{"id":13462749,"url":"https://github.com/sroberts/awesome-iocs","last_synced_at":"2026-04-29T02:17:47.238Z","repository":{"id":38206568,"uuid":"74331654","full_name":"sroberts/awesome-iocs","owner":"sroberts","description":"A collection of sources of indicators of compromise.","archived":false,"fork":false,"pushed_at":"2025-05-08T15:09:05.000Z","size":57,"stargazers_count":971,"open_issues_count":5,"forks_count":122,"subscribers_count":56,"default_branch":"master","last_synced_at":"2026-04-27T10:02:48.499Z","etag":null,"topics":["awesome","awesome-list","ioc","signature","yara-rules"],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/sroberts.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE.md","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2016-11-21T06:07:44.000Z","updated_at":"2026-04-26T20:50:31.000Z","dependencies_parsed_at":"2024-11-09T06:01:00.275Z","dependency_job_id":"24e169ce-6e84-4a5f-a060-b3de27237a31","html_url":"https://github.com/sroberts/awesome-iocs","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/sroberts/awesome-iocs","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sroberts%2Fawesome-iocs","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sroberts%2Fawesome-iocs/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sroberts%2Fawesome-iocs/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sroberts%2Fawesome-iocs/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sroberts","download_url":"https://codeload.github.com/sroberts/awesome-iocs/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sroberts%2Fawesome-iocs/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32407282,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-28T19:38:08.556Z","status":"online","status_checked_at":"2026-04-29T02:00:06.602Z","response_time":110,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["awesome","awesome-list","ioc","signature","yara-rules"],"created_at":"2024-07-31T13:00:29.401Z","updated_at":"2026-04-29T02:17:47.222Z","avatar_url":"https://github.com/sroberts.png","language":"Shell","funding_links":[],"categories":["Shell","\u003ca id=\"f56806b5b229bdf6c118f5fb1092e141\"\u003e\u003c/a\u003e威胁情报","Other useful repositories","Other Useful Repositories","Related Awesome Lists","\u003ca id=\"8c5a692b5d26527ef346687e047c5c21\"\u003e\u003c/a\u003e收集","Other Lists","🛠️ Helpful Repositories","Uncategorized","Forensics, Reversing, and OSINT"],"sub_categories":["\u003ca id=\"3e10f389acfbd56b79f52ab4765e11bf\"\u003e\u003c/a\u003eIOC","TeX Lists","Uncategorized","Secure OSes"],"readme":"# Awesome IOCs [![Awesome](https://awesome.re/badge.svg)](https://awesome.re)\n\nAn [awesome](https://github.com/sindresorhus/awesome) collection of indicators of compromise (and a few IOC related tools).\n\n## Contents\n\n- [IOCs](https://github.com/sroberts/awesome-iocs#iocs)\n  - [Indicators](https://github.com/sroberts/awesome-iocs#indicators)\n  - [Snort Signatures](https://github.com/sroberts/awesome-iocs#snort-signatures)\n  - [Yara Signatures](https://github.com/sroberts/awesome-iocs#yara-signatures)\n- [Tools](https://github.com/sroberts/awesome-iocs#tools)\n  - [IOC Tools](https://github.com/sroberts/awesome-iocs#ioc-tools)\n  - [IOC Formats](https://github.com/sroberts/awesome-iocs#ioc-formats)\n\n## IOCs\n\n### Indicators\n\n- [0x27/linux.mirai](https://github.com/0x27/linux.mirai) - Leaked Linux.Mirai Source Code for Research/IoC Development Purposes.\n- [Neo23x0/signature-base](https://github.com/Neo23x0/signature-base) - Signature base for my scanner tools.\n- [aptnotes/data](https://github.com/aptnotes/data) - APTnotes data.\n- [botherder/targetedthreats](https://github.com/botherder/targetedthreats) - Collection of IOCs related to targeting of civil society.\n- [circl/osint-feed](https://www.circl.lu/doc/misp/feed-osint/) - Open Source Intelligence for MISP.\n- [citizenlab/malware-indicators](https://github.com/citizenlab/malware-indicators) - Citizen Lab Malware Reports.\n- [da667/667s_Shitlist](https://github.com/da667/667s_Shitlist) - Hi kids, do you like cyber violence? Wanna see me destroy evil in the blink of an eyelid?\n- [eset/malware-ioc](https://github.com/eset/malware-ioc) - Indicators of Compromises (IOC) of our various investigations.\n- [fireeye/iocs](https://github.com/fireeye/iocs) - FireEye Publicly Shared Indicators of Compromise (IOCs).\n- [jasonmiacono/IOCs](https://github.com/jasonmiacono/IOCs) - Indicators of compromise for threat intelligence.\n- [makflwana/IOCs-in-CSV-format](https://github.com/makflwana/IOCs-in-CSV-format) - The repository contains IOCs in CSV format for APT, Cyber Crimes, Malware and Trojan and whatever I found as part of hunting and research.\n- [nshc-threatrecon/IoC-List](https://github.com/nshc-threatrecon/IoC-List) - NSHC ThreatRecon IoC Repository\n- [pan-unit42/iocs](https://github.com/pan-unit42/iocs) - Indicators from Unit 42 Public Reports.\n- [swisscom/detections](https://github.com/swisscom/detections) - This repo contains threat intelligence information and threat detection indicators (IOC, IOA) shared by Swisscom CSIRT.\n\n### Snort Signatures\n\n- [Snort Downloads](https://www.snort.org/downloads) - Signatures for the Snort (\u0026 Suricata) Intrusion Detection System.\n- [kingtuna/Signatures](https://github.com/kingtuna/Signatures) - A mixture of snort and suricata signatures.\n\n### Yara Signatures\n\n- [0pc0deFR/YaraRules](https://github.com/0pc0deFR/YaraRules) - Multiple rules for yara-project for detect compiler/packer/protector.\n- [InQuest/yara-rules](https://github.com/InQuest/yara-rules) - A collection of Yara rules we wish to share with the world, most probably referenced from [http://blog.inquest.net](http://blog.inquest.net).\n- [OALabs/iocs](https://github.com/OALabs/iocs) - Machine-digestible malware indicators.\n- [Yara-Rules/rules](https://github.com/Yara-Rules/rules) - Repository of yara rules.\n- [advanced-threat-research/Yara-Rules](https://github.com/advanced-threat-research/Yara-Rules) - Repository of YARA rules made by McAfee ATR Team\n- [citizenlab/malware-signatures](https://github.com/citizenlab/malware-signatures) - Yara rules for malware families seen as part of targeted threats project.\n- [intezer/yara-rules](https://github.com/intezer/yara-rules) - Yara rules from Intezer.\n- [kevthehermit/YaraRules](https://github.com/kevthehermit/YaraRules) - My Yara Rules Collection.\n- [reversinglabs/reversinglabs-yara-rules](https://github.com/reversinglabs/reversinglabs-yara-rules) - ReversingLabs YARA Rules.\n- [x64dbg/yarasigs](https://github.com/x64dbg/yarasigs) - Various Yara signatures (possibly to be included in a release later).\n\n## Tools\n\n### IOC Tools\n\n- [InQuest/ThreatIngestor](https://github.com/InQuest/ThreatIngestor) - Flexible framework for consuming threat intelligence.\n- [InQuest/iocextract](https://github.com/inquest/python-iocextract) - Advanced Indicator of Compromise (IOC) extractor.\n- [Neo23x0/yarGen](https://github.com/Neo23x0/yarGen) - yarGen is a generator for YARA rules.\n- [mandiant/ioc_writer](https://github.com/mandiant/ioc_writer) - Provide a python library that allows for basic creation and editing of OpenIOC objects.\n- [yahoo/PyIOCe](https://github.com/yahoo/PyIOCe) - Python IOC Editor.\n- [ninoseki/mitaka](https://github.com/ninoseki/mitaka#downloads) - Browser extension to lookup IoCs/observables on many sources.\n\n### IOC Formats\n\n- [MISP Malware Information Sharing Platform \u0026 Threat Sharing format](https://github.com/MISP/misp-rfc) - Specifications used in the MISP project including MISP core format.\n- [Mitre Cyber Observable eXpression (CybOX™)](https://cyboxproject.github.io/) - This site contains archived CybOX documentation.\n- [Mitre Malware Attribute Enumeration and Characterization (MAEC™)](https://maecproject.github.io/) - A schema for understanding malware.\n- [Mitre Structured Threat Information eXpression (STIX™)](https://stixproject.github.io/) - A structured language for cyber threat intelligence.\n- [Yara](https://virustotal.github.io/yara/) - The pattern matching swiss knife for malware researchers (and everyone else).\n- [mandiant/OpenIOC_1.1](https://github.com/mandiant/OpenIOC_1.1) - This repository contains a revised schema, iocterms file, and other supporting documents which are the basis for a draft of a revised version of OpenIOC that we are calling OpenIOC 1.1.\n\n## License\n\nThis content uses the CC0 1.0 Universal (CC0 1.0)\nPublic Domain Dedication license.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsroberts%2Fawesome-iocs","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsroberts%2Fawesome-iocs","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsroberts%2Fawesome-iocs/lists"}