Threat intelligence: turn one indicator into the whole picture

Every analysis feeds a searchable corpus of samples, URLs, infrastructure and behaviour. Search it, pivot through it, save a standing hunt against it, and pull the results into your own tooling.

What you can do with it

In the corpus today

Common questions

Where does the data come from?
From analyses run on this platform: user submissions plus public malware feeds, each analysed by the same pipeline. Counts describe this corpus, and pages reporting prevalence say so rather than implying a global sensor network.
Can I get the data programmatically?
Yes. The REST API covers submission, lookup, search, reports and intelligence, with an OpenAPI specification. STIX 2.1 and CSV feeds and a TAXII endpoint are available for indicator consumption.
How current is it?
Reports are indexed as they finalise, so a sample analysed a minute ago is searchable now. A stored report reflects the detection content in place when it ran, which is why re-analysing an old sample can produce a different verdict.

Related