{"repo":"bobby-tablez/TTP-Threat-Feeds","free":true,"listed":false,"github":"https://github.com/bobby-tablez/TTP-Threat-Feeds","clone":"git clone https://github.com/bobby-tablez/TTP-Threat-Feeds.git","description":"Threat feeds designed to extract adversarial TTPs and IOCs, using: ✨AI✨","language":"Python","stars":74,"topics":["ai","automation","llm","llms","threat-feeds","threat-hunting","threat-intelligence","threat-reports","threat-research"],"license":"MIT","category":"ai-agents","readme_excerpt":"TTP-Threat-Feeds TTP-Threat-Feeds is a script-powered threat feed generator designed to extract adversarial TTPs and IOCs using ✨AI✨ The purpose of this project is to automate the discovery and parsing of threat actor behavior from published security research. By scraping posts from trusted vendors and blogs listed in urls.txt , the tool identifies relevant content, extracts observable adversary behaviors (TTPs) and then outputs structured, human-readable YAML files. These YAML files are designed to help detection engineers and threat researchers quickly derive detection opportunities and correlation logic. --- How It Works - Scrapes URLs from vetted threat intel sources ( urls.txt ) - Extracts the text of each publication including embedded image OCR for screenshots - Feeds content into a local LLM with a purpose-built prompt - Extracts: - Summary - Attribution - Malware families - MITRE ATT&CK techniques - Full command lines - Process relationships - Persistence and lateral movement artifacts - IOCs (domains, IPs, hashes and URLs) - Saves results as structured YAML files, sorted by date and source - Each file includes a timestamp, source domain, and top malware family name (if found). --- LLM Setup This project supports multiple LLM providers, both local and cloud-based. Supported Providers Provider Type Default Model Notes ---------- ------ --------------- ------- LM Studio Local qwen2.5-coder-32b-instruct Default, OpenAI-compatible endpoint Ollama Local qwen2.5-coder:32b ","default_branch":null,"files":null,"tree":[],"storefront":"/r/bobby-tablez","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bobby-tablez/TTP-Threat-Feeds/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}