Threat Intelligence

KnowledgeSecurity

Looks up a threat actor, malware family, ransomware family or tool by name or vendor alias in the MISP galaxy clusters, resolves a MITRE ATT&CK technique by id or name, and classifies an indicator such as an IP address, domain, URL, hash or crypto address before checking it against the catalogues and the ScamSniffer community list of scam addresses on EVM chains. It is a catalogue lookup and not a reputation service: it holds no IP, domain, URL or file reputation, no scanner telemetry and no passive DNS, so for every indicator type except an EVM address the most it can say is whether a threat catalogue mentions the indicator. Each answer names the sources it read, the ones it could not reach and the capabilities this service does not have at all, and an indicator nothing was found for comes back as unknown rather than clean. Informational only, and not a determination about an indicator, a person or an organisation.

Serves today. Built into ahel, nothing to set up.

One link, every agent. Your own credentials, stored once.

Advanced
Catalog kind
dataset
Gateway key
ahel-datasets-threat-intelligence