Platform

One database for events, abuse and scored output.

CTIAD — Central Threat Intelligence & Abuse Database — is the system that collects security events and abuse signals, relates them, scores them and makes the result usable.

Architecture

Own data, own scoring, own reports.

CTIAD is an independent system. It is not a mirror of an external catalogue and it is not a new name for a blacklist.

In

Events and abuse signals

The intended input is what protection systems already observe: blocked sources, probes, floods and other abuse. Each item keeps its time and its reason.

Captured, not invented
Core

Correlation and score

Related records are meant to be read together and given a score. That score is the basis for later lists and reports.

Assessment inside CTIAD
Out

Protection and review

Output is for firewalls such as CDPGuard and for operators who need a case, not a single log line.

Usable, not decorative
Module

Blacklist stays a module

Publishing indicators is one module. The platform also holds threat intelligence and the abuse database.

See the Blacklist page

Boundary

What this page does not claim.

  • No live feed advertisedExternal reporting channels and third-party integrations are not described as already in production.
  • AbuseIPDB is contextPublic abuse catalogues such as AbuseIPDB are a useful comparison. They are not CTIAD’s data basis.
  • CDPGuard stays the firewallDetection and blocking remain CDPGuard’s job. CTIAD does not replace the packet filter.
  • Own operatorThe platform is operated by CertThor PlatForms Ltd. inside the CTPF network.

Read the two data areas next.

Threat intelligence covers indicators and events. The abuse database covers abuse cases.

Threat intelligence