Edgewatch Cyber Threat Intelligence API

The Edgewatch Cyber Threat Intelligence (CTI) API delivers real-time, structured, and enriched threat data directly from our global honeypot sensor network. It empowers security professionals with access to high-fidelity attacker data, malware hashes, and contextual threat intelligence enriched with MITRE ATT&CK and shared using STIX/TAXII standards. Each event represents a real attack observed on our honeypots.

Download free, ready-to-use threat intelligence feeds. For REST API usage details and endpoint specifications, visit the API Docs or consult our Knowledge Base. STIX 2.1 feeds are also available via our TAXII 2.1 server.

IoCs (90d): Loading... Active Threats (24h): Loading... Today's New: Loading... Top Attack: Loading...
Time Range: Last 30 days
IPs
IP Address Icon
Hostnames
Hostname Icon
URLs
URL Icon
Malware
Malware Icon
Other IoCs
Other IoC Icon
Indicators Activity
Type of IoCs ingested
ip
hostname
url
malware

Loading indicators activity...

Loading classification...

Loading threat activity...

Loading cumulative statistics...

Top Attack Vectors
Loading attack vectors...

Anomaly-detected threats with unusual activity spikes (7-day baseline)

  Detecting anomalies...
Global Attack Origins

Geographic distribution of attack sources detected over the last 7 days

Loading geographic attack data...

Threat Categories
Loading categories...

Real-time threat intelligence from our global sensor network (last 10 days)

Loading threat trends...

Loading data...

This service is subject to our Terms of Use and Privacy Policy.