Open Source Threat Intelligence
Threat intelligence is only useful if you trust where the indicators came from and can act on them before they go stale, yet most feeds arrive as opaque lists you are expected to ingest on faith. The open source tools here let you see how indicators are collected, enriched, and correlated, and keep your own sensitive observations inside your environment rather than handing your incident data to a sharing platform.

OpenCTI
Threat intelligence platform for structuring, linking, and visualizing cyber threat knowledge

MISP
Open source threat intelligence sharing platform for collecting, correlating, and exchanging cyber threat data

capa
Command line binary analysis tool that identifies capabilities in PE, ELF, .NET, shellcode, and sandbox reports

IntelOwl
Threat intelligence management with one API to query many sources and analysis tools at once

Yeti
Threat intelligence platform for DFIR teams, with bulk observable search and enrichment via web API

Cortex
Observable analysis and active response engine for threat intelligence and incident response
Harpoon
OSINT and threat intelligence CLI tool for querying many external sources from one command line

IntelMQ
Threat intelligence collection and processing for CERTs, CSIRTs, and SOCs