CTI
Threat intelligence
CTI helps read technical indicators in context and turn them into defensive decisions. The workflows here focus on passive checking, verification, and reporting.
First steps
- Name the indicator type: domain, IP, URL, hash, or CVE.
- Collect date and context from passive sources.
- Write the false-positive risk.
- Recommend a defensive action with confidence.
Limits
- No exploit or proof-of-concept execution guidance.
- Do not test systems without authorization.
- Do not download or run suspicious files on your main system.
What this field covers
A quick scope view.
IOC checks
CVE verification
Domain and IP reputation
Malware-report reading
Defensive notes
Related source collections
Good places to start in this field.
Threat intelligence
AlienVault OTX
Open threat exchange for pulses, indicators, and community threat intelligence.
Open sourceMalware intelligence
ANY.RUN
Interactive malware sandbox and public task repository.
Open sourceThreat intelligence
Awesome Threat Intelligence
A broad GitHub list of threat-intelligence datasets, tools, platforms, and learning resources.
Open sourceCVE and vulnerability tracking
CISA Known Exploited Vulnerabilities Catalog
Authoritative CISA catalog of vulnerabilities known to be exploited in the wild.
Open sourceCVE and vulnerability tracking
CVE.org
Official CVE program site for CVE records and CNA information.
Open sourceDomain and DNS intelligence
DNSDumpster
Passive DNS and domain mapping service for public DNS discovery.
Open source