Huntable CTI Studio is an AI-assisted cyber threat intelligence workbench that turns open-source CTI into Sigma rules.
-
Updated
Aug 28, 2026 - Python
Huntable CTI Studio is an AI-assisted cyber threat intelligence workbench that turns open-source CTI into Sigma rules.
Open-source Python CTI pipeline that collects and enriches IoCs from five feeds, generates a Plotly dashboard and CSV export, and forecasts seven-day threat trends for SOC analysts.
An automated cybersecurity threat intelligence analysis pipeline that extracts indicators of compromise (IOCs), maps MITRE ATT&CK techniques, and builds knowledge graphs from unstructured CTI reports using NLP and LLMs. Features cross-platform compatibility and RESTful API for integration.
Forensic analysis of a targeted phishing campaign, email header tracing, URL sandboxing, and IOC extraction.
AI-powered phishing email analyzer for SOC analysts — Claude AI, MITRE ATT&CK mapping, IOC extraction
AI-assisted SOC/SIEM platform for forensic log analysis, threat detection, IOC extraction, threat intelligence correlation and enterprise incident reporting.
High‑performance iocx plugin for detecting Windows Registry keys, values, and persistence locations. Includes full test coverage, performance benchmarks, and security checks.
TotalOSINT is a privacy-first, client-side OSINT toolkit for security analysts. Instantly extract IOCs (IPs, Domains, Hashes) from raw logs and launch bulk investigations across dozens of threat intelligence sources. Zero-data-persistence workflow for SOC and DFIR teams. No installation required.
A Python-based static analysis toolkit for detecting malicious indicators in PDF files using metadata analysis, IOC extraction, YARA scanning, CVE detection, and threat intelligence integration.
Reverse-engineering workstation provisioner and automated binary analysis pipeline for Kali/Debian Linux. Installs a full toolchain and runs type-aware static + dynamic analysis (46 stages) on binaries, producing structured JSON, self-contained HTML reports, and explainable verdicts. Ideal for malware triage and RE workflows.
🕵️♂️ Extract IOCs quickly with TotalOSINT, a client-side OSINT tool designed for privacy-first investigations in security analysis.
Scored MITRE ATT&CK verdict engine (noisy-OR confidence), ELF/PE capability inference, attribution hashes (imphash/symhash/ssdeep/TLSH), file magic + embedded-file carving, IOC extraction, YARA on file + memory dump, pcap network intel (DNS/SNI/JA3), TOML config, report schema_version. Verified on live traffic; full test + fuzz coverage."
Modular Python static malware-analysis sandbox for IOC extraction, YARA scanning, entropy analysis, hashing, risk scoring, reports, and HTML dashboards.
Free, local phishing email analyzer — parses .eml/.msg, extracts IOCs, checks SPF/DKIM/DMARC, scores risk 0–100, and optionally enriches with VirusTotal, AbuseIPDB, URLScan, WHOIS, and Claude AI threat intelligence. No cloud. Your emails stay on your machine.
SOC-focused phishing email investigation dashboard with email authentication checks, IOC extraction, risk scoring, and investigation history.
AI-powered malware static analysis orchestrator using Model Context Protocol (MCP). Automates file triage, PE analysis, YARA scanning, string extraction, and VirusTotal enrichment through an isolated Docker worker.
End-to-end phishing investigation playbook covering email analysis, KQL hunting, identity compromise assessment, IOC extraction, threat hunting, detection opportunities, and remediation.
Python automation pipeline for malware triage — YARA rule scanning, SHA256 hashing, metadata extraction, and auto-generated HTML/CSV reports. Built for SOC analysts and DFIR workflows.
Real-world malware PCAP analysis — Lumma Stealer C2 decoded, browser fingerprinting exfiltration captured, DNS infection patterns identified. Mapped to MITRE ATT&CK using Wireshark.
Add a description, image, and links to the ioc-extraction topic page so that developers can more easily learn about it.
To associate your repository with the ioc-extraction topic, visit your repo's landing page and select "manage topics."