SpiderFoot screenshot thumbnail

SpiderFoot

SpiderFoot is an open-source OSINT automation platform, replacing hours of manual reconnaissance with automated intelligence gathering across more than 200 data collection modules. The platform accepts ten distinct target types including IP addresses, domains, hostnames, network subnets, ASNs, email addresses, phone numbers, usernames, person names, and Bitcoin addresses, then feeds them through a publisher-subscriber event bus where each module's findings trigger downstream analysis automatically. SpiderFoot queries Shodan, VirusTotal, HaveIBeenPwned, AlienVault OTX, Censys, crt.sh, WHOIS databases, social media platforms, breach databases, and dozens more sources, with most modules requiring no API keys and many offering free tiers for those that do. The YAML-configurable correlation engine applies 37 pre-defined rules to identify relationships between discovered data points, flagging patterns like shared infrastructure, credential exposure, and domain reputation anomalies. Results export in CSV, JSON, and GEXF graph formats for integration with external analysis tools. TOR integration enables dark web searching, and SpiderFoot can invoke external tools including DNSTwist, Whatweb, Nmap, and CMSeeK for deeper technical assessment. The embedded web server delivers an intuitive dashboard for scan management, data visualization, and result exploration alongside a full command-line interface for scripted automation. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.

Deploy
Agentic SOC Platform screenshot thumbnail

Agentic SOC Platform

Agentic SOC Platform compresses hours of manual security analysis into seconds by deploying specialized AI agents that autonomously triage, investigate, and enrich security alerts. The Python/Django backend processes SIEM webhooks through Redis Streams into a modular pipeline where LangGraph-orchestrated agents extract IOCs, correlate signals, and generate Cases with severity, confidence, impact, priority, and structured verdicts. The built-in SIRP provides full case management with Alerts, Artifacts, Enrichments, Tickets, and a Knowledge base that accumulates institutional memory for both human analysts and LLM agents. Native Splunk and Elasticsearch/Kibana integrations deliver unified log search through a standardized interface so agents and analysts share identical security context. The playbook engine combines traditional SOAR automation with AI-powered investigation — launching threat hunting agents, knowledge extraction, threat intelligence enrichment, and CMDB lookups from a single orchestration layer. MCP Plugin support exposes ASP capabilities to Claude Code, Codex, and OpenCode, enabling external AI agents to operate cases, search logs, query threat intelligence, and write custom modules directly. Python Modules adapt new alert sources while Playbooks orchestrate LLM analysis and automated response actions, scaling the platform with your security scenarios. Deploy via Docker Compose with all data staying inside your network. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.

Deploy
IRONSIGHT screenshot thumbnail

IRONSIGHT

IRONSIGHT fuses over 50 publicly available intelligence sources into a single real-time dashboard that requires zero API keys and zero configuration. The Live Intel Feed aggregates 20+ RSS news sources with keyword relevance filtering from outlets including Reuters, Al Jazeera, and Kyiv Post. The Telegram OSINT module scrapes 27 channels every 60 seconds with automatic translation from Hebrew, Arabic, and Farsi. The interactive Leaflet Theater Map plots military aircraft positions via ADS-B transponder data, naval vessel locations in the Persian Gulf and Eastern Mediterranean, strike markers extracted from news and Telegram, missile trajectory arcs with range rings, and country-border overlays with a distance measurement tool. A header toggle switches the entire dashboard between Iran/Israel and Russia/Ukraine theaters, re-pointing every panel, map layer, and data feed to the selected conflict. The Israel Alert module streams live Pikud HaOref missile alerts with audio notifications, while the Conflict Monitor categorizes events into strikes, defense, diplomatic, and nuclear. Financial panels track defense contractor stocks, S&P 500, VIX, gold, Bitcoin, Ethereum, energy commodities via Yahoo Finance, and Polymarket prediction odds on conflict outcomes. NASA FIRMS satellite thermal detection flags fire and explosion signatures. The Next.js 16 App Router handles server-side data fetching for RSS and API endpoints while client-side React state management drives real-time polling updates. On RepoCloud, deploy IRONSIGHT on a dedicated VPS with persistent storage, root SSH access, and full control over your intelligence monitoring environment, all under the MIT license.

Deploy