> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Watcher - Open Source Cybersecurity Threat Hunting Platform
- URL: https://darkwebinformer.com/watcher-open-source-cybersecurity-threat-hunting-platform/
- Published: 2024-08-02T15:38:16.000Z
- Updated: 2025-09-04T22:28:08.000Z
- Author: Dark Web Informer
- Tags: OSINT

Watcher is a Django & React JS automated platform for discovering new potentially cybersecurity threats targeting your organisation.

It should be used on webservers and available on Docker.

## Watcher capabilities

[](https://github.com/thalesgroup-cert/Watcher?tab=readme-ov-file#watcher-capabilities)

- Detecting emerging cybersecurity trends like new vulnerabilities, malwares... Via RSS feeds ([www.cert.ssi.gouv.fr](http://www.cert.ssi.gouv.fr/), [www.cert.europa.eu](http://www.cert.europa.eu/), [www.us-cert.gov](http://www.us-cert.gov/), [www.cyber.gov.au](http://www.cyber.gov.au/)...).
- Monitor for information leaks, for example in Pastebin & other IT content exchange websites (stackoverflow, github, gitlab, bitbucket, apkmirror, npm...).
- Monitor malicious domain names for changes (IPs, mail/MX records, web pages using [TLSH](https://github.com/trendmicro/tlsh)).
- Detecting suspicious domain names targeting your organisation, using:
  - [dnstwist](https://github.com/elceef/dnstwist) algorithm.
  - Certificate transparency stream: [certstream](https://github.com/CaliDog/certstream-python)

Useful as a bundle regrouping threat hunting/intelligence automated features.

## Additional features

[](https://github.com/thalesgroup-cert/Watcher?tab=readme-ov-file#additional-features)

- Create cases on [TheHive](https://thehive-project.org/) and events on [MISP](https://www.misp-project.org/).
- Integrated IOCs export to [TheHive](https://thehive-project.org/) and [MISP](https://www.misp-project.org/).
- LDAP & Local Authentication.
- Email notifications.
- Ticketing system feeding.
- Admin interface.
- Advance users permissions & groups.

[GitHub - thalesgroup-cert/Watcher: Watcher - Open Source Cybersecurity Threat Hunting Platform. Developed with Django & React JS.Watcher - Open Source Cybersecurity Threat Hunting Platform. Developed with Django & React JS. - thalesgroup-cert/Watcher![](https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg)GitHubthalesgroup-cert![](https://repository-images.githubusercontent.com/292021736/c0e27b00-22c2-11eb-82da-785887f31685)](https://github.com/thalesgroup-cert/Watcher)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2024/08/Watcher-iocs-export.png)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2024/08/Watcher-keywords-detection.png)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2024/08/Watcher-malicious-domain-names-monitoring.png)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2024/08/Watcher-suspicious-domain-names-detection.png)