Threat intelligence

Indicators with a source, a time and a score.

Threat intelligence in CTIAD means stored security events that can be compared, scored and handed to a protection system. A loose list of addresses is not enough.

Record

What an intelligence record is for.

Source

Who was seen

An address or other indicator stays attached to the event that produced it. The database does not detach the indicator from its evidence.

Evidence stays attached
Time

When it happened

Time is part of the record. A source that appeared once months ago is not treated as a source that is active today.

Recency matters
Reason

Why it was stored

Probe, flood, protocol abuse or another observed reason. The reason is what later scoring and reports are built on.

Not an anonymous hit
Score

How it should be read

Scoring turns many events into a rating a firewall or an analyst can use. Publishing that rating is a later step, not the first one.

Score, then publish

Comparison

External catalogues are not the database.

Operators often look at public abuse catalogues such as AbuseIPDB when they review an address. That comparison is useful context. CTIAD’s intelligence is still its own records: what was observed, stored and scored here.

  • Own basisA CTIAD indicator exists because an event was stored in CTIAD, not because a third party listed it.
  • No claimed importThis site does not state that an external intelligence feed is connected or updating the database.
  • For protection systemsThe intended consumer is a system such as CDPGuard, plus operators who review cases.

Abuse cases live next door.

Threat intelligence is the indicator view. The abuse database is the case view of the same system.

Abuse database