checking the existence of Tor hidden services (.onion address) and retrieving their associated metadata. onion-lookup relies on an private AIL instance to obtain the metadata.
- OnionScan https://github.com/s-rah/onionscan - Free and open source tool for investigating the Dark Web. Its main goal is to help researchers and investigators monitor and track Dark Web sites.
- OTX AlienVault https://otx.alienvault.com/ - Open Threat Exchange is the neighborhood watch of the global intelligence community. It enables private companies, independent security researchers, and government agencies to openly collaborate and share the latest information about emerging threats, attack methods, and malicious actors, promoting greater security across the entire community.
- Pharos AI https://conflicts.app - Real-time open-source intelligence dashboard for conflict tracking with interactive geospatial visualization, multi-source RSS monitoring, and actor dossiers.
- PhishingSecLists https://github.com/spmedia/PhishingSecLists - This list is to be used with web scanning tools (Gobuster, ffuf, Burp Suite, DirBuster). These lists are specifically tailored and designed for fuzzing phishing, crypto scam landing pages, and other malicious sketch af websites. You can gain vaulable intel on successful hits.
- REScure Threat Intel Feed https://rescure.fruxlabs.com/ - REScure is an independent threat intelligence project which we undertook to enhance our understanding of distributed systems, their integration, the nature of threat intelligence and how to efficiently collect, store, consume, distribute it.
- STIX Viewer https://stix-viewer.threatlandscape.io/ - An online free STIX 2.1 viewer / visualizer.
- Taranis AI https://github.com/taranis-ai/taranis-ai - Open-source OSINT platform for collecting, enriching, analyzing, and publishing intelligence from web, RSS, email, and other sources with AI/NLP-assisted workflows.
- Threat Actor Usernames Scrape https://github.com/spmedia/Threat-Actor-Usernames-Scrape - A collection of fresh intel and 450k+ threat actor usernames scraped from various cybercrime sources & forums.
- VoidAccess https://github.com/KatrielMoses/voidaccess - Self-hosted, open-source dark web threat intelligence platform that automates the full OSINT investigation workflow. Supports query refinement, multi-engine Tor search, entity extraction (wallets, CVEs, IPs, actor handles, hashes), relationship graphing, and structured export in STIX 2.1, MISP, Sigma, and CSV. Runs on Docker with free LLMs. MIT licensed.
- Voidly Censorship Index https://voidly.ai/censorship-index - Real-time global internet censorship intelligence aggregating 19.6M live OONI samples and 1.6M historical records across 119+ countries. Provides a citable incident database (5,356 incidents, 16,822 evidence items), an ML-driven shutdown early-warning feed, ISP-level risk scoring, and a public REST/MCP API for blocking, DNS poisoning, and BGP-level outage signals. Data licensed CC BY 4.0.
Sections
Threat Intelligence
open-source intelligence