Skip to content
84

Awesome IOCs

Curated sources of indicators of compromise, detection signatures and IOC tools.

1k stars128 forks35 entriesLast push Sep 29, 2026 (today)License CC0-1.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

IOCs >Indicators

CIRCL OSINT Feed

CIRCL's public MISP feed of indicators from open-source reporting, ready to subscribe to from a MISP instance.

Cisco-Talos/IOCs

IOCs from Cisco Talos.

In 2 lists

CyberBriefing IOC API

Vendor-operated REST API that puts active IOCs from public feeds (AlienVault OTX, Abuse.ch URLhaus, ThreatFox, CISA KEV, Tor exit nodes, OpenPhish) behind one query interface; free tier requires an API key.

DomainTools-Investigations/Malware-and-Scams

IOCs from DomainTools for malware and scams.

DomainTools-Investigations/Nation-State-Threats

IOCs from DomainTools for nation-state threats.

Extuno Malicious Package Database

Vendor-operated database of malicious browser extensions and packages across 12 ecosystems (Chrome, Firefox, VS Code, npm, PyPI, WordPress and others), aggregated from OSV, OpenSSF and vendor feeds, for checking software supply-chain exposure; free web lookup and JSON endpoint.

Neo23x0/signature-base

YARA rules and IOCs behind the LOKI and THOR Lite scanners, curated for a low false-positive rate and updated frequently.

In 2 lists

PaloAltoNetworks/Unit42-Threat-Intelligence-Article-Information

IOCs and supporting data for Palo Alto Networks Unit 42 threat research articles, so indicators can be traced back to their write-up.

In 2 lists

ThreatCluster Public IOC Feed

Vendor-operated feed of indicators extracted from clustered public reporting, available as TXT, CSV and JSON.

ThreatView Feeds

Free daily blocklists of malicious IPs, domains, URLs and file hashes, plus a C2 hunt feed of command-and-control servers with beacon configs; included in MISP's default feed list.

aptnotes/data

Index of public reports on APT campaigns sorted by year, useful for tracing indicators back to the original vendor reporting.

In 3 lists

botherder/targetedthreats

Network indicators from reports on the targeting of civil society, published as CSV, JSON and generated Snort rules.

citizenlab/malware-indicators

Indicators from Citizen Lab investigations into targeted attacks on civil society, one directory per report.

cystack/stealer-fingerprints

Fingerprints of infostealer log formats (banner strings, field signatures, YARA rules) for 30+ families including RedLine, Vidar, Lumma and StealC, for identifying which stealer produced a leaked log.

In 2 lists

eset/malware-ioc

Indicators from ESET research publications, one directory per report and actively updated.

In 4 lists

hvs-consulting/ioc_signatures

IOCs, CSV context and YARA rules from HvS-Consulting incident response work, organized by threat actor or campaign for threat hunting.

trilwu/apttrail

APT indicators that carry the actor they belong to, its MITRE ATT&CK group ID, when they first appeared and the report that published them.

volexity/threat-intel

IOCs from Volexity public threat research blog posts, organized by year and post.

In 3 lists

IOCs >Snort and Suricata Signatures

Emerging Threats Open

Free Proofpoint Emerging Threats ruleset for Snort and Suricata, a common baseline for network intrusion detection.

Snort Downloads

Official Snort rule sets, many of which also work with Suricata.

IOCs >YARA Signatures

InQuest/yara-rules

YARA rules from InQuest research, intended for hunting rather than production detection; many are referenced from the InQuest blog.

In 2 lists

Yara-Rules/rules

Community-compiled YARA ruleset classified by threat type, a broad starting point for hunting.

In 4 lists

advanced-threat-research/Yara-Rules

YARA rules that accompany Trellix Advanced Threat Research (formerly McAfee ATR) blog posts and investigations.

In 2 lists

elastic/protections-artifacts

YARA rules and EQL behavior rules used by Elastic Security for endpoint, with coverage mapped to MITRE ATT&CK.

In 3 lists

intezer/yara-rules

YARA rules from Intezer malware research.

In 2 lists

reversinglabs/reversinglabs-yara-rules

Detection-focused YARA rules from ReversingLabs threat analysts, written with the stated aim of zero false positives.

In 2 lists

x64dbg/yarasigs

YARA signatures for identifying packers, compilers and crypto constants, useful during reverse engineering.

In 2 lists

Tools >IOC Tools

Neo23x0/yarGen

Generates YARA rules from malware samples while filtering out strings common in goodware.

In 4 lists

ninoseki/mitaka

Browser extension that looks up a selected IOC across many OSINT and scanning services from the context menu.

In 2 lists

pedramamini/ThreatIngestor

Extendable framework that extracts and aggregates IOCs from threat feeds and passes them to other tools.

pedramamini/iocextract

Extracts IOCs from text, including defanged URLs, IP addresses and hashes.

Tools >IOC Formats

MISP Malware Information Sharing Platform & Threat Sharing format

Specifications for the MISP core format and related formats, used to exchange indicators between MISP and other platforms.

MITRE Malware Attribute Enumeration and Characterization (MAEC™)

Schema for encoding malware behaviors, capabilities and attributes.

OASIS Structured Threat Information Expression (STIX™)

A structured language and serialization format for exchanging cyber threat intelligence.

YARA

Pattern-matching language and tool for identifying and classifying malware, used by most signature collections in this list.

In 2 lists
See category
94

Awesome OpenClaw Skills

VoltAgent/awesome-openclaw-skills

The awesome collection of OpenClaw skills. 5,400+ skills filtered and categorized from the official OpenClaw Skills Registry.🦞

Fresh★ 53k830 entriesPushed today
92

Awesome DeepSeek Harness (DSH) Plugin

awesome-dsh-plugin/awesome-dsh-plugin

A curated list of plugins for DeepSeek Harness (dsh) · DeepSeek Harness 插件精选列表

Fresh★ 17k1654 entriesPushed today
91

Awesome Guidelines

Kristories/awesome-guidelines

Programming style, best practices, and coding conventions.

Fresh★ 11k166 entriesPushed 2 days ago
90

Awesome

sindresorhus/awesome

😎 Awesome lists about all kinds of interesting topics [NOTE: Pull requests are temporarily disabled until I have a chance to catch up with the existing ones]

Fresh★ 513k51 entriesPushed 28 days ago
90

Awesome Prompts

ai-boost/awesome-prompts

Curated list of chatgpt prompts from the top-rated GPTs in the GPTs Store. Prompt Engineering, prompt attack & prompt protect. Advanced Prompt Engineering papers.

Fresh★ 9k288 entriesPushed today
90

Awesome README

matiassingers/awesome-readme

A curated list of awesome READMEs

Fresh★ 22k143 entriesPushed yesterday