Threat intelligence
How SecureOPS enriches your telemetry with threat intelligence feeds.
Threat intelligence turns anonymous observables — IPs, domains, file hashes, URLs — into context. SecureOPS checks observables against multiple intel sources automatically during detection and AI triage.
Included feeds
Every SecureOPS tenant includes curated feeds covering:
- Known-malicious IPs and domains (C2 infrastructure, phishing, scanning)
- Malware file hashes
- Compromised credential notifications for your monitored domains
- Vulnerability intelligence matched against software observed in your environment
Feeds update continuously; matches are recorded on the event and factored into alert severity.
Where enrichment appears
- Alerts — matched observables are flagged with the source feed, confidence, and first/last-seen dates.
- Cases — the entity panel shows intel context for every observable in the case.
- Search — use
intel.match:trueto find historical events involving known-bad infrastructure, including activity that happened before the indicator was published (retro-matching runs daily).
Custom indicators
Add your own indicators under Settings → Threat intelligence → Custom indicators:
- Upload a CSV/STIX file or paste indicators directly.
- Set a confidence level and an expiry date.
- Optionally tag them (for example
red-team,partner-advisory) — tags appear wherever the indicator matches.
Custom indicators participate in detection and retro-matching exactly like the built-in feeds.
Connecting external platforms
If you subscribe to a commercial intel platform or participate in an ISAC, connect it under Settings → Threat intelligence → External feeds (TAXII 2.1 and REST pull are supported). External matches show the originating feed name so analysts can weigh the source.