One indicator feed, ready for every tool.

Compromise indicators aggregated from resale-safe open-source sources, deduplicated, confidence-scored and signed, delivered in the format each of your tools expects. Plug it in, it matches.

3 589 000+
indicators
4 types
IP · domain · URL · hash
5 formats
CSV · STIX · MISP · blocklists · RPZ
Ed25519
signed, daily updates

What we added recently

A living feed: here is the coverage added to it, dated.

  • +50 indicateurs
  • +57 indicateurs
  • +80 indicateurs
  • +67 indicateurs
  • +19 indicateurs
  • +108,778 indicateurs

Four indicator types, one source of truth.

IP

Botnet C2 IPs and confirmed malicious hosts, private/reserved IPs are filtered out (zero self-block).

Domaines

Malware-distribution and phishing domains.

URLs

Live malicious-payload and drop URLs.

Hashes

Malicious file hashes (MD5/SHA-1/SHA-256) and C2 TLS-certificate hashes.

Every indicator carries a confidence score (number of independent sources listing it) so you can filter to your false-positive tolerance.

See the full coverage

The right format for every tool.

CSVfirewalls, pfSense, scripts, Suricata iprep
STIX 2.1SIEM (Sentinel, QRadar), TIP (MISP, OpenCTI), EDR
MISPMISP, OpenCTI, CERT communities
Blocklistsfirewalls, pi-hole, IP/domain lists
RPZDNS sinkhole (BIND, Unbound, pi-hole)

Not a raw mirror of public feeds.

01
Aggregated & deduplicated

Several sources merged into one clean feed, no duplicates to reconcile.

02
Confidence-scored

Each indicator is scored by how many independent sources confirm it.

03
Resale-safe licenses

Only CC0 / Unlicense / MIT sources, redistributable, MSSP included.

04
Ed25519-signed

The feed is signed; you verify its integrity before applying it.

05
Anti-false-positive

Format validation and legitimate-infra exclusion (private/reserved IPs).

06
Multi-format, one key

Every format free, updated daily.

Where do the indicators come from?

From permissively-licensed open-source sources (CC0 / Unlicense / MIT), aggregated, normalized, deduplicated and scored. Nothing under a non-commercial or GPL license enters the feed, so it stays resalable and redistributable.

How often is it updated?

Rebuilt daily. The feed is versioned and signed, so your tool only pulls what changed.

How is this different from the ThreatClaw agent’s IOCs?

The ThreatClaw agent uses these indicators internally for its own detection. This feed is the standalone product: the same indicators, exported in standard formats for your OTHER tools (SIEM, firewall, DNS, TIP). Free.

Can I use it as an MSSP / redistribute it?

Yes. The feed only aggregates resalable sources (CC0 / Unlicense / MIT), built for MSSP use and redistribution to your clients.

Use it in MISP or TheHive.

It’s a public MISP feed, no key required. In MISP: Sync Actions → Feeds → Add Feed, set Input Source to Network and Format to MISP, then paste the URL below. Enable the feed and run a Fetch. The same feed also plugs into TheHive via a MISP connector.

https://get.threatclaw.io/api/misp-feed

No key required, it’s public.

Need curated detection rules (Sigma/YARA/WAF)?See the packs

Ready to enrich your tools?

Free community feed. No key required. Subscribe from MISP or TheHive.

Free
Try before you buy: free demo pack

A sample of our in-house rules across every engine we run (Sigma, YARA, osquery, Velociraptor, Falco, network, policy), each detection with its investigation playbook in the CACAO 2.0 standard, importable into your SOAR. The Sigma rules come already converted for 6 SIEMs: Splunk, Sentinel, Elastic, QRadar, CrowdStrike and Panther. A NIS2 compliance-coverage sample is included. Generated without AI.

Download the demo pack .zip

What this pack does not cover

What we do not cover, we tell you

No one detects 100%, and a feed that claims otherwise burns out your analyst. Anything that does not compile on the real engine, or lights up on a benign corpus, never reaches the pack. What a rule cannot see, we show as a gap rather than paper over it. And by default the agent observes and proposes, acting only after human validation (human-in-the-loop). You buy signal, not volume.

Detection that holds up in front of the auditor

The question is no longer only “can I detect?” but “can I prove it?”. Every subscription ships with the compliance layer, at no extra cost.

Design coverage, not a certification nor a real-time measurement: it evidences that the catalogue addresses the requirement, your CISO validates compliance.

Detection guides

The method behind the pack, on our blog.

2026-08-08
Proven Detection, Not Scraped Rules: What Sets the ThreatClaw Feed Apart

A rule feed is not worth its rule count. It is worth the proof that the rules fire and what you do when they trigger. Tested on real engines, false-positive-proven, signed, and every rule ships an investigation playbook wired to our other engines.

2026-08-08
YARA Summer Pack: 72 malware families covered this summer (Prometei, WannaCry, SpyNote…)

From June to August 2026, ThreatClaw forged 72 new malware families into its YARA feed: Prometei, WannaCry, EternalBlue, GhostNFC, SpyNote, Mamont, Neshta… each tested against 5,694 legitimate binaries, zero false positives.

2026-07-24
DBIR 2026: 96% of Ransomware Victims Are SMBs, Now What?

The Verizon 2026 report puts vulnerability exploitation ahead as the top initial access vector and confirms ransomware mainly hits SMBs. The concrete actions.

2026-07-24
14 new malware families covered: the June YARA batch

Prometei botnet on Linux, Windows code injection, Office macros, Android, downloaders. ThreatClaw adds 14 fresh malware families to its YARA feed, 391 rules, tested against 5,694 legitimate binaries with zero false positives.

2026-07-19
IOC Feeds Compared: abuse.ch, OTX, MISP and Curated Aggregation

The best IOC feeds are largely free. So what do you actually pay for? A practical comparison of abuse.ch, AlienVault OTX, MISP and commercial threat intel, and where a curated aggregation layer earns its place.

2026-07-18
Fake Interpol Emails: The Ransomware Aimed Straight at SMBs

A campaign impersonates Interpol to trap SMBs: Proton Drive link, encrypted archive, executable disguised as a video. The indicators and the detection rule.