online│syscfg.research
utc
syscfg://research
ls ./tools/

Tools

Browser-side utilities. Nothing leaves your machine.

IOC Extractor

Extract IPs, domains, hashes, CVEs from any text

Input
//

Recommended Open Source

Tools I actually use. All open source, all well-maintained.

GhidraReverse Engineering

Software reverse engineering framework developed by the NSA over decades before public release in 2019. Disassembles, decompiles, and debugs binaries across x86, ARM, MIPS, PowerPC, and dozens more architectures. The closest open source equivalent to IDA Pro.

Java·★ ~52k
github →
MISPThreat Intelligence

Malware Information Sharing Platform. The industry-standard open source threat intelligence platform used by national CERTs, government agencies, and security teams globally. Structured IOC storage, correlation, and sharing via STIX, OpenIOC, and native MISP formats.

PHP / Python·★ ~5.5k
github →
ZeekNetwork

Passive network security monitor that turns raw traffic into high-fidelity structured logs. Rather than signature matching, Zeek creates a detailed record of every connection, DNS query, HTTP request, TLS handshake, and file transfer - built for long-term analysis and threat hunting.

C++ / Zeek Script·★ ~6.5k
github →
SpiderFootOSINT

Automated OSINT framework with 200+ modules covering domains, IPs, email addresses, usernames, phone numbers, and more. Aggregates data from passive DNS, WHOIS, breach databases, threat feeds, social media, and certificate transparency logs into a single investigation graph.

Python·★ ~13k
github →
GNU RadioRF / Signals

The definitive open source SDR toolkit. Provides signal processing blocks to build software radio systems - from protocol analysis to spectrum monitoring to custom decoder development. Works directly with HackRF, RTL-SDR, USRP, and most SDR hardware via SoapySDR.

C++ / Python·★ ~5.5k
github →
SigmaDetection

Generic signature format for SIEM detection rules. Write a rule once, convert it to Splunk, Elastic, QRadar, Azure Sentinel, Chronicle, and 20+ other backends. The SigmaHQ repository maintains thousands of community rules mapped to MITRE ATT&CK - the detection equivalent of YARA.

YAML·★ ~8.5k
github →