Skip to content

Threat Intelligence Feed

Vendor verdicts, blocklist hits, and malware references aggregated from external feeds. Each signal cites the source feed and the timestamp the evidence surfaced.

  • 12 named signals across 5 subgroups
  • Recomputed live per IOC, not pulled from a static feed
  • Every signal ships with evidence + 3-question Q&A trail
About

What Threat Intelligence Feed models

Aggregates third-party vendor verdicts, blocklist hits, and malware references.

What it models
Aggregates third-party vendor verdicts, blocklist hits, and malware references.
How it fires
Each signal cites the source feed and the timestamp the evidence surfaced; auditable, deduplicated across overlapping vendors.
Why it matters
Gives the engine a corroboration layer; analysts see exactly which feeds agree and which disagree on the same IOC.
Subgroups

5 subgroups · 12 signals in Threat Intelligence Feed

Each subgroup bundles signals that share a mechanism: same evidence shape, same direction logic. Tap one to inspect its signal names; every name opens a leaf page with the underlying Q&A trail.

See subgroup detail
See subgroup detail
See subgroup detail
See subgroup detail
See subgroup detail
Verdict scenarios

How Threat Intelligence Feed shapes the call

Three real-world situations where this group's evidence dominates the decision. The verdict and explanation are how VerdictIQ would frame the outcome to an analyst, not raw signal slugs.

High riskVERDICT · BLOCK
The situation

A domain present on three independent vendor blocklists in the last 14 days, with at least one feed citing malware C2 association.

VerdictIQ explains

Decline this domain. Multiple unrelated feeds converging on the same asset within a tight window is high-confidence external signal. The C2 attribution adds intent. Block until the feeds clear it.

Medium riskVERDICT · REVIEW
The situation

A domain that surfaced on a single low-precision feed six months ago, with no recent reputation activity but lingering historical mention.

VerdictIQ explains

Send to analyst review. One stale feed hit isn't enough to block, but the historical mention warrants confirmation that the asset has changed hands or behavior since. Verify before granting trust.

Low riskVERDICT · ALLOW
The situation

A domain with no presence on any monitored vendor feed, no historical malware association, and a clean abuse record.

VerdictIQ explains

Allow. The external reputation surface is clean across the feeds we aggregate. No threat-intelligence reason to delay the request.

See Threat Intelligence Feed signals fire on your data

Free tier: 100 IOCs/day, LLM layer included.