For the complete documentation index, see llms.txt. This page is also available as Markdown.

Intel Feeds and Sources

Use this page for cyber threat intelligence feeds, standards, sharing platforms, source collections, and research sources. Indicator reputation and enrichment lookups live in Threat Data; sandboxing and malware behavior analysis live in DFIR.

Intelligence Lifecycle: Deprecation and Priority

Not all indicators are equal. A malware hash tied to a confirmed intrusion usually carries more evidentiary weight than an IP address observed scanning the internet. Indicator priority depends on fidelity, corroborating context, and where the indicator sits in the attack chain.

Indicators also decay. IP addresses, domains, and infrastructure relationships can change quickly; hashes and well-described behaviors usually age better. When using feed data, track first-seen time, last-seen time, source reliability, and whether the indicator still matches current adversary behavior.

Threat Intelligence Frameworks

  • MITRE ATT&CK - Knowledge base of adversary tactics and techniques.

  • Cyber Kill Chain - Lockheed Martin's seven-stage model for attack progression.

  • Diamond Model - Intrusion analysis model built around adversary, capability, infrastructure, and victim.

Indicator Standards and Formats

  • OASIS CTI Technical Committee - Standards body for STIX and TAXII.

  • STIX 2.x - Structured Threat Information Expression for machine-readable CTI.

  • TAXII 2.x - API protocol for exchanging STIX threat intelligence.

  • OpenIOC - Mandiant framework for sharing threat intelligence in a machine-digestible format.

  • CybOX - Legacy cyber observable specification. CybOX concepts were folded into STIX 2.x observables.

Daily Checkers and Roundups

DFIR-specific news and case studies are preserved in the DFIR section.

Blue - DFIR: Digital Forensics and Incident Response

CTI Resource Collections

Threat Intelligence Platforms and Tools

  • MISP - Open-source threat sharing platform for storing, correlating, enriching, and distributing indicators.

  • OpenCTI - Open-source CTI platform built around STIX 2.1 concepts.

  • Yeti - Platform for organizing observables, IOCs, TTPs, and threat knowledge.

  • IntelOwl - Open-source analyzer and enrichment platform for files, IPs, domains, and other observables.

  • S-TIP - Threat intelligence platform focused on CTI sharing workflows.

  • TheHive - Incident response and case management platform that integrates with MISP and other CTI tools.

  • Cortex - Observable analysis and active response engine.

  • Harpoon - OSINT and threat intelligence CLI.

  • IoC Ingester - Extracts and aggregates IoCs from threat feeds.

  • Mihari - Continuous OSINT-based indicator monitoring framework.

  • IoC Parser - Extracts indicators from security reports.

  • MITRE CTI - ATT&CK content expressed in STIX 2.0.

  • TALR - Detection rule sharing in STIX format.

Threat Dragon is a threat modeling tool rather than a CTI feed platform, so it belongs with secure design and architecture references rather than this page.

Government, ISAC, and Sharing Sources

Intel Platforms

Premium intelligence providers:

TruSTAR was acquired by Splunk; verify current Splunk Enterprise Security, SOAR, and threat intelligence workflows before depending on old TruSTAR documentation.

IoC Feeds

MISP includes many default feeds. For the current list, use MISP OSINT feeds.

Common free feeds:

Reputation and enrichment platforms such as VirusTotal, GreyNoise, AbuseIPDB, urlscan.io, and OPSWAT MetaDefender are maintained on Threat Data.

Threat Data

Malware sandboxes such as ANY.RUN, Hybrid Analysis, Joe Sandbox, Triage, Intezer, UnpacMe, and Cuckoo are maintained in DFIR sandboxing.

Sandboxing

Research Blogs

Threat research groups:

Corporate security blogs:

Offensive methodology blogs such as Hakluke, PentesterLab-style content, and Null Byte fit better in Red Offensive or Web App Hacking.

Communities and Media

Podcasts and webcasts:

Training, YouTube channels, and labs are preserved in Training.

Training and Resources

Deprecated or Archived Tools

  • CRITs - Collaborative Research Into Threats. Last updated in 2018; consider OpenCTI, MISP, or TheHive.

  • NSA Unfetter - Archived. Use ATT&CK Navigator and related MITRE tooling.

  • Malware Domain List - Degraded/no longer maintained; use URLhaus, ThreatFox, and other abuse.ch feeds.

  • Threatpost - Shut down in 2022 after acquisition.

  • TruSTAR standalone docs - Splunk acquired TruSTAR; verify current Splunk CTI/SOAR workflows.

  • CybOX - Legacy observable model folded into STIX 2.x.

Onion Feeds

  • OSINT Party Fresh Onion RSS - Fresh .onion RSS feed. Service status can vary, and links may be illegal or harmful; verify availability, treat links as untrusted, and follow the OPSEC section.

Grey - Privacy/TOR/OPSEC

Last updated