Threat Intel · Sub-capability

CTI Feed API

Integrate our threat intel with your SIEM/SOAR: Splunk, Microsoft Sentinel, Cortex XSOAR, Elastic, Chronicle. STIX/TAXII standard + REST + webhooks. No proprietary lock-in.

Capabilities

REST API + webhooks

Endpoints for IoCs, alerts, breach hits, lookalikes. Webhooks for push (better latency than polling).

STIX/TAXII 2.1

Standard TAXII server for SIEMs preferring the industry-standard protocol. Splunk + IBM QRadar + ArcSight out-of-the-box.

Pre-built connectors

Cortex XSOAR (Palo Alto), Splunk SOAR, Microsoft Sentinel logic apps, Elastic SIEM, Chronicle (Google). 15-minute setup.

Real-time vs batch

Streamed feeds (websocket) for production + batch endpoints for enriching historical logs. Same data, different delivery.

API key management

Per-team API keys with independent rate limits. Audit log of which team consumes which feed.

Full documentation

OpenAPI spec + Postman collection + sample integrations on GitHub. No "contact us for the schema".