Navigation
AboutExperienceBlogResourcesMerchContact

inquiries@ctijen.com

CTIJen Resources

The Analyst Toolkit

Every tool on this page has been used or evaluated by Jen. No sponsorships, no affiliate links — just the real ones.

01 — Threat Intelligence Platforms

TIPs

Ordered by ease of implementation — Jen's opinion.

MISPFree + paid
Easiest

Open source threat data sharing platform. Perfect for beginners to see what a TIP is, how to correlate data, and practice collection and processing.

I may catch heat for saying it's easy to implement but I feel MISP is perfect for beginners. Tell me if you disagree!

OpenCTIFree + paid
Intermediate

Great platform, but will take some technical know-how to install if going the free/self-hosted route. Very capable once running.

Intermediate / Difficult

TheHive 🤝 MISP. Requires technical know-how to set up, but once it is, it's MISP's best friend and really shines ingesting MISP events.

TheHive + MISP together is a genuinely powerful combo once you've got them talking to each other.

02 — IOC & Analysis Tools

Capability Reference

Quick-reference matrix for what each tool can handle. Great for bookmarking.

IOC Query & Enrichment

ToolFreeHashIPDomainURLSandboxPassive DNSEnrichment
VirusTotalMalware and URL scanning and threat intelligence
PulsediveEnrich and research IOCs and threats
ShodanSearch engine for internet-connected devices
AlienVault OTXCommunity-powered threat intel sharing. Noisy — proceed with caution.
GreyNoiseContext for IPs scanning the internet
AbuseIPDBInspect and report malicious IPs

Capabilities may be limited on free versions

Malware Analysis & Sandboxes

ToolFreeHashIPDomainURLSandboxPassive DNSEnrichment
Hybrid AnalysisCommunity malware analysis service
Any.RunInteractive malware sandbox?
BrowserlingRun and test URLs in live browser sandboxes
Joe SandboxAdvanced malware analysis and threat detection
Cuckoo SandboxOpen-source automated malware analysis

Capabilities may be limited on free versions

More Tools Jen Uses Sometimes

ToolFreeHashIPDomainURLSandboxPassive DNSEnrichment
MaltegoGraph-based link analysis for OSINT investigations
SpiderFootAutomated OSINT collection and correlation
urlscan.ioScan and visually inspect URLs for threats
Cisco TalosThreat intelligence and reputation data
deobfuscate.relative.imLightweight tool to deobfuscate malicious JavaScript
MXToolboxDomain/IP reputation, mail server checks, and DNS tools
GhidraNSA's open-source software reverse engineering framework

Capabilities may be limited on free versions

Missing a tool that should be here? Jen's always looking to expand this list.

Suggest a tool →