{"repo":"bhavikmalhotra/ThreatPad","free":true,"listed":false,"github":"https://github.com/bhavikmalhotra/ThreatPad","clone":"git clone https://github.com/bhavikmalhotra/ThreatPad.git","description":"Open-source collaborative note-taking platform for cybersecurity and CTI teams. IOC auto-extraction, STIX 2.1 export, real-time editing, RBAC, version history, and audit logging. Self-hosted with Docker.","language":"TypeScript","stars":23,"topics":["collaboration","cti","cybersecurity","fastify","ioc","nextjs","self-hosted","stix","stix2","threat-intelligence"],"license":"MIT","category":"self-hosted-apps","readme_excerpt":"ThreatPad A collaborative, real-time note-taking platform built for Cyber Threat Intelligence (CTI) and security operations teams. ThreatPad combines the speed of modern productivity tools with CTI-specific capabilities: IOC auto-extraction, STIX 2.1 export, structured threat templates, and fine-grained access control. Live Demo — login with demo@threatpad.io / password123 Features - Rich Editor — WYSIWYG with syntax highlighting, tables, task lists, Edit/Preview toggle - Drawing & Diagrams — Full-page Excalidraw canvas for attack flowcharts, network diagrams, and workflows. Also embeddable as inline drawing blocks within text notes. - IOC Auto-Extraction — Detects IPs, domains, URLs, hashes, emails, CVEs from note content - Plugin-Based Exports — JSON, CSV, STIX 2.1 built-in. Add your own with a single file - CTI Templates — IOC Dump, Threat Actor Profile, Incident Notes, Campaign Tracker - Workspaces & Folders — Nested folders, multiple workspaces, tag-based filtering - Access Control — Workspace RBAC (owner/editor/viewer), per-note sharing, private notes - Version History — Auto-snapshots every 5 min, diff view, one-click restore - Full-Text Search — Postgres-backed substring + stemmed search - Audit Logging — Track all user actions across workspaces - Self-Hosted — Your data stays on your network Quick Install Requires Docker. That's it. Open http://localhost:3000 — you'll be guided through creating your admin account. This starts PostgreSQL, Redis, the API server, and th","default_branch":null,"files":null,"tree":[],"storefront":"/r/bhavikmalhotra","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bhavikmalhotra/ThreatPad/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}