IntelOwl
Analyze files, IPs, domains, and URLs in one request by fanning out to many free/TI analyzers (YARA, PE, DNS, etc.).
Why it is included
Popular Django-based OSS enrichment hub that pairs naturally with MISP and SOAR webhooks.
Best for
SOCs centralizing observable analysis without paying per-engine SaaS for every tier.
Strengths
- Many analyzers
- Extensible
- API + Django UI
Limitations
- AGPL deployment implications; API key hygiene for external services
Good alternatives
Cortex analyzers · commercial TI platforms
Related tools
Security & Privacy
MISP
Threat intelligence sharing platform: IOCs, galaxies, taxonomies, sync between communities, and API automation.
Security & Privacy
Cortex
Observable analysis engine powering TheHive: run analyzers and responders against IOCs via a unified API.
Security & Privacy
Shuffle
Open-source security automation (SOAR) with visual workflows, webhooks, and app integrations for SOC glue code.
Security & Privacy
MWDB
CERT.pl malware repository and collaboration platform: samples, configs, tags, Karton pipeline integration, and REST API for teams.
Security & Privacy
mitmproxy
Interactive TLS-capable HTTP(S) proxy with console, web, and scriptable interception.
Security & Privacy
Volatility 3
Advanced memory forensics framework for extracting artifacts from RAM dumps across OS versions.
