Skip to content

**Cyber Threat Intelligence Repository**: A collection of CTI research on threat actors, IOCs, TTPs, and cybersecurity trends. Includes profiles, reports, tools, and analyses for ransomware, APTs, and emerging threats. Designed for cybersecurity professionals and researchers to collaborate and share insights.

License

Notifications You must be signed in to change notification settings

spearsies/CTI-Research

Repository files navigation

A sleek cybersecurit

Cybersecurity | Discipline | Innovation

===============================================

Stanley Spears (cyb3rlop3) Retired Army • Cybersecurity Analyst • Designer Defending Systems • Empowering People • Automating Security

===============================================

📘 CTI-Research Repository Legend

Element Purpose / Description
CTI_Authoring/ Templates and guidance for creating structured CTI content.
Ransomware/ Profiles, indicators, and tactics related to ransomware threats.
RunBooks/ Operational playbooks for incident response and threat mitigation.
Threat Actors/ Detailed profiles of known threat groups, including aliases, motivations, and TTPs.
LICENSE Repository licensing information. Defines usage rights and restrictions.
README.md Overview of the repository, its structure, and how to contribute or use the content.
cti-templates.zip Downloadable archive of CTI authoring templates for offline use or integration.

Threat Intelligence Aggregator 🛡️

Author: Stanley Spears (cyb3rlop3)
Purpose: Automated aggregation of threat intelligence from multiple security feeds for SOC analysts, threat intelligence teams, and security researchers.


🔑 Key Projects

  • Threat Intelligence Aggregator → Automates multi‑source threat intelligence collection, CVE extraction, IOC tracking, SIEM‑ready exports.
  • Security Automation Scripts → Workflow optimization tools for log parsing, vulnerability checks, and reporting automation.
  • Learning Modules → Exploratory Python scripts demonstrating continuous growth and adaptability.

👉 Detailed examples and integrations are available in the /docs folder.


📌 Overview

The Threat Intelligence Aggregator reduces manual effort by consolidating threat intelligence into a single, searchable dataset.
It supports SOC operations, incident response, vulnerability management, and compliance reporting.


✨ Features

  • Multi‑source aggregation (CISA, US‑CERT, The Hacker News, SANS ISC, OpenPhish)
  • CVE extraction, IOC identification, severity classification
  • Deduplication and keyword filtering
  • Export formats: JSON, CSV, HTML
  • SIEM integration (Splunk, ELK)

🚀 Quick Start

Clone the repository:

git clone https://github.com/spearsies/Pythonscripts.git
cd Pythonscripts
python threat_intel_aggregator.py

Generates timestamped reports in JSON, CSV, and HTML formats.


📂 Documentation

For technical depth, see the /docs folder:

  • Overview → Architecture, workflow, and professional value
  • Usage Examples → Role‑based scenarios (SOC, Threat Intel, Researchers, Compliance)
  • Integrations → Splunk, ELK, MISP, SOAR
  • Roadmap → Completed, in‑progress, and planned features
  • Troubleshooting → Common issues and fixes

🛡️ Professional Value

This project demonstrates:

  • Applied cybersecurity expertise: CEH, SSCP, AZ‑500 training
  • Hands‑on SOC and incident response skills: automation, log analysis, threat hunting
  • Strategic thinking: blending military discipline with technical depth
  • Enterprise readiness: SIEM integration, roadmap for MISP/SOAR compatibility

👤 Author

Stanley Spears

Defending Systems • Empowering People • Automating Security


📜 License

MIT License – Free for security research and defensive use.

About

**Cyber Threat Intelligence Repository**: A collection of CTI research on threat actors, IOCs, TTPs, and cybersecurity trends. Includes profiles, reports, tools, and analyses for ransomware, APTs, and emerging threats. Designed for cybersecurity professionals and researchers to collaborate and share insights.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published