IntelOwl: manage your Threat Intelligence at scale
4,711
stars
3,102
commits
Python
primary language
Sep 10, 2026
updated
Do you want to get threat intelligence data about a malware, an IP address or a domain? Do you want to get this kind of data from multiple sources at the same time using a single API request?
You are in the right place!
IntelOwl is an Open Source solution for management of Threat Intelligence at scale. It integrates a number of analyzers available online and a lot of cutting-edge malware analysis tools.
This application is built to scale out and to speed up the retrieval of threat info.
It provides:
We try hard to keep our documentation well written, easy to understand and always updated. All info about installation, usage, configuration and contribution can be found here
To know more about the project and its growth over time, you may be interested in reading the official blog posts and/or videos about the project by clicking on this link
You can see the full list of all available analyzers in the documentation.
| Type | Analyzers Available |
|---|---|
| Inbuilt modules | - Static Office Document, RTF, PDF, PE, ELF, APK File Analysis and metadata extraction - Strings Deobfuscation and analysis (FLOSS, Stringsifter, ...) - Yara, ClamAV (a lot of public rules are available. You can also add your own rules) - PE Emulation with Qiling and Speakeasy - PE Signature verification - PE Capabilities Extraction (CAPA and Blint) - Javascript Emulation (Box-js) - Android Malware Analysis (Quark-Engine, Androguard, Mobsf, ...) - SPF and DMARC Validator - PCAP Analysis with Suricata and Hfinger - Honeyclients (Thug, Selenium) - Scanners (WAD, Nuclei, ...) - more... |
| External services | - Abuse.ch MalwareBazaar/URLhaus/Threatfox/YARAify - GreyNoise v2 - Intezer - VirusTotal v3 - Crowdsec - URLscan - Shodan - AlienVault OTX - Intelligence_X - MISP - many more.. |
Since v6.8.0 important changes have been applied to the management of the project which is fully in Certego hands now. For more information please check the discussion here
(top 30 of 102)
Python
75.1%
JavaScript
23.8%
IntelOwl: manage your Threat Intelligence at scale
4,711
stars
3,102
commits
Python
primary language
Sep 10, 2026
updated
Do you want to get threat intelligence data about a malware, an IP address or a domain? Do you want to get this kind of data from multiple sources at the same time using a single API request?
You are in the right place!
IntelOwl is an Open Source solution for management of Threat Intelligence at scale. It integrates a number of analyzers available online and a lot of cutting-edge malware analysis tools.
This application is built to scale out and to speed up the retrieval of threat info.
It provides:
We try hard to keep our documentation well written, easy to understand and always updated. All info about installation, usage, configuration and contribution can be found here
To know more about the project and its growth over time, you may be interested in reading the official blog posts and/or videos about the project by clicking on this link
You can see the full list of all available analyzers in the documentation.
| Type | Analyzers Available |
|---|---|
| Inbuilt modules | - Static Office Document, RTF, PDF, PE, ELF, APK File Analysis and metadata extraction - Strings Deobfuscation and analysis (FLOSS, Stringsifter, ...) - Yara, ClamAV (a lot of public rules are available. You can also add your own rules) - PE Emulation with Qiling and Speakeasy - PE Signature verification - PE Capabilities Extraction (CAPA and Blint) - Javascript Emulation (Box-js) - Android Malware Analysis (Quark-Engine, Androguard, Mobsf, ...) - SPF and DMARC Validator - PCAP Analysis with Suricata and Hfinger - Honeyclients (Thug, Selenium) - Scanners (WAD, Nuclei, ...) - more... |
| External services | - Abuse.ch MalwareBazaar/URLhaus/Threatfox/YARAify - GreyNoise v2 - Intezer - VirusTotal v3 - Crowdsec - URLscan - Shodan - AlienVault OTX - Intelligence_X - MISP - many more.. |
Since v6.8.0 important changes have been applied to the management of the project which is fully in Certego hands now. For more information please check the discussion here
(top 30 of 102)
Python
75.1%
JavaScript
23.8%