
Mistborn
Multi-source threat intelligence and IOC aggregation platform
Activity unknown
No repository statistics available for this project.

Mistborn is an open source threat intelligence aggregation service designed to collect indicators of compromise (IOCs) and related threat data from multiple sources, normalize it, and make it easier to consume for security operations. It helps teams centralize feeds, reduce duplication, and improve the usability of threat intel in downstream tooling.
Key Features
- Aggregates threat intelligence from multiple sources and feed formats
- Normalizes and de-duplicates common IOC types (such as IPs, domains, URLs, and hashes)
- Enrichment support to add context to indicators (where configured)
- Export-oriented design for integrating aggregated intel into other systems
- Designed for ongoing ingestion and updating of intelligence over time
Use Cases
- Consolidating multiple threat feeds into a single curated dataset
- Providing enriched IOC lists for SIEM, EDR, or firewall blocklists
- Supporting incident response investigations with centralized threat intel
Mistborn is a practical option for teams that want a lightweight, self-managed way to operationalize threat intelligence, especially when working with many disparate feeds. By unifying collection and normalization, it can reduce analyst overhead and improve consistency across security workflows.
Categories:
Tags:
Tech Stack:
Similar to Mistborn

Riven
VFS-based automated media management and streaming platform
Open-source media management system that exposes a FUSE-based virtual filesystem, automates discovery/scraping/downloading, and integrates with Plex/Jellyfin/Emby.

Huginn
Open-source platform for self-hosted automation agents
Huginn is an open-source automation platform that runs agents to monitor web data, process events, and trigger actions — self-hosted and extensible.


Mattermost
Secure, self-hosted team collaboration and messaging platform.
Open-source, self-hosted messaging platform for secure team collaboration with real-time chat, audio calls, screen sharing, and integrations.


Kestra
Open-source, event-driven workflow orchestration and scheduling platform
Declarative, API-first orchestration platform for scheduled and event-driven workflows with a plugin ecosystem, UI editor, CI/CD and Terraform integration.

Fail2Ban
Log-monitoring daemon that bans abusive IPs via firewall rules
Fail2Ban monitors service logs for repeated failures and automatically bans abusive IP addresses by updating firewall rules for a configurable time.
CrowdSec
Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence
CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.
