Cyber Threat
Intel Feed
Our own internet-facing sensors record the addresses that attack them, and every entry keeps the evidence behind it. We work out where each one comes from, who runs it, whether it hides behind Tor, and which MITRE ATT&CK techniques it maps to, then deliver all of that to the tools your team already uses.
Right now, something is scanning your network.
Brute force attempts, port scans, credential stuffing and exploit probes run every hour of every day. We do not have to quote an industry report to show you that: our own sensors are ordinary hosts nobody has a legitimate reason to touch, so everything they record is an unsolicited attack. Here is what is in the database right now.
attack events our sensors have recorded
distinct source addresses behind them
countries those addresses came from
sightings added in the past day
Read from the CTIF database when this page was built. How we collect and score · per-sensor freshness
A threat intelligence feed
that does the analysis for you.
From the second a sensor spots an address to the second it appears in your dashboard, CTIF handles everything in between. It collects the indicator, looks up what is known about it, and works out how much it should worry you. There are no manual steps and nothing left for your team to stitch together.
First-party Global Capture
Our own sensors, in more than one country, record attacks against real services, and every address arrives with the evidence that flagged it: the service hit, the log line and the time. Collection runs several times a day, and the exact freshness of each sensor is published on our status page.
Automatic Enrichment
Every address is checked against geolocation, ASN and ISP, reverse DNS, RDAP and WHOIS, Tor exit status, and the MITRE ATT&CK framework.
Hostility Scoring
Every indicator carries a hostility score from 0 to 100, so your team can sort by real risk instead of working through flat, unranked alerts.
More Services
New services beyond the core feed: packaged SIEM connectors on top of the integrations that already work, and broader threat coverage.
Our sensors sit on the routes that matter.
The sensor network is live and still growing, and every node feeds the same enrichment pipeline the moment it captures something. What the sensors see is already global:
What happens between a sensor and your dashboard.
Every address we report travels the same short path before it reaches you. Follow it from the first packet a sensor sees to the moment your tools can query it.
Capture
Sensors across the world spot hostile behaviour and flag the source address the instant they see it.
Enrich
Geolocation, ASN and ISP, reverse DNS, RDAP and WHOIS, Tor and CDN status, then a map to MITRE ATT&CK.
Score and store
Each indicator gets a hostility score from 0 to 100, then it is stored with its sighting count, first and last seen, and the reasons it was flagged.
Deliver
Pull the feed however suits you: a rate-limited REST API, STIX 2.1 bundles and a scored blocklist any firewall can fetch, every indicator carrying its hostility score. Guides cover Splunk, Palo Alto, FortiGate, MISP and OpenCTI.
Follow one attack through the pipeline.
At 03:14 UTC one of our European sensors picks up a burst of failed SSH logins, all coming from one address hammering port 22. Here is what CTIF makes of it in the next second.
Block at the perimeter and flag any successful SSH or RDP login from this ASN for review.
Plug it into your SOC tools.
CTIF delivers over open formats rather than proprietary plumbing: a REST API, STIX 2.1 bundles and a scored list served as text or CSV over an authenticated URL. Every indicator carries its hostility score, geolocation and ATT&CK mapping. Splunk, Palo Alto, FortiGate, MISP and OpenCTI each have a step-by-step guide.
A REST API today
Pull enriched, scored indicators into the tools you already run over a simple, authenticated REST API.
Hostility scoring
Every indicator carries a hostility score from 0 to 100, so your team triages by real risk instead of raw volume.
Splunk today, no app required
Schedule the scored CSV into a Splunk lookup and enrich src_ip at search time. The full recipe is in the Splunk guide.
index=firewall | lookup ctif_blocklist ip AS src_ip OUTPUT hostility_score country | where hostility_score >= 70 | table src_ip country hostility_score | sort -hostility_score
We keep adding new services.
CTIF is built to grow. We are steadily broadening what the feed covers, adding new services and threat sources so it keeps pace with what your team actually faces.
More services on the way
We are steadily broadening what CTIF covers.
Spam & relay abuse
Open relays and bulk senders that abuse mail infrastructure.
Packaged SIEM connectors
Splunk, MISP and OpenCTI work today through documented lookups, feeds and STIX. Packaged connectors come next, driven by what customers actually deploy.
Broader coverage
New threat sources and services, added as the feed keeps growing.
Priced by how much you query.
Plans scale with how many requests your team makes each day. Every tier ships the full feed and enrichment; higher tiers add API access and deeper support.
Base
For focused teams adding global context through the dashboard.
- Global sensor feed
- Full IP enrichment
- MITRE ATT&CK mapping
- Hostility scoring
- Dashboard access
- Email support
Paid in USDT on TRON (TRC20)
SMB
For growing security teams running active detection.
- Everything in Base
- REST API + STIX 2.1
- Extended sighting history
- Priority support
Paid in USDT on TRON (TRC20)
SOC
For MSSPs and 24/7 SOCs operating at scale.
- Everything in SMB
- Highest request volume
- Dedicated support channel
- Onboarding assistance
Paid in USDT on TRON (TRC20)
Start on any plan and upgrade whenever your team needs more. No need to commit to a higher tier up front. Billed monthly or annually (two months free on annual) and exclude VAT. Need a blocklist for your edge devices or a private instance? See more ways to deploy.
Service guarantee: if the API is unavailable for more than 24 consecutive hours we extend your subscription by the affected days, or refund the unused balance if you would rather leave. The response targets and availability commitments per plan are written out on the support page.
An IP blocklist for your edge, or a private instance.
Not every team consumes intelligence the same way. Push it into your network gear, or get a private, fully managed instance dedicated to your team.
Blocklist Feed
A curated blocklist you drop straight into your edge devices, firewalls, IPS and gateways. It stops common, known-bad traffic before it ever reaches your network.
- Ready for edge firewalls, IPS and gateways
- Blocks known threats upstream, before they act
- Less noise for your analysts and operations team
- Rebuilt from the feed on every pull, at a score you choose
Private Instance
A dedicated CTIF instance we spin up and run in your region, just for you. Fully managed by us, single-tenant, and isolated to your team, without the burden of hosting it yourself.
- Deployed and operated in your region
- Single-tenant, isolated to your team only
- Fully managed, no infrastructure to run
- Custom request volume and dedicated keys
Give your SOC a
head start.
Bring global, enriched and scored threat intelligence into your tools, and get ahead of the traffic that is already probing your network.
First-party sensors, MITRE ATT&CK mapping, a REST API and STIX 2.1 export.