๐Ÿ“š Threat Intelligence Knowledge Bases

MITRE ATT&CK

A structured knowledge base of adversary tactics, techniques, and procedures (TTPs) used in real-world attacks. Commonly referenced for threat modeling, detection engineering, and security assessments.

MITRE D3FEND

A defensive counterpart to ATT&CK that catalogs countermeasures mapped to adversary techniques. Useful for blue teamers planning security control implementation and mitigation strategies.

Malpedia

An open repository of malware family information maintained by Fraunhofer Institute. Includes behavioral profiles, YARA rules, threat actor links, and campaign details.


๐Ÿง  IOC Aggregation & Threat Sharing Platforms

Open Threat Exchange (OTX)

A collaborative platform by AlienVault for sharing IOCs, attack patterns, and pulse intelligence. Allows subscriptions to community-generated threat feeds.

ThreatFox

A platform for submitting and retrieving malware-related IOCs (IPs, URLs, domains). Offers enrichment and tagging to support real-time detection and feed integration.

IOC Bucket

A free, open-source aggregator of threat intelligence with structured IOCs collected from various community sources. Supports API-based access and download in STIX format.

APT_REPORT

A curated collection of APT reports and related indicators categorized by threat group and geography. Useful for understanding historical APT behaviors and campaigns.


๐Ÿงช Malware Analysis & Sandboxing Platforms