Awesome IOCs
An awesome collection of indicators of compromise (and a few IOC related tools).
Contents
IOCs
Indicators
- 0x27/linux.mirai - Leaked Linux.Mirai Source Code for Research/IoC Development Purposes.
- Neo23x0/signature-base - Signature base for my scanner tools.
- aptnotes/data - APTnotes data.
- botherder/targetedthreats - Collection of IOCs related to targeting of civil society.
- circl/osint-feed - Open Source Intelligence for MISP.
- citizenlab/malware-indicators - Citizen Lab Malware Reports.
- da667/667s_Shitlist - Hi kids, do you like cyber violence? Wanna see me destroy evil in the blink of an eyelid?
- eset/malware-ioc - Indicators of Compromises (IOC) of our various investigations.
- fireeye/iocs - FireEye Publicly Shared Indicators of Compromise (IOCs).
- jasonmiacono/IOCs - Indicators of compromise for threat intelligence.
- makflwana/IOCs-in-CSV-format - The repository contains IOCs in CSV format for APT, Cyber Crimes, Malware and Trojan and whatever I found as part of hunting and research.
- nshc-threatrecon/IoC-List - NSHC ThreatRecon IoC Repository
- pan-unit42/iocs - Indicators from Unit 42 Public Reports.
- swisscom/detections - This repo contains threat intelligence information and threat detection indicators (IOC, IOA) shared by Swisscom CSIRT.
Snort Signatures
- Snort Downloads - Signatures for the Snort (& Suircata) Intrusion Detection System.
- kingtuna/Signatures - A mixture of snort and suricata signatures.
Yara Signatures
- 0pc0deFR/YaraRules - Multiple rules for yara-project for detect compiler/packer/protector.
- advanced-threat-research/Yara-Rules - Repository of YARA rules made by McAfee ATR Team
- InQuest/yara-rules - A collection of Yara rules we wish to share with the world, most probably referenced from http://blog.inquest.net.
- OALabs/iocs - Machine-digestible malware indicators.
- Yara-Rules/rules - Repository of yara rules.
- citizenlab/malware-signatures - Yara rules for malware families seen as part of targeted threats project.
- intezer/yara-rules - Yara rules from Intezer.
- kevthehermit/YaraRules - My Yara Rules Collection.
- x64dbg/yarasigs - Various Yara signatures (possibly to be included in a release later).
Tools
IOC Tools
- InQuest/ThreatIngestor - Flexible framework for consuming threat intelligence.
- InQuest/iocextract - Advanced Indicator of Compromise (IOC) extractor.
- Neo23x0/yarGen - yarGen is a generator for YARA rules.
- mandiant/ioc_writer - Provide a python library that allows for basic creation and editing of OpenIOC objects.
- yahoo/PyIOCe - Python IOC Editor.
- ninoseki/mitaka - Browser extension to lookup IoCs/observables on many sources.
IOC Formats
- MISP Malware Information Sharing Platform & Threat Sharing format - Specifications used in the MISP project including MISP core format.
- Mitre Cyber Observable eXpression (CybOXâ„¢) - This site contains archived CybOX documentation.
- Mitre Malware Attribute Enumeration and Characterization (MAECâ„¢) - A schema for understanding malware.
- Mitre Structured Threat Information eXpression (STIXâ„¢) - A structured language for cyber threat intelligence.
- Yara - The pattern matching swiss knife for malware researchers (and everyone else).
- mandiant/OpenIOC_1.1 - This repository contains a revised schema, iocterms file, and other supporting documents which are the basis for a draft of a revised version of OpenIOC that we are calling OpenIOC 1.1.
License
This content uses the CC0 1.0 Universal (CC0 1.0) Public Domain Dedication license.