Home / Services / Web Security / Threat intelligence

Web Security / Threat Intelligence Hub

Attacker data,
ready to use for defense.

Threat Intelligence Hub automatically collects public threat intelligence feeds licensed for commercial use and manages them in one place together with your own IOCs (indicators of compromise) and the feeds you subscribe to. It removes data that tends to cause false positives, assigns confidence scores, and delivers the results over the REST API and TAXII 2.1 / STIX 2.1. Combined with WAAP, the list of malicious IPs becomes your WAF rules directly.

Challenges

Sound familiar?

Scattered feeds

Free blocklists and subscribed feeds each live separately, in different formats and with different update cycles, so they never make it into day-to-day operations.

Too risky to use because of false positives

Using a list that includes CDN or cloud provider IPs as-is ends up blocking legitimate traffic too.

Your own findings go unused

IOCs gathered during incident response stay with the individual responder and never reach the organization's defenses.

Features

Threat intelligence key features

01Automatic collection of public feeds

Ingests feeds licensed for commercial use and redistribution every 3 hours, including Spamhaus DROP, FireHOL, CINS Army, Tor exit nodes, abuse.ch (URLhaus, MalwareBazaar, Feodo Tracker, ThreatFox, SSL Blacklist), Emerging Threats and blocklist.de.

02Many IOC types

Handles IP addresses (CIDR), domains, URLs, file hashes (SHA-256 / SHA-1 / MD5) and TLS fingerprints (JA3 / JA4) in a single format.

03Noise removal and confidence scores

Automatically removes ranges that commonly cause false positives, such as CDN edge IPs, and assigns severity, confidence (0-100) and classification labels per feed.

04Register your own IOCs

Register IOCs from incident response and other work one at a time or in bulk, from the console or the API. Set an expiration date and they expire automatically.

05Ingest subscribed feeds

Ingest and combine the feeds you subscribe to over HTTP, TAXII 2.1 or MISP. Set the fetch interval from 1 to 24 hours, and run connection tests or immediate fetches. Credentials are stored encrypted and never shown in the console or API.

06Delivery over TAXII 2.1 / STIX 2.1

Serves the combined data as a TAXII 2.1 server, so SIEMs and threat intelligence platforms can read it over a standard protocol. You can also write to a collection dedicated to your organization.

07Lookup API and console

Check instantly from the API or console whether an IP or hash is on the list. The dashboard shows additions per feed and trends in your own IOCs.

08False-positive exclusions and audit logs

Register values that are harmless for your organization as exclusions. For results hidden by an exclusion, you can see which exclusion hid them. Actions taken with each API key are recorded in the audit log.

How it works

Collect, refine,
and deliver to your defenses

Threat data is not useful just because you collected it. Threat Intelligence Hub normalizes multiple sources into one format, removes the causes of false positives, and delivers the data in the form your systems consume.

COLLECT

Collect

Ingests public feeds, your own IOCs and subscribed feeds into a common format covering IPs, domains, URLs, hashes and TLS fingerprints.

REFINE

Refine

Removes ranges that include legitimate traffic, such as CDN edges, assigns confidence and classification, and applies your organization's exclusions. Expired values are retired automatically.

DELIVER

Deliver

Delivers to SIEM and EDR over the REST API and TAXII 2.1, and applies the data to WAAP automatically as WAF rules, using a confidence threshold you specify.

With WAAP

Turn the malicious IP list
directly into WAF rules

Combined with WAAP, the malicious IPs collected by Threat Intelligence Hub are applied automatically as rules in your AWS WAF. You choose per policy the minimum confidence to use and whether to include Tor exit nodes.

MIN CONFIDENCE

Confidence threshold

The default is confidence 80 or higher. Adjust how certain the data must be per policy, anywhere from 50 to 100.

COUNT → BLOCK

Start in count mode

The default is count. Confirm how many requests actually match, then switch to block.

JA3

TLS fingerprints

Malicious TLS fingerprints are used in WAAP detection and help track attacks that continue while switching IPs.

FAIL SAFE

Protection stays if fetching fails

If fetching the data fails, your existing WAF rules stay as they are. Updates run every 3 hours, and immediately when a policy changes.

Please note: Applying data to WAAP requires subscriptions to both Threat Intelligence Hub and WAAP.

Specifications

Scope and delivery

IOC types
  • IP / CIDR, domain, URL, SHA-256 / SHA-1 / MD5, JA3 / JA4
Ingestion
  • Public feeds (automatic, every 3 hours)
  • Your own IOCs, individually or in bulk (with expiration)
  • Subscribed feeds (HTTP / TAXII 2.1 / MISP, up to 10 feeds)
Delivery
  • REST API (API key authentication)
  • TAXII 2.1 / STIX 2.1
  • Automatic application to WAAP WAF rules
Management
  • False-positive exclusions (per organization)
  • Audit logs

Please note: The data delivered is based on the content of the collected feeds. The service does not provide original research or analysis reports. Because no public JA4 feeds exist, JA4 covers only values you register yourself.

Getting started

Getting started

  1. Get started

    Enable the service in the console and public feed data is available right away.

  2. Add your own data

    If needed, register your own IOCs and the feeds you subscribe to.

  3. Put it to use

    Issue an API key and read the data from your SIEM or TAXII client, or enable application in your WAAP policy.

FAQ

FAQ

What can I do by combining it with WAAP?

You can apply the malicious IP list to your WAAP policies automatically, with a confidence threshold you specify (subscriptions to both are required). Start in count mode to check the impact, then switch to block.

Does it work with my existing SIEM?

Yes. Any product that supports TAXII 2.1 / STIX 2.1 can read the data over the standard protocol. Lookups and list retrieval over the REST API are also available.

Works well with

Threat intelligence — details and demo requests

Our team will explain deployment options and pricing for your environment.