# thalesgroup-cert/Watcher

Watcher - Open Source AI-powered Cyber Threat Intelligence & Hunting Platform. Developed with Django & React JS.

Repository: https://github.com/thalesgroup-cert/Watcher
Canonical: https://ross.abutalabs.com/products/thalesgroup-cert-watcher
Homepage: https://thalesgroup-cert.github.io/Watcher/
Language: JavaScript
License: AGPL-3.0
License Family: copyleft
Topics: cybersecurity, threat-hunting, django, reactjs, misp, thehive, security, incident-response, threat-detection, threat-intelligence, watcher, certificate-transparency, certstream, osint, monitoring, phishing, ai, huggingface, ai-threat-intelligence, cyber-ai
Last push: 2026-08-12T03:28:32+00:00

## Health v2 (maintenance only)
Score: 97/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 97, release rhythm 94, longevity 100
- inputs: {"age_days": 2192, "days_push": 21, "days_rel": 42, "gap_med": 24.0, "n_releases_24m": 23}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1372, forks 204 (observed 2026-08-28T04:04:32.246916+00:00)

## What it is
Watcher is an open-source, self-hosted cyber threat intelligence and hunting platform built with Django and React JS. It uses AI to analyze threat feeds, detect phishing and data leaks, monitor sites, and integrates with MISP and TheHive for incident response workflows.

## Use cases
- monitor emerging cybersecurity threats from RSS feeds with AI summaries
- detect phishing domains and typosquatting via DNS finder and certificate transparency
- get alerts on data leaks mentioning my domains or keywords
- monitor websites for defacement or suspicious changes
- export threat intelligence to MISP or create TheHive cases
- generate weekly digests of trending cyber threats and CVEs
- track threat actors and CVEs related to security keywords

## When to choose
- you need a self-hosted CTI platform with AI-assisted analysis
- your SOC wants automated phishing, data leak, and site monitoring alerts
- you already use MISP or TheHive and want a feed/connector layer
- you want weekly trending threat digests and breaking news alerts

## When to avoid
- you need a commercial enterprise CTI suite with vendor support
- you only want a lightweight CLI scanner rather than a full web platform
- you cannot run Docker or maintain a Django/React deployment

## Facets
- artifact type: application
- maturity: active
- function: monitoring, alerting, search-engine, nlp, machine-learning, web-framework, self-hosted, osint
- domain: security, osint
- platform: self-hosted, python
- tags: threat-intelligence, threat-hunting, misp, thehive, phishing-detection, dns-finder, data-leak-detection, site-monitoring, certstream, django, reactjs, cybersecurity, incident-response, web-server, docker, linux

## Member repositories
- thalesgroup-cert/Watcher (main) score 97

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:32.246916+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:40:47.844949+00:00, confidence not recorded.
  - readme: https://github.com/thalesgroup-cert/Watcher (fetched 2026-08-28T04:04:32.246916+00:00, sha edaf2b99a135)
  - homepage: https://thalesgroup-cert.github.io/Watcher/ (fetched 2026-08-29T11:57:44.007455+00:00, sha f80296804c3a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
