# AmnestyTech/investigations

Indicators of Compromise from Amnesty International's cyber investigations

Repository: https://github.com/AmnestyTech/investigations
Canonical: https://ross.abutalabs.com/products/investigations
Homepage: https://securitylab.amnesty.org
Language: Python
License Family: other
Topics: forensics, spyware, threat-hunting, threat-intelligence
Last push: 2024-12-16T11:26:55+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2955, "days_push": 625, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1696, forks 183 (observed 2026-08-28T04:05:23.927828+00:00)

## What it is
A repository of indicators of compromise (IOCs) extracted from Amnesty International's technical investigations into targeted spyware attacks against human rights defenders. The data is shared under a CC-BY license for use by threat hunters and security researchers.

## Use cases
- find indicators of compromise for pegasus spyware
- feed IOCs into my threat intelligence platform
- check whether our network contacted known spyware infrastructure
- hunt for targeted surveillance malware in logs
- research state-sponsored spyware campaigns
- get IOC lists from Amnesty investigations

## When to choose
- you need curated, well-documented IOCs from reputable human rights forensics investigations
- you are threat hunting for spyware such as Pegasus or other targeted surveillance tools
- you want freely reusable (CC-BY) threat intelligence data

## When to avoid
- you need a tool or software library rather than datasets of indicators
- you require real-time automated threat feeds with SLAs
- you need a license permitting unrestricted use without attribution

## Facets
- artifact type: dataset
- maturity: active
- function: security, osint, developer-tools
- domain: security, osint, privacy
- platform: cross-platform
- tags: threat-intelligence, indicators-of-compromise, forensics, spyware, threat-hunting, ioc-feeds

## Member repositories
- AmnestyTech/investigations (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:23.927828+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:37:52.681130+00:00, confidence not recorded.
  - readme: https://github.com/AmnestyTech/investigations (fetched 2026-08-28T04:05:23.927828+00:00, sha ad9ee0204844)
  - homepage: https://securitylab.amnesty.org (fetched 2026-08-29T11:12:43.386664+00:00, sha 935f5c9b13fa)
  - site_page: https://securitylab.amnesty.org/about (fetched 2026-08-29T11:12:43.395892+00:00, sha aa716abeb6bb)
- Data as of 2026-08-30T08:39:29.467469+00:00.
