Home / Services / Web Security / Threat intelligence
Web Security / Threat Intelligence HubAttacker data,
ready to use for defense.
Threat Intelligence Hub automatically collects public threat intelligence feeds licensed for commercial use and manages them in one place together with your own IOCs (indicators of compromise) and the feeds you subscribe to. It removes data that tends to cause false positives, assigns confidence scores, and delivers the results over the REST API and TAXII 2.1 / STIX 2.1. Combined with WAAP, the list of malicious IPs becomes your WAF rules directly.
Challenges
Sound familiar?
Scattered feeds
Free blocklists and subscribed feeds each live separately, in different formats and with different update cycles, so they never make it into day-to-day operations.
Too risky to use because of false positives
Using a list that includes CDN or cloud provider IPs as-is ends up blocking legitimate traffic too.
Your own findings go unused
IOCs gathered during incident response stay with the individual responder and never reach the organization's defenses.
Features
Threat intelligence key features
01Automatic collection of public feeds
Ingests feeds licensed for commercial use and redistribution every 3 hours, including Spamhaus DROP, FireHOL, CINS Army, Tor exit nodes, abuse.ch (URLhaus, MalwareBazaar, Feodo Tracker, ThreatFox, SSL Blacklist), Emerging Threats and blocklist.de.
02Many IOC types
Handles IP addresses (CIDR), domains, URLs, file hashes (SHA-256 / SHA-1 / MD5) and TLS fingerprints (JA3 / JA4) in a single format.
03Noise removal and confidence scores
Automatically removes ranges that commonly cause false positives, such as CDN edge IPs, and assigns severity, confidence (0-100) and classification labels per feed.
04Register your own IOCs
Register IOCs from incident response and other work one at a time or in bulk, from the console or the API. Set an expiration date and they expire automatically.
05Ingest subscribed feeds
Ingest and combine the feeds you subscribe to over HTTP, TAXII 2.1 or MISP. Set the fetch interval from 1 to 24 hours, and run connection tests or immediate fetches. Credentials are stored encrypted and never shown in the console or API.
06Delivery over TAXII 2.1 / STIX 2.1
Serves the combined data as a TAXII 2.1 server, so SIEMs and threat intelligence platforms can read it over a standard protocol. You can also write to a collection dedicated to your organization.
07Lookup API and console
Check instantly from the API or console whether an IP or hash is on the list. The dashboard shows additions per feed and trends in your own IOCs.
08False-positive exclusions and audit logs
Register values that are harmless for your organization as exclusions. For results hidden by an exclusion, you can see which exclusion hid them. Actions taken with each API key are recorded in the audit log.
How it works
Collect, refine,
and deliver to your defenses
Threat data is not useful just because you collected it. Threat Intelligence Hub normalizes multiple sources into one format, removes the causes of false positives, and delivers the data in the form your systems consume.
Collect
Ingests public feeds, your own IOCs and subscribed feeds into a common format covering IPs, domains, URLs, hashes and TLS fingerprints.
Refine
Removes ranges that include legitimate traffic, such as CDN edges, assigns confidence and classification, and applies your organization's exclusions. Expired values are retired automatically.
Deliver
Delivers to SIEM and EDR over the REST API and TAXII 2.1, and applies the data to WAAP automatically as WAF rules, using a confidence threshold you specify.
With WAAP
Turn the malicious IP list
directly into WAF rules
Combined with WAAP, the malicious IPs collected by Threat Intelligence Hub are applied automatically as rules in your AWS WAF. You choose per policy the minimum confidence to use and whether to include Tor exit nodes.
Confidence threshold
The default is confidence 80 or higher. Adjust how certain the data must be per policy, anywhere from 50 to 100.
Start in count mode
The default is count. Confirm how many requests actually match, then switch to block.
TLS fingerprints
Malicious TLS fingerprints are used in WAAP detection and help track attacks that continue while switching IPs.
Protection stays if fetching fails
If fetching the data fails, your existing WAF rules stay as they are. Updates run every 3 hours, and immediately when a policy changes.
Please note: Applying data to WAAP requires subscriptions to both Threat Intelligence Hub and WAAP.
Specifications
Scope and delivery
| IOC types |
|
|---|---|
| Ingestion |
|
| Delivery |
|
| Management |
|
Please note: The data delivered is based on the content of the collected feeds. The service does not provide original research or analysis reports. Because no public JA4 feeds exist, JA4 covers only values you register yourself.
Getting started
Getting started
Get started
Enable the service in the console and public feed data is available right away.
Add your own data
If needed, register your own IOCs and the feeds you subscribe to.
Put it to use
Issue an API key and read the data from your SIEM or TAXII client, or enable application in your WAAP policy.
FAQ
FAQ
What can I do by combining it with WAAP?
You can apply the malicious IP list to your WAAP policies automatically, with a confidence threshold you specify (subscriptions to both are required). Start in count mode to check the impact, then switch to block.
Does it work with my existing SIEM?
Yes. Any product that supports TAXII 2.1 / STIX 2.1 can read the data over the standard protocol. Lookups and list retrieval over the REST API are also available.
Works well with
Threat intelligence — details and demo requests
Our team will explain deployment options and pricing for your environment.