Intel Feeds and Sources
Use this page for cyber threat intelligence feeds, standards, sharing platforms, source collections, and research sources. Indicator reputation and enrichment lookups live in Threat Data; sandboxing and malware behavior analysis live in DFIR.
Intelligence Lifecycle: Deprecation and Priority
Not all indicators are equal. A malware hash tied to a confirmed intrusion usually carries more evidentiary weight than an IP address observed scanning the internet. Indicator priority depends on fidelity, corroborating context, and where the indicator sits in the attack chain.
Indicators also decay. IP addresses, domains, and infrastructure relationships can change quickly; hashes and well-described behaviors usually age better. When using feed data, track first-seen time, last-seen time, source reliability, and whether the indicator still matches current adversary behavior.
Threat Intelligence Frameworks
MITRE ATT&CK - Knowledge base of adversary tactics and techniques.
Cyber Kill Chain - Lockheed Martin's seven-stage model for attack progression.
Diamond Model - Intrusion analysis model built around adversary, capability, infrastructure, and victim.
Indicator Standards and Formats
OASIS CTI Technical Committee - Standards body for STIX and TAXII.
STIX 2.x - Structured Threat Information Expression for machine-readable CTI.
TAXII 2.x - API protocol for exchanging STIX threat intelligence.
OpenIOC - Mandiant framework for sharing threat intelligence in a machine-digestible format.
CybOX - Legacy cyber observable specification. CybOX concepts were folded into STIX 2.x observables.
Daily Checkers and Roundups
Feedly - RSS reader with cybersecurity collections.
Hackerpom Intel Feed Tool - Aggregates security news, tweets, and Reddit sources.
DFIR-specific news and case studies are preserved in the DFIR section.
Blue - DFIR: Digital Forensics and Incident ResponseCTI Resource Collections
Threat Intelligence Platforms and Tools
MISP - Open-source threat sharing platform for storing, correlating, enriching, and distributing indicators.
OpenCTI - Open-source CTI platform built around STIX 2.1 concepts.
Yeti - Platform for organizing observables, IOCs, TTPs, and threat knowledge.
IntelOwl - Open-source analyzer and enrichment platform for files, IPs, domains, and other observables.
S-TIP - Threat intelligence platform focused on CTI sharing workflows.
TheHive - Incident response and case management platform that integrates with MISP and other CTI tools.
Cortex - Observable analysis and active response engine.
Harpoon - OSINT and threat intelligence CLI.
IoC Ingester - Extracts and aggregates IoCs from threat feeds.
Mihari - Continuous OSINT-based indicator monitoring framework.
IoC Parser - Extracts indicators from security reports.
MITRE CTI - ATT&CK content expressed in STIX 2.0.
TALR - Detection rule sharing in STIX format.
Threat Dragon is a threat modeling tool rather than a CTI feed platform, so it belongs with secure design and architecture references rather than this page.
Government, ISAC, and Sharing Sources
InfraGard - FBI-affiliated public/private partnership.
CISA AIS - Automated Indicator Sharing. Treat as a historical or transition-sensitive source and verify the current program status before building new dependencies on it.
IC3 - FBI Internet Crime Complaint Center.
National Council of ISACs - Find sector-specific ISACs.
Intel Platforms
Premium intelligence providers:
Intelligence X - Search engine and archival intelligence platform.
TruSTAR was acquired by Splunk; verify current Splunk Enterprise Security, SOAR, and threat intelligence workflows before depending on old TruSTAR documentation.
IoC Feeds
MISP includes many default feeds. For the current list, use MISP OSINT feeds.
Common free feeds:
Rescure - Curated CTI feeds.
Reputation and enrichment platforms such as VirusTotal, GreyNoise, AbuseIPDB, urlscan.io, and OPSWAT MetaDefender are maintained on Threat Data.
Threat DataMalware sandboxes such as ANY.RUN, Hybrid Analysis, Joe Sandbox, Triage, Intezer, UnpacMe, and Cuckoo are maintained in DFIR sandboxing.
SandboxingResearch Blogs
Threat research groups:
Corporate security blogs:
Offensive methodology blogs such as Hakluke, PentesterLab-style content, and Null Byte fit better in Red Offensive or Web App Hacking.
Communities and Media
infosec.exchange - Primary cybersecurity Mastodon instance.
Podcasts and webcasts:
Training, YouTube channels, and labs are preserved in Training.
Training and ResourcesDeprecated or Archived Tools
CRITs - Collaborative Research Into Threats. Last updated in 2018; consider OpenCTI, MISP, or TheHive.
NSA Unfetter - Archived. Use ATT&CK Navigator and related MITRE tooling.
Malware Domain List - Degraded/no longer maintained; use URLhaus, ThreatFox, and other abuse.ch feeds.
Threatpost - Shut down in 2022 after acquisition.
TruSTAR standalone docs - Splunk acquired TruSTAR; verify current Splunk CTI/SOAR workflows.
CybOX - Legacy observable model folded into STIX 2.x.
Onion Feeds
OSINT Party Fresh Onion RSS - Fresh
.onionRSS feed. Service status can vary, and links may be illegal or harmful; verify availability, treat links as untrusted, and follow the OPSEC section.
Last updated