One indicator feed, ready for every tool.
Compromise indicators aggregated from resale-safe open-source sources, deduplicated, confidence-scored and signed, delivered in the format each of your tools expects. Plug it in, it matches.
What we added recently
A living feed: here is the coverage added to it, dated.
- +50 indicateurs
- +57 indicateurs
- +80 indicateurs
- +67 indicateurs
- +19 indicateurs
- +108,778 indicateurs
Four indicator types, one source of truth.
Botnet C2 IPs and confirmed malicious hosts, private/reserved IPs are filtered out (zero self-block).
Malware-distribution and phishing domains.
Live malicious-payload and drop URLs.
Malicious file hashes (MD5/SHA-1/SHA-256) and C2 TLS-certificate hashes.
Every indicator carries a confidence score (number of independent sources listing it) so you can filter to your false-positive tolerance.
The right format for every tool.
Not a raw mirror of public feeds.
Several sources merged into one clean feed, no duplicates to reconcile.
Each indicator is scored by how many independent sources confirm it.
Only CC0 / Unlicense / MIT sources, redistributable, MSSP included.
The feed is signed; you verify its integrity before applying it.
Format validation and legitimate-infra exclusion (private/reserved IPs).
Every format free, updated daily.
Where do the indicators come from?
From permissively-licensed open-source sources (CC0 / Unlicense / MIT), aggregated, normalized, deduplicated and scored. Nothing under a non-commercial or GPL license enters the feed, so it stays resalable and redistributable.
How often is it updated?
Rebuilt daily. The feed is versioned and signed, so your tool only pulls what changed.
How is this different from the ThreatClaw agent’s IOCs?
The ThreatClaw agent uses these indicators internally for its own detection. This feed is the standalone product: the same indicators, exported in standard formats for your OTHER tools (SIEM, firewall, DNS, TIP). Free.
Can I use it as an MSSP / redistribute it?
Yes. The feed only aggregates resalable sources (CC0 / Unlicense / MIT), built for MSSP use and redistribution to your clients.
Use it in MISP or TheHive.
It’s a public MISP feed, no key required. In MISP: Sync Actions → Feeds → Add Feed, set Input Source to Network and Format to MISP, then paste the URL below. Enable the feed and run a Fetch. The same feed also plugs into TheHive via a MISP connector.
https://get.threatclaw.io/api/misp-feedNo key required, it’s public.
Ready to enrich your tools?
Free community feed. No key required. Subscribe from MISP or TheHive.