Events and abuse signals
The intended input is what protection systems already observe: blocked sources, probes, floods and other abuse. Each item keeps its time and its reason.
Captured, not inventedPlatform
CTIAD — Central Threat Intelligence & Abuse Database — is the system that collects security events and abuse signals, relates them, scores them and makes the result usable.
Architecture
CTIAD is an independent system. It is not a mirror of an external catalogue and it is not a new name for a blacklist.
The intended input is what protection systems already observe: blocked sources, probes, floods and other abuse. Each item keeps its time and its reason.
Captured, not inventedRelated records are meant to be read together and given a score. That score is the basis for later lists and reports.
Assessment inside CTIADOutput is for firewalls such as CDPGuard and for operators who need a case, not a single log line.
Usable, not decorativePublishing indicators is one module. The platform also holds threat intelligence and the abuse database.
See the Blacklist pageBoundary
Threat intelligence covers indicators and events. The abuse database covers abuse cases.