Tools
Browser-side utilities. Nothing leaves your machine.
IOC Extractor
Extract IPs, domains, hashes, CVEs from any text
Recommended Open Source
Tools I actually use. All open source, all well-maintained.
Software reverse engineering framework developed by the NSA over decades before public release in 2019. Disassembles, decompiles, and debugs binaries across x86, ARM, MIPS, PowerPC, and dozens more architectures. The closest open source equivalent to IDA Pro.
Malware Information Sharing Platform. The industry-standard open source threat intelligence platform used by national CERTs, government agencies, and security teams globally. Structured IOC storage, correlation, and sharing via STIX, OpenIOC, and native MISP formats.
Passive network security monitor that turns raw traffic into high-fidelity structured logs. Rather than signature matching, Zeek creates a detailed record of every connection, DNS query, HTTP request, TLS handshake, and file transfer - built for long-term analysis and threat hunting.
Automated OSINT framework with 200+ modules covering domains, IPs, email addresses, usernames, phone numbers, and more. Aggregates data from passive DNS, WHOIS, breach databases, threat feeds, social media, and certificate transparency logs into a single investigation graph.
The definitive open source SDR toolkit. Provides signal processing blocks to build software radio systems - from protocol analysis to spectrum monitoring to custom decoder development. Works directly with HackRF, RTL-SDR, USRP, and most SDR hardware via SoapySDR.
Generic signature format for SIEM detection rules. Write a rule once, convert it to Splunk, Elastic, QRadar, Azure Sentinel, Chronicle, and 20+ other backends. The SigmaHQ repository maintains thousands of community rules mapped to MITRE ATT&CK - the detection equivalent of YARA.