Module

Blacklist is a module. It is not the product.

CTIAD collects, correlates, scores and reports. The blacklist module is the part that publishes indicators after that work. A list alone is not a threat-intelligence database.

Place in the system

Publication comes after the database.

1

Store

Events and abuse signals are stored in CTIAD first. Without that record there is nothing honest to publish.

Abuse database and intelligence
2

Score

A source is scored from its own evidence: repetition, reason and recency. A single stray hit is not automatically a listing.

Inside CTIAD
3

Publish

The blacklist module is the publication step. Its job is a list of evaluated indicators that protection systems can consume.

One module
4

Protect

CDPGuard remains the system that detects and blocks. The blacklist does not filter packets by itself.

CDPGuard does the blocking

Scope

What this module page states.

  • Not the whole of CTIADPlatform, threat intelligence and the abuse database stay in place if the list is empty.
  • Evaluated indicatorsA blacklist entry is meant to be the result of scoring, not a copy of an outside list.
  • No live feed claimed hereThis page does not state that a public submission API or a third-party import is already accepting data.
  • Comparison onlyServices such as AbuseIPDB show how public abuse lists are usually read. They are not this module.

Questions about the module.

Licensing, scope and how a protection system should read CTIAD output — use the contact form.

Contact