Open-source Python CTI pipeline that collects and enriches IoCs from five feeds, generates a Plotly dashboard and CSV export, and forecasts seven-day threat trends for SOC analysts.
-
Updated
Jul 6, 2026 - Python
Open-source Python CTI pipeline that collects and enriches IoCs from five feeds, generates a Plotly dashboard and CSV export, and forecasts seven-day threat trends for SOC analysts.
🛡️ 10 production-shaped SOC automation playbooks for n8n LLM-assisted alert triage, phishing analysis, IOC enrichment, human-approved containment, CVE watch & SOC reporting. Import-ready JSON, zero secrets.
PS Banshee is a command-line interface (CLI) tool designed to provide quick and efficient access to Recorded Future Intelligence. Built for security professionals, PS Banshee helps streamline investigations and automate common security operations tasks.
Python script to enrich Domain and IP Address IOCs with data from RiskIQ, VirusTotal & Symantec's sitereview.
veCTIon enriches IOCs by correlating data into a meaningful story: IOC → Malware Family → APT Group → MITRE TTPs. By providing an IOC, veCTIon performs IOC enrichment and threat actor attribution, attempting to provide the most information about an IOC to aid in CTI.
A simple Python CLI tool that reads file hashes from a text file and checks their reputation using the VirusTotal v3 API. Built to be free-tier friendly by respecting VirusTotal’s public API rate limits and using caching to avoid re-querying.
Ioc enrichment tool .
A Dockerized threat intelligence graph platform for IOC pivoting, CVE investigation, MITRE ATT&CK mapping, and SIEM/Wazuh alert enrichment using FastAPI and Neo4j.
Async Python threat-intel pipeline — enriches IDS alerts and scan findings against AbuseIPDB, OTX, URLhaus, CISA KEV and EPSS, scores them, and exports STIX 2.1 bundles. 89% coverage, mypy strict, CI-enforced.
Integrated Wazuh with Tines SOAR to automate security alert handling, threat intelligence enrichment, Slack notifications, analyst approval, and response actions. Built an end-to-end workflow using AbuseIPDB, VirusTotal, Wazuh API, and Active Response to detect, investigate, and contain suspicious activity.
IOC enrichment engine — parallel threat intelligence across VirusTotal, AbuseIPDB, MalwareBazaar, URLScan, GreyNoise, OTX and more
IOC enrichment and threat intelligence dashboard for analyzing IPs, domains, URLs and hashes with automated risk scoring and relationship visualization.
Self-hosted SIEM alert enrichment microservice for Splunk — auto-enriches IOCs via VirusTotal, Shodan & AbuseIPDB, scores risk 0–100, and cuts SOC analyst triage time from ~8 min to <90 sec. FastAPI + Redis, Docker-ready.
Python security automation tool that extracts IOCs from logs, enriches IPs with VirusTotal, caches results in SQLite, generates firewall blocklists, and drafts analyst-ready incident reports.
SOC security automation scripts for alert triage, IOC enrichment, and incident response workflows
A SOC analyst console + automation backend that ingests SIEM alerts (e.g., Wazuh), extracts IoCs, enriches them (IP/domain/hash/URL), correlates activity, computes risk & confidence scores, and generates triage-ready reports. Includes an EML upload pipeline for phishing email analysis and Slack/Discord notifications via n8n.
Add a description, image, and links to the ioc-enrichment topic page so that developers can more easily learn about it.
To associate your repository with the ioc-enrichment topic, visit your repo's landing page and select "manage topics."