Threat Intelligence Overview
Aggregated consensus indicators indexed in real-time across multi-vector telemetry.
| Indicator | Type | Risk Level | Score | Category | Family / Actor | Country | Confidence | Action |
|---|---|---|---|---|---|---|---|---|
| Loading stream data... | ||||||||
IP Threat Directory
Active malicious IP addresses and subnets indexed in memory.
| IP / Subnet | Risk Level | Score | Category | Threat / Actor | Country | Confidence | Last Updated | Action |
|---|---|---|---|---|---|---|---|---|
| Loading IP indicators... | ||||||||
Domains & Phishing
Active phishing hosts, C2 domains, and malicious FQDNs.
| Domain | Risk Level | Score | Category | Malware Strain | Confidence | Action |
|---|---|---|---|---|---|---|
| Loading domain indicators... | ||||||
Payload URLs
Verified malware download endpoints and dropper URLs.
| Payload URL | Risk Level | Score | Malware Family | Technique | Confidence | Action |
|---|---|---|---|---|---|---|
| Loading payload URLs... | ||||||
Malware File Hashes
Cryptographic hashes (SHA256, SHA1, MD5) of verified malicious binaries.
| Hash Value | Algorithm | Risk Level | Score | Malware Strain | Attributed Actor | Confidence | Action |
|---|---|---|---|---|---|---|---|
| Loading malware hashes... | |||||||
Exploited CVEs (CISA KEV)
Known exploited vulnerabilities cataloged by CISA with active in-the-wild exploitation.
| CVE ID | Vendor & Product | Vulnerability Details | CVSS Severity | Ransomware | Catalog Date | Action |
|---|---|---|---|---|---|---|
| Loading CVE vulnerabilities... | ||||||
JA3 TLS Fingerprints
Client-side TLS handshake fingerprints for malware agent detection.
| JA3 MD5 Hash | Associated Threat | Risk Level | Score | MITRE Technique | Confidence | Action |
|---|---|---|---|---|---|---|
| Loading JA3 fingerprints... | ||||||
JARM Server Fingerprints
Active TLS server signatures for C2 framework identification.
| JARM Hash (62 chars) | C2 Framework | Threat Actor | Risk Level | Score | Technique |
|---|---|---|---|---|---|
| Loading JARM signatures... | |||||
Threat Actors
Tracked nation-state adversaries and cybercrime groups with associated TTPs and indicators.
| Adversary | Origin | Motivation | Targeted Sectors | Primary Tooling | Active Indicators | Severity | Actions |
|---|---|---|---|---|---|---|---|
| Loading threat actors... | |||||||
Offensive Tool Signatures
Signatures of penetration testing tools, automated exploit frameworks, and scanners.
| Signature / User-Agent | Category | Risk Level | Score | Technique |
|---|---|---|---|---|
| Loading tool signatures... | ||||
Recon Netblocks & ASNs
Known mass scanner infrastructure and malicious ASNs.
| CIDR / Subnet | Scanner / Organization | Risk Level | Score | Category | Country |
|---|---|---|---|---|---|
| Loading scanner netblocks... | |||||
MITRE ATT&CK Matrix
Correlation of indicators across MITRE Enterprise tactics and techniques.
—
| Protocol & Scope | — |
| Reverse DNS (PTR) | — |
| Autonomous System (ASN) | — |
| Regional Registry (RIR) | — |
| Routing Prefix (CIDR) | — |
| ISP & Upstream Carrier | — |
| Geographic Location | — |
| Coordinates & Timezone | — |
| Infrastructure Class | — |
| Routability Status | — |
API Keys & Developer Tokens
Provision scoped authentication tokens for firewall feeds, SIEM pipelines, and automated threat lookups.
| Key Label | Key Prefix | Created | Expires | Last Used | Status | Actions |
|---|---|---|---|---|---|---|
| Loading active keys... | ||||||
Authentication & Integration Guides
Client SDK examples, HTTP headers, and API quickstart snippets
X-API-Key: <token>Authorization: Bearer <token>?api_key=<token>Feeds & Integrations
Ready-to-use threat feed URLs for firewalls, SIEM ingestion streams, and database snapshot downloads.
| Feed Name & Description | Tier / Depth | Target System | Format | Actions |
|---|
Account & Security Settings
Manage your account profile, corporate email, authentication credentials, and session telemetry.
Administrator
ADMINISTRATORUser Profile Details
Update your username and account email address.
Administration
System configuration, telemetry diagnostics, user access management, and threat feed orchestration.
System Runtime
Observable Storage
Database Pool
Feed Collectors
Operational status and sync metrics per intelligence collector
| Collector | Category | Status | Last Synchronized | Indicators | Errors | Feed Toggle | Actions |
|---|