Ross ROSS = Recommend OSS · open-source software intelligence for agents

yeti-platform/yeti

Your Everyday Threat Intelligence observed · 2026-08-28

github.com/yeti-platform/yeti · homepage · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

99/100

  • Activity 99
  • Release rhythm 99
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 15.0
  • age_days: 3916
  • days_rel: 9
  • days_push: 7
  • n_releases_24m: 23

Full methodology

Adoption not part of the score

2020 stars · 320 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Yeti is a self-hosted threat intelligence platform that stores and links observables, entities, and indicators to answer questions like 'where have I seen this artifact before?'. It provides a REST API, plugin system for enrichment and feeds, and exports in user-defined formats for SIEM and DFIR tooling.

Use cases

  • store and search IOCs and observables
  • track threat actors, malware, and campaigns with linked artifacts
  • enrich indicators from feeds and sandboxes via plugins
  • manage Yara, Sigma, and DFIQ rules for DFIR investigations
  • export threat data to SIEM or incident response platforms
  • query threat intelligence programmatically via REST API
  • monitor GitHub for CVE proof-of-concept code

When to choose

  • you need a centralized, searchable repository of CTI observables and entities
  • your DFIR team wants to correlate artifacts across incidents and threats
  • you want to automate indicator enrichment and export to other security tools

When to avoid

  • you only need simple IOC list sharing without a graph data model
  • you cannot operate a multi-container Docker deployment with ArangoDB, Redis, and Celery
  • you need a turnkey commercial TI feed rather than a platform you populate yourself

Facets

application · maturity active

search-engine api-framework plugin-system webhook security analytics security self-hosted developer-tools self-hosted python threat-intelligence cti dfir ioc-management observables yara sigma dfiq misp enrichment threat-hunting docker web-server

10 sources

Member repositories

RepositoryRoleHealth v2
yeti-platform/yetimain99

For agents

markdown · JSON · MCP: product_card(name="yeti-platform/yeti")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem