Threat intelligence

How SecureOPS enriches your telemetry with threat intelligence feeds.

Threat intelligence turns anonymous observables — IPs, domains, file hashes, URLs — into context. SecureOPS checks observables against multiple intel sources automatically during detection and AI triage.

Included feeds

Every SecureOPS tenant includes curated feeds covering:

  • Known-malicious IPs and domains (C2 infrastructure, phishing, scanning)
  • Malware file hashes
  • Compromised credential notifications for your monitored domains
  • Vulnerability intelligence matched against software observed in your environment

Feeds update continuously; matches are recorded on the event and factored into alert severity.

Where enrichment appears

  • Alerts — matched observables are flagged with the source feed, confidence, and first/last-seen dates.
  • Cases — the entity panel shows intel context for every observable in the case.
  • Search — use intel.match:true to find historical events involving known-bad infrastructure, including activity that happened before the indicator was published (retro-matching runs daily).

Custom indicators

Add your own indicators under Settings → Threat intelligence → Custom indicators:

  1. Upload a CSV/STIX file or paste indicators directly.
  2. Set a confidence level and an expiry date.
  3. Optionally tag them (for example red-team, partner-advisory) — tags appear wherever the indicator matches.

Custom indicators participate in detection and retro-matching exactly like the built-in feeds.

Connecting external platforms

If you subscribe to a commercial intel platform or participate in an ISAC, connect it under Settings → Threat intelligence → External feeds (TAXII 2.1 and REST pull are supported). External matches show the originating feed name so analysts can weigh the source.

On this page