Available Premium Feeds
The table below lists all premium feeds available in ThreatStream and indicates whether each feed requires activation credentials or is available through a free trial. These feeds can be activated in the App Store. For details on activating and managing premium feeds, refer to Managing Premium Feeds.
Filter:
| Feed Name | Description | Credential/Trial | Notes |
|---|---|---|---|
| Abusix Threat Intelligence | Identifies compromised IPs via specialized mechanisms and monitors high volumes of malicious emails to determine responsible IPs. | Trial | |
| Anomali PDRP Enhanced | Monitor the dark web for leaked employee credentials and protect your brand from lookalike domains, fake social accounts, and counterfeit apps impersonating your business. | Credential | For activation details, refer to Activating the Anomali PDRP Enhanced Feed. |
| Anomali C2 Detection | Provides observables of active command-and-control servers and infrastructure associated with your IP space. Powered by RedSense. | Credential | The feed must be configured to monitor IPs of your organization. Contact your Customer Support Manager (CSM) to configure and activate the feed before use. |
| Anomali Credential Monitoring | Continuously monitors employee credentials surfaced on the dark web, underground forums, and adversary infrastructure. Delivers targeted alerts enabling your team to force resets before credentials are weaponized. Powered by RedSense. | Credential | The feed must be configured to monitor corporate email domains of your organization. Contact your Customer Support Manager (CSM) to configure and activate the feed before use. |
| Anomali Early Warning Alerts | Alerts when initial access brokers list access to your organization on underground forums and markets. Powered by RedSense. | Credential | The feed must be configured to monitor domains of your organization. Contact your Customer Support Manager (CSM) to configure and activate the feed before use. |
| Anomali Premium Digital Risk Protection | Provides a dashboard and feed of threat models and observables focused on threats to your organization and digital assets. Includes leaked credentials, domain registrations, rogue apps, leaked documents, phishing URLs, and more. | Credential | For more details, refer to Anomali Premium Digital Risk Protection (PDRP). |
| Anomali Threat Research Premium | Provides observables, bulletins, actors, campaigns, TTPs, and signatures from the Anomali Threat Research Team. Also includes dark web data pertaining to actor activity and intelligence collected from underground forums. | Credential | |
| Bfore.Ai - PreCrime Network | Predicts malicious domain names as their behavior changes using patented technology combined with hyperscale observation infrastructure. Delivers knowledge of the attack vector days to weeks in advance. | Credential | |
| Bitdefender Intelligence - C2 Servers | Delivers observables (IPs and domains) used for command-and-control (C2), with associated full threat context such as actor and threat-family attribution, TTP mapping, targeted industry and country, severity, and confidence scoring. | Trial | |
| Bitdefender Intelligence - Mobile | Delivers observables (IPs, domains, and file hashes) associated with Android malware, with complete threat context including actor and threat-family attribution, TTPs, targeted industry and country, severity, and confidence scoring. | Trial | |
| Bitdefender Intelligence - Phishing and Fraud | Delivers observables (domains and URLs) for phishing and fraud, together with associated full threat context including actor, threat-family, and TTP attribution. | Trial | |
| Bitdefender Intelligence - Ransomware | Delivers observables (IPs, domains, and file hashes) associated with ransomware, with complete threat context including actor and threat-family attribution, TTPs, targeted industry and country, severity, and confidence scoring. | Trial | |
| Certego Data Feeds | Provides EU- and Italy-focused threat intelligence, categorizing malicious IPs and domains by type and reliability. Powered by Quokka, delivers real-time insights, blocks threats, and improves efficiency for MDR and MSSP services. | Credential | |
| Check Point Exposure Management IoC Feed | Provides threat intelligence from OSINT and deep/dark web sources. Delivers a daily feed and query API with risk-scored observables to enrich security tools and threat intelligence platforms. | Credential | |
| Check Point Exposure Management IoC Intelligence | Delivers real-world threat data from global firewalls, Threat Emulation, and email security. Every observable represents a confirmed attack blocked by ThreatCloud AI. | Credential | |
| Cofense Intelligence | Provides a high-fidelity, human-verified phishing threat intelligence service with accurate and timely alerts to strengthen your organization's ability to identify and respond to phishing attacks. | Trial | |
| Cofense Triage | Surfaces phishing threat observables — including URLs, hostnames, hashes, senders, and subjects — designated by Cofense Triage security analysts. Observables are actionable based on threat level from suspicious emails reported by employees. | Credential | |
| Cognyte: Luminar IOCs, Leaked Credentials and AI Cyber Feeds | Enables brand monitoring, threat and risk analysis, adversary monitoring, and malware intelligence. | Credential | You must obtain your Account ID, Client ID, and Client Secret to activate the feed. Additionally, you must add domains, profiles, and mobile apps that you want the feed to monitor on the Assets page. |
| CrowdStrike Falcon X: Threat Intelligence | Provides actionable insights into top threat actors, attack vectors, and threat intelligence trends. Seamlessly integrates to automatically inject all observables into your security infrastructure. | Credential | |
| CrowdStrike Threat Reports | Delivers groundbreaking intelligence reports presenting customers and the global cybersecurity community with the latest developments and defenses for an increasingly dangerous threat landscape. | Credential | |
| CSIS Financial Threat Intelligence | Provides malware observables targeting the global financial sector, including sinkhole domains, email names, drive-by websites, malware hashes, C&C servers, and web inject and drop servers. | Trial | |
| Cybersixgill Actionable Alerts | Monitors underground activity regarding key assets (names, IP addresses, domains, CVEs, and third-party BINs) and delivers real-time alert notifications on incoming threats. | Credential | |
| Cybersixgill Darkfeed™ Premium | Leverages Cybersixgill's premium underground intelligence collection capabilities for real-time collection and advanced warning about observables, helping you maintain an edge against unknown threats. | Credential | |
| Cybersixgill Reports Premium | Provides bespoke threat intelligence with detailed insight into the latest headlines dominating the cybersecurity space, harnessing Cybersixgill's threat intelligence from the deep and dark web to illuminate current cyber events and trends. | Trial | |
| Dataminr Pulse | Brings leading AI-powered real-time alerting into Anomali, fitting seamlessly into your workflows and enabling rapid identification and mitigation of emerging threats for faster time to detection and response. | Credential | You must obtain your Dataminr Pulse Client ID and Client Secret to activate the feed. |
| Digital Shadows | Monitors and manages the digital risk of an organization across the widest range of data sources within the visible, deep, and dark web to protect the organization's business and reputation. | Credential | |
| DomainTools - Iris Detect | Monitors internet infrastructure using DomainTools' discovery engine and domain data to detect and risk-score new domains within minutes, helping brand, fraud, and security teams respond quickly. | Credential | |
| Doppel | Provides threat intelligence from Doppel covering brand impersonation, phishing infrastructure, and related external risk signals to support detection, investigation, and response workflows. | Credential | |
| Dragos | Delivers threat intelligence reports that enhance ICS cybersecurity through greater threat awareness, expert analysis, and actionable recommendations on threats, vulnerabilities, behaviors, and key observables. | Credential | |
| Dragos - Trial | Delivers threat intelligence reports that enhance ICS cybersecurity through greater threat awareness, expert analysis, and actionable recommendations on threats, vulnerabilities, behaviors, and key observables. This is a 30-day trial. | Trial | |
| FalconFeeds | Provides real-time threat intelligence from dark web, ransomware groups, and hacker sources. Trusted by governments and enterprises to detect, monitor, and respond to cyber threats globally. | Credential | |
| Feedly for Threat Intelligence | Ingests threat reports, observables, threat actors, CVEs, TTPs, and malware discovered by Feedly into Anomali. | Credential | When activating the feed, enter your primary stream ID in the Feedly Stream ID field. Then, list any additional stream IDs in the Secondary Feedly Stream ID field, separating them with commas. The Feedly for Threat Intelligence feed creates a folder for each stream ID and assigns a corresponding tag name to the intelligence on ThreatStream. |
| Flashpoint Automated Alerting | Matches conversations from illicit online communities with an organization's areas of concern and automatically delivers these matches to the user, ensuring timely notifications that identify potential risks. | Credential | |
| Flashpoint Compromised Credentials | Provides unique collections of compromised enterprise accounts and passwords to help flag accounts, reset employee passwords, and restrict permissions — preventing actors from accessing confidential or personally identifiable information (PII). | Credential | |
| Flashpoint Intelligence Reports | Delivers Flashpoint's most critical findings, hand-picked, prioritized, and packaged in intra-daily intelligence reports. | Credential | |
| Flashpoint Technical Indicators | Provides observables gathered by Flashpoint analysts from malware events and exploits observed in the wild. | Credential | |
| Flashpoint VulnDB | Integrates data from Flashpoint's VulnDB product, offering thousands of unique vulnerabilities not found in common databases. Provides the richest, most complete vulnerability intelligence to address risk points across your organization. | Credential | |
| Flexera Software Vulnerability Research | Integrates real-time vulnerability intelligence into Anomali, enabling correlation of vulnerabilities with active exploits, prioritization based on threat activity, and improved remediation workflows with actionable insights. | Trial | |
| Fox-IT InTELL | Tracks global criminal activity and provides relevant, timely intelligence on key cyber threats. Includes structured threat information linked to the latest malware developments, criminal infrastructure, and targeted attacks. | Trial | |
| Fraudlogix IP intelligence | Identifies infected devices, bots, and malware. Prevents DDoS attacks, unauthorized logins, network breaches, and more. Endpoint data is gathered from 640 million users monthly via JavaScript sensors placed on 12 million URLs. | Trial | |
| Google Threat Intelligence | Unites Google's global telemetry, Mandiant expertise, and VirusTotal data with AI to deliver real-time insights on threats, helping organizations detect, investigate, and respond faster. | Credential | When activating the feed, you must enter your GTI user ID, API key, and daily request limit (optional). The daily request limit helps to control your API usage. Once the specified limit is reached, intelligence ingestion pauses automatically and resumes the following day. If no maximum request limit is specified, ingestion will continue without a daily cap. |
| Google Threat Intelligence - Live Yara Rule Hunting | Notifies you immediately when a file matching your own YARA rules, including internal documents, is uploaded to Google Threat Intelligence, with results delivered straight into ThreatStream. | Credential | |
| GreyNoise - Benign IPv4 Scanner Feed | Contains internet scanners observed and classified as benign by GreyNoise. | Credential | |
| GreyNoise - Malicious IPv4 Scanner Feed | Collects, analyzes, and labels data on IPs that scan the internet and saturate security tools with noise. Contains internet scanners observed by GreyNoise and classified as malicious based on their behavior. | Credential | |
| Group-IB Anti-Phishing | Monitors for adversaries attacking your customers. Provides unlimited identification, automated collection of credentials, collection of phishing kits, drop email accounts, and takedowns of phishing infrastructure. | Credential | |
| Group-IB ASM | Uncovers and secures your external attack surface with Group-IB's Attack Surface Management. | Credential | |
| Group-IB DBR | Detects and disrupts impersonation, fraud, and data leaks with Group-IB's Digital Risk Protection. | ||
| Group-IB Threat Intelligence | Provides high-fidelity intelligence curated by a team with 16 years of experience fighting cybercrime. Includes credentials from botnets, C&C tracking, new campaigns by APT groups such as Lazarus, Cobalt, and Silence, and much more. | Credential | |
| IBM X-Force | Contains the latest threat information findings across X-Force investigations and research. Provides OSINT advisories, malware analysis reports, threat group profiles, and threat activity observables — approximately 15 reports per week. | Trial | |
| iDefense | Provides a curated list of vetted observables via the Accenture CTI Threat Indicator Service, enabling customers to identify, divert, and/or block traffic from malicious sources. | Trial | |
| Intel 471 - Adversary Intelligence (Base) | Provides premier cybercrime intelligence focused on infiltrating and maintaining access to closed sources where threat actors collaborate, communicate, and plan cyberattacks. Subscription-based for Intel 471 Base Package clients. | Trial | |
| Intel 471 - Adversary Intelligence (Gold/Platinum) | Provides premier cybercrime intelligence focused on infiltrating and maintaining access to closed sources where threat actors collaborate, communicate, and plan cyberattacks. Subscription-based for Intel 471 Gold and Platinum clients. | Trial | |
| Intel 471 - Adversary Intelligence (Silver) | Provides premier cybercrime intelligence focused on infiltrating and maintaining access to closed sources where threat actors collaborate, communicate, and plan cyberattacks. Subscription-based for Intel 471 Silver clients. | Trial | |
| Intel 471 - Breach Alerts | Delivers near-real-time alerts of confirmed or suspected breaches surfaced from Intel 471's HUMINT collection across underground forums, marketplaces, and chat channels, with victim attribution and threat actor context. | Credential | |
| Intel 471 - Credential Intelligence | Continuously collects data from tens of millions of unique data points to enable searching, filtering, monitoring, and alerting on compromised credentials of relevance. Compromised credentials are a valuable commodity in the underground. | Credential | |
| Intel 471 - FINTEL Reports | Delivers finished intelligence products from Intel 471 analysts, including intelligence bulletins, threat actor profiles, Underground Pulse, Underground Perspective, and whitepapers covering strategic and operational topics. | Credential | |
| Intel 471 - Geopolitical Reports | Provides analyst-curated insights on global events, conflicts, policy shifts, and nation-state activity, organized via Intel 471's SEMPLICE framework with country risk scoring to link geopolitical dynamics to cyber threats. | Credential | |
| Intel 471 - Information Reports | Delivers tactical and operational intelligence reports from Intel 471's globally dispersed HUMINT research team, derived from direct engagement with threat actors and observation of underground forums, markets, and channels. | Credential | |
| Intel 471 - Malware Intelligence | Provides in-depth analysis of top criminal malware families, covering features, network traffic, code samples, configuration extraction, control servers, encryption keys, campaign IDs, and detection and decoding guidance. | Credential | |
| Intel 471 - Malware Intelligence (Silver/Gold/Platinum) | Provides early access to malware observables with high confidence, timely and rich context curated from Intel 471's industry-leading access in the cybercriminal underground. | Trial | |
| Intel 471 - Spot Reports | Delivers short, time-sensitive reports providing breaking news and observations on notable underground events, threat actors, malware activity, campaigns, and possible breach observables as they emerge. | Credential | |
| Intel 471 - Vulnerability Intelligence | Provides analyst-driven assessments of priority vulnerabilities, focusing on precursors to exploitation in the wild. Purposefully designed to deliver relevant and timely intelligence about the adversary scenario. | Trial | |
| Intel 471 - Vulnerability Reports | Tracks significant vulnerabilities through their underground lifecycle — disclosure, weaponization, productization, and exploitation — to support patch prioritization and risk-based remediation. | Credential | |
| Intel 471 Verity - Credential Intelligence | Surfaces compromised credentials affecting employees, VIPs, customers, and third parties — sourced from infostealer logs, breach dumps, and underground listings — for account takeover prevention and exposure remediation. | Credential | |
| Intel 471 Verity - Watcher Alerts | Delivers real-time alerts triggered by customer-defined keyword, forum, actor, and asset watchers running continuously across Intel 471's underground collection in text, images, and logos for proactive threat monitoring. | Credential | |
| LastInfoSec Cyber Threat Intelligence | Provides a comprehensive CTI feed that makes it easy to detect internal and external threats likely to target your information system. Includes a library of 6 million observables, over 5,000 new daily qualified markers, and over 3,000 different sources. | Credential | |
| Malware Patrol - Evaluation | Provides a sample of observables sourced by a team dedicated to threat intelligence since 2005. | Trial | |
| Malware Patrol - Malicious Campaigns | Provides essential observables from current malware campaigns, curated by a team dedicated to collecting and analyzing threat intelligence since 2005. | Trial | |
| Mandiant DTM | Monitors open, deep, and dark web sources to detect data leaks, brand abuse, credential exposure, and ransomware threats in near real-time using Mandiant's threat intelligence and machine learning. | Credential | |
| Mandiant v4 | Provides access to contextually rich threat intelligence from Mandiant, including observables, threat actors, malware families, and finished intelligence reports. | Credential | |
| Mandiant v4 (non OSINT) | Provides access to contextually rich threat intelligence from Mandiant — featuring no OSINT data — including observables, threat actors, malware families, and finished intelligence reports. | Credential | |
| Mimecast US Region Threat Feed | Provides threat intelligence data from attacks observed by Mimecast grids around the world, helping organizations identify and mitigate sophisticated attacks. | Trial | |
| Mobile Threat Intel (MTI) | Leverages ThreatFabric's expertise in mobile threat intelligence. Enables banks to track mobile banking malware campaigns targeting their apps and import information reports on malware families and their evolution. | Trial | |
| Proofpoint - ET Intel IP & Domain Reputation List | Provides actionable threat intelligence feeds to identify IPs and domains involved in suspicious and malicious activity. Threat intelligence is based on threat actors and behavior observed in the wild by Proofpoint ET Labs. | Trial | |
| Proofpoint - Targeted Attack Protection (TAP) | Helps detect, mitigate, and block advanced threats that target people through email, including attacks that use malicious attachments and URLs to install malware or trick users into sharing passwords and sensitive information. | Credential | See the Connected Apps menu on the Proofpoint TAP Dashboard to create the credentials needed to activate the Proofpoint TAP feed. |
| Q6 Cyber e-Crime Intelligence | Monitors marketplaces, forums, private chat platforms, botnets, and malware networks where cybercriminals operate. Delivers significant ROI through reduction of fraud losses and helps transform operations from reactive to proactive. | Trial | |
| RANE Risk Intelligence | Provides threat intelligence and analysis. | Credential | |
| Recorded Future - Default Risk List | Helps security teams make faster, more confident decisions with integrated real-time intelligence. Provides risk lists with context-rich observables for IPs, domains, URLs, and file hashes. | Credential | A Recorded Future API token is required for feed activation. |
| Recorded Future - Large Risk List | Helps security teams make faster, more confident decisions with integrated real-time intelligence. Provides expanded risk lists with context-rich observables for IPs, domains, URLs, and file hashes. | Credential | A Recorded Future API token is required for feed activation. |
| Recorded Future Alerts | Ingests Recorded Future alerts and playbook alerts as Anomali ThreatStream incidents. | Credential | |
| Recorded Future Analyst Notes | Ingests Insikt Group notes (Recorded Future threat research) into Anomali ThreatStream. Includes current intelligence assessments, malware analysis, threat actor profiles, and TTP leads published by Insikt Group. | Credential | A Recorded Future API token is required for feed activation. |
| Recorded Future Vulnerability Risk List | Provides Recorded Future vulnerability risk lists to enrich CVE data, enabling alerts and patch prioritization. | Credential | A Recorded Future API token is required for feed activation. |
| Red Sky Alliance | Provides Red Sky Alliance cyber intelligence, including malicious IPs and domains. | Trial | |
| Resecurity | Provides a live observable/IOA feed for TIP/SIEM integration, including malicious activity, threat actors, ransomware, and espionage. Based on 254 million IPs and dark web research. | Trial | |
| Resonance by spiderSilk | Provides feeds from the Resonance platform. | Credential | |
| ReversingLabs - Ransomware and Related Tools Intel List | Provides a timely and curated threat intelligence list containing recent observables extracted from ransomware and the tools used to deploy ransomware, suitable for threat hunting or deployment to security controls. | Trial | |
| ReversingLabs TitaniumCloud Threat Intelligence ELMA Feed | Provides observables for exploits and Linux, macOS, and Android-based malware. One of more than 20 diverse ReversingLabs feeds. | Trial | |
| SecAI CTI | Provides full-coverage, high-fidelity, context-rich, and up-to-date threat intelligence API services dedicated to helping SecOps teams work more efficiently on compromise detection and alert noise reduction. | Trial | |
| Secure Malware Analytics | Provides advanced malware analysis and global threat intelligence. | Trial | |
| SEKOIA.IO Threat Intelligence | Provides an all-in-one feed including SEKOIA exclusive intelligence and the best of OSINT. Includes plaintext reports to explain current developments and delivers observables from 100+ trackers on threat actors and malware. Uses STIX, with every object carrying context and relationships. | Trial | |
| Silobreaker Threat Feeds | Provides automated and highly customizable feeds from structured and unstructured open, partner, and dark web sources. Covers hundreds of thousands of sources with support for additional content on a per-client basis. | Trial | |
| SpyCloud Enterprise Protection | Delivers breach alerts directly into Anomali via SpyCloud's Enterprise API. Detects exposed credentials and enables response to fraud, account takeover, and ransomware threats before attackers can act. | Credential | |
| SWIFT ISAC threat intelligence feed | Provides a companion threat intelligence feed for SWIFT customers via the SWIFT ISAC. As part of the SWIFT CSP, shares information related to security threats potentially impacting the SWIFT community through a dedicated section of swift.com. | Credential | |
| Symantec Malicious Files | Provides new high-confidence malicious file SHA256 observables. Updated daily. | Credential | |
| Symantec Malicious URIs Feed | Provides daily new high-confidence malicious URI observables with a risk level of 8 or above, as determined by Symantec WebPulse. | Credential | |
| Symantec Threat Alert Indicators | Provides Symantec Threat Intelligence threat alert observables. | Credential | |
| Team Cymru - BARS feed | Provides in-depth analysis, tracking, and history of 40+ malware families that utilize unique control protocols and encryption mechanisms via the Botnet Analysis & Reporting Service (BARS). | Trial | |
| Team Cymru - Controller Feed | Provides near-real-time identification of botnet command-and-control (C&C) IP addresses (IRC, HTTP, and P2P) built for DDoS, warez, and underground economy, including bot types, passwords, channels, and expert insight. | Trial | |
| Team Cymru - Reputation feed | Enables subscribers to monitor for infected computers visiting their networks in near real-time, identifying compromised hosts as they access the network so they can be monitored or blocked before causing damage. | Trial | |
| The Media Trust | Provides real-time, original-source, web-based malware detected on compromised digital advertisements and third-party code used to render the world's most heavily trafficked websites. | Credential | |
| ThreatBook CTI Premium | Provides high-fidelity, actionable threat intelligence to enhance detection, response, and operational efficiency. | Credential | |
| ThreatWorx Threat and Vulnerability Intelligence | Provides machine-curated, AI-enhanced threat and vulnerability intelligence with advanced keyword-based filtering and noise reduction. | Credential | |
| VMRAY - UniqueSignal - Essential | Provides a high-throughput threat intelligence feed with TAXII 2.1/STIX 2.1 API, JSON, CSV, and MISP outputs. Processes 500–1,500 daily malware samples to deliver near-real-time, noise-free observables and contextual relationships. | Credential | |
| VMRay Threat Intelligence | Ingests observables, malware attributes, threat families, and detailed reports from files, URLs, and emails submitted to VMRay by CERT, SOC, and CTI teams. Automated deep analysis and enrichment of samples produces reliable threat intelligence. | Credential | |
| Well Fed Intelligence DGA Feeds - Domains | Tracks 53 families of malware and approximately one million malicious domains using domain generation algorithms. Created hourly with resolution, domain, IP, and nameserver information. Lists all actively resolving, non-whitelisted domains. | Trial | |
| Well Fed Intelligence DGA Feeds - IP Addresses | Tracks 53 families of malware and approximately one million malicious domains using domain generation algorithms. Created hourly with resolution, domain, IP, and nameserver information. Lists all actively resolving, non-whitelisted IPs currently used by DGAs. | Trial | |
| ZeroFox - Cyber Threat Intelligence Feeds | Improves the depth and accuracy of alerting, analysis, and investigations with unique threat data via ZeroFox's Network & Vulnerability Intelligence Feeds. An active ZeroFox subscription is required to use this application. | Credential | |
| ZeroFox Alerts | Provides insight into your public attack surface by streamlining traditional threat intelligence and digital risk protection to enable action on cyberthreats. An active ZeroFox subscription is required to use this application. | Credential |