Abuse.ch (opens in a new tab)
Why: Abuse.ch operates free community threat-intelligence projects (malware, botnets, URLhaus and related feeds) widely used for blocking and hunting.
Practical tools used in real programmes — selected for usefulness, not novelty.
50 current resources
Highest starting-point strength resources in this category.
Why: Abuse.ch operates free community threat-intelligence projects (malware, botnets, URLhaus and related feeds) widely used for blocking and hunting.
Why: The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis.
Why: Unix living-off-the-land binaries companion to LOLBAS; essential for detection engineering and abuse-path review.
Showing 50 resources
Why: Abuse.ch operates free community threat-intelligence projects (malware, botnets, URLhaus and related feeds) widely used for blocking and hunting.
Why: The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis.
Why: Unix living-off-the-land binaries companion to LOLBAS; essential for detection engineering and abuse-path review.
Why: Interactive ATT&CK layer viewer for mapping techniques to detections and coverage, helping teams visualise gaps and brief stakeholders on adversary behaviour.
Why: Open-source automated adversary-emulation platform for running ATT&CK-mapped red-team and purple-team exercises safely in your own lab.
Why: Community IP reputation database for checking whether an address has been reported for abuse before you block or investigate it.
Why: ANY.RUN dashboard of malware trends from live sandboxes, showing which families and behaviours are circulating so teams can prioritise detection and awareness work.
Why: Scans websites and maps related attack infrastructure, helping analysts pivot from a single site to the wider hosting and threat landscape behind it.
Why: Mobile-app security search — find exposed endpoints, secrets and risky configurations across Android and iOS applications.
Why: Internet-wide asset search that helps teams discover exposed hosts, certificates and services on their attack surface.
Why: Certificate Transparency log search — enumerate domains and subdomains that have obtained TLS certificates.
Why: Search leaked credentials and related identity artefacts from known breaches — useful when checking exposure after phishing or account takeover.
Why: Fast DNS reconnaissance that maps hosts, records and related infrastructure for a domain during investigations and attack-surface reviews.
Why: Generates lookalike domain variants so you can spot typosquatting and phishing infrastructure before attackers use it against your brand.
Why: Curated archive of public exploits and proof-of-concept code for vulnerability research, detection writing and controlled testing.
Why: Cyberspace search engine (FOFA) for finding exposed assets and fingerprinting services on the public internet during OSINT and attack-surface reviews.
Why: Fortinet encyclopaedia of malware, vulnerabilities and threat intelligence for rapid lookup during research and response.
Why: Attack-surface search that helps organisations discover internet-facing assets tied to their domains, supporting continuous external exposure monitoring and review.
Why: Open-source reverse-engineering suite (NSA-origin) for analysing binaries when dissecting malware or unknown software.
Why: Indexes publicly exposed cloud storage buckets so analysts can find accidental data spills and misconfigured object stores.
Why: Code search across hundreds of thousands of public git repositories — useful for finding secrets, vulnerable patterns and reuse of known code.
Why: Internet noise intelligence — tell scanner/benign mass probing apart from targeted attacks on your IPs.
Why: Free breach-notification service to check whether an email address or password has appeared in known data breaches.
Why: Finds publicly listed email addresses tied to a domain — useful for OSINT checks and phishing-defence awareness work.
Why: Deep file-inspection laboratory for analysing suspicious samples and extracting indicators — useful when you need richer context than a quick multi-engine scan.
Why: Search engine for leaked data, dark-web content and historical internet records when investigating compromised accounts and domains.
Why: Search engine for publicly indexed services and leak indicators — helps find exposed databases, panels and misconfigurations on the open internet.
Why: Living Off the Land Binaries and Scripts for Windows — essential reference for detection engineering and abuse-path reviews alongside GTFOBins.
Why: Internet-wide asset search and monitoring for hosts, services and related observables during OSINT and attack-surface work.
Why: Cyber threat intelligence search across IPs, domains and related observables — a practical OSINT and enrichment source when investigating hosts and infrastructure.
Why: Long-running feed of advisories, exploits and tools for staying current on disclosed vulnerabilities and attack techniques.
Why: Facial recognition search — find where a face appears online (use carefully; privacy-sensitive).
Why: Crowdsourced malware scanning for files and URLs, giving multi-engine verdicts useful in triage and indicator validation.
Why: Source-code search across public websites to find scripts, trackers and technology fingerprints at scale — useful for OSINT, brand protection and supply-chain checks.
Why: Threat intelligence search with community-scored risk context on indicators, helping analysts decide which IPs, domains and hashes deserve closer attention.
Why: Source-code search across millions of public projects — useful for finding leaked secrets, vulnerable patterns and library usage.
Why: Historical DNS, WHOIS and domain intelligence that helps investigators reconstruct past infrastructure and related assets during domain and host research.
Why: Search engine for internet-connected devices and services — classic attack-surface reconnaissance.
Why: Trellix Advanced Threat Research white-paper library covering laboratory techniques (function hooking, patch diffing, ICS simulation, Android SSL pinning, and related methods) for practitioners reducing attack surfaces.
Why: Converts Sigma detection rules into formats used by common SIEM and EDR platforms, speeding up detection engineering when the same logic must run across tools.
Why: abuse.ch malware URL blocklist publishing known-bad links for blocking, hunting and research — a trusted free feed for defenders tracking malicious URLs.
Why: Sandbox a suspicious URL — see page behaviour, redirects, and related indicators without opening it yourself.
Why: Multi-engine file and URL scanner that helps analysts quickly see whether a sample or link is widely flagged as malicious.
Why: Large vulnerability knowledge base spanning CVEs, advisories and related artefacts for prioritisation and research.
Why: Internet Archive web history — recover deleted or changed pages and track how sites evolved during investigations.
Why: Community wireless-network map and database for locating Wi-Fi and cellular observations during physical and RF investigations.
Why: Cyberspace search for hosts, services and exposures across the public internet — useful for OSINT, red-team reconnaissance and attack-surface checks. Canonical hub remapped from zoomeye.org (HTTP 521) to zoomeye.ai.
Why: Public malware analysis submissions from the ANY.RUN sandbox — useful for spotting what’s circulating and reviewing related indicators.
Why: Discovery hub for bug bounty programmes — helps researchers and programme owners find active scopes and opportunities.
Why: Deutsche Telekom Security’s open-source repositories — tools and detection content useful for SOC and security engineering teams.