# How to Find Malware Analysis and Cyber Threat Intelligence Resources in Legendary OSINT

> Discover malware analysis and cyber threat intelligence resources within Legendary OSINT. Explore categorized platforms, tools, and feeds to enhance your security investigations.

- Repository: [Henri/Legendary_OSINT](https://github.com/K2SOsint/Legendary_OSINT)
- Tags: how-to-guide
- Published: 2026-08-09

---

**The malware analysis and cyber threat intelligence resources in Legendary OSINT are centralized in [`docs/malware-cti.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/docs/malware-cti.md), which catalogs platforms, tools, feeds, and services across seven logical categories.**

Legendary_OSINT is a documentation-centric repository that aggregates free tools and resources for open-source intelligence investigations. If you are looking for malware analysis and cyber threat intelligence resources in Legendary OSINT, the repository organizes these assets into a single, well-structured markdown file accessible directly from the main index.

## Locating the Central Resource File

### Navigating to docs/malware-cti.md

According to the Legendary_OSINT source code, all malware analysis and CTI resources are gathered in [`docs/malware-cti.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/docs/malware-cti.md). The top-level [`README.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/README.md) provides a clickable navigation index that directs users to this specific page, serving as the entry point for threat intelligence research.

### Repository Structure Overview

The repository follows a simple documentation structure where each OSINT domain receives its own markdown file in the `docs/` directory. For malware investigations, [`docs/malware-cti.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/docs/malware-cti.md) serves as the authoritative source, while complementary automation guidance appears in [`docs/automation-recon.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/docs/automation-recon.md) and AI-assisted techniques are documented in [`docs/ai-osint.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/docs/ai-osint.md).

## Categories of Malware Analysis and CTI Resources

The [`docs/malware-cti.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/docs/malware-cti.md) file organizes resources into seven distinct sections:

- **Malware Analysis Platforms**: Sandbox services like VirusTotal, Hybrid Analysis, and ANY.RUN
- **Malware Analysis Tools**: Specialized utilities including REMnux, YARA, and Capa
- **Reverse Engineering & Disassembly**: Frameworks such as Ghidra and IDA Free
- **Network & Behavior Analysis**: Tools like Wireshark and Procmon for traffic and system monitoring
- **Malware Feeds & Repositories**: Curated collections including Malpedia and URLhaus
- **Threat-Intelligence Platforms**: Collaboration systems like MISP and OpenCTI
- **IOC Enrichment & Internet Scanners**: Services such as ThreatMiner, Shodan, and GreyNoise

## Programmatically Extracting Resource Lists

Because Legendary_OSINT is hosted on GitHub, you can fetch the raw markdown programmatically for automation or integration into your own tooling. The structured headings and bullet lists in [`docs/malware-cti.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/docs/malware-cti.md) make parsing straightforward with libraries like `markdown-it-py` or simple regex patterns.

The following Python example downloads the malware-CTI file and extracts URLs from the Malware Analysis Platforms section:

```python
import requests
import re

# Raw URL for the Markdown file

url = "https://raw.githubusercontent.com/K2SOsint/Legendary_OSINT/main/docs/malware-cti.md"
resp = requests.get(url)
resp.raise_for_status()
markdown = resp.text

# Extract all URLs from the "Malware Analysis Platforms" section

platform_section = re.search(r"### Malware Analysis Platforms(.*?)(\n###|$)", markdown, re.S).group(1)

platform_urls = re.findall(r"\[(.*?)\]\((https?://[^)]+)\)", platform_section)

print("Malware Analysis Platforms:")
for name, link in platform_urls:
    print(f"- {name}: {link}")

```

This approach leverages the consistent markdown structure to build automated tooling pipelines.

## Integrating with External APIs

The resources listed in Legendary_OSINT can be integrated directly into analysis workflows. Below are practical examples using platforms referenced in the repository.

### Querying VirusTotal for File Analysis

Use the VirusTotal API to check file hashes against the database:

```python
import os
import requests

VT_API_KEY = os.getenv("VT_API_KEY")          # Store your key in an .env file – never hard‑code it

hash_to_check = "d41d8cd98f00b204e9800998ecf8427e"

vt_url = f"https://www.virustotal.com/api/v3/files/{hash_to_check}"
headers = {"x-apikey": VT_API_KEY}
response = requests.get(vt_url, headers=headers)

if response.status_code == 200:
    data = response.json()
    print("Malicious? :", data["data"]["attributes"]["malicious"])
else:
    print("Error:", response.status_code, response.text)

```

### Fetching Samples from MalwareBazaar

Retrieve the latest public malware samples without requiring an API key:

```python
import requests

mb_url = "https://mb-api.abuse.ch/api/v1/"
payload = {"query": "get_recent", "selector": "10"}   # Get 10 most recent samples

resp = requests.post(mb_url, data=payload)
resp.raise_for_status()
samples = resp.json()["data"]

for s in samples:
    print(f"SHA256: {s['sha256']}")
    print(f"Tags: {', '.join(s['tags'])}")
    print("-" * 40)

```

These integrations demonstrate how the curated lists in [`docs/malware-cti.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/docs/malware-cti.md) translate into actionable security operations.

## Summary

- **Primary Location**: All malware analysis and cyber threat intelligence resources reside in [`docs/malware-cti.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/docs/malware-cti.md) within the Legendary_OSINT repository.
- **Navigation**: The main [`README.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/README.md) provides a clickable index to access the malware-CTI documentation.
- **Organization**: Resources are grouped into seven logical categories ranging from sandbox platforms to IOC enrichment services.
- **Automation**: The markdown structure supports programmatic extraction via the GitHub raw content URL or API.
- **Integration**: Listed services like VirusTotal and MalwareBazaar offer APIs that enable automated threat hunting workflows.

## Frequently Asked Questions

### Where are malware analysis resources located in Legendary OSINT?

All malware analysis and cyber threat intelligence resources are centralized in the [`docs/malware-cti.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/docs/malware-cti.md) file. The top-level [`README.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/README.md) contains a navigation index that links directly to this document, making it the single source of truth for CTI tooling within the repository.

### What categories of CTI tools are listed in the repository?

The [`docs/malware-cti.md`](https://github.com/K2SOsint/Legendary_OSINT/blob/main/docs/malware-cti.md) file organizes tools into seven categories: Malware Analysis Platforms, Malware Analysis Tools, Reverse Engineering & Disassembly, Network & Behavior Analysis, Malware Feeds & Repositories, Threat-Intelligence Platforms, and IOC Enrichment & Internet Scanners.

### How can I automate extraction of resources from the markdown files?

You can fetch the raw markdown content from `https://raw.githubusercontent.com/K2SOsint/Legendary_OSINT/main/docs/malware-cti.md` using HTTP requests. The consistent use of ATX headings and bullet lists allows straightforward parsing with regex or markdown processing libraries like `markdown-it-py`.

### Does Legendary OSINT include API integration examples?

While the repository itself is documentation-focused, it catalogs services that provide APIs such as VirusTotal and MalwareBazaar. The repository structure supports integration by providing the resource URLs and context needed to implement API calls in Python or other languages for automated threat intelligence gathering.