Edgewatch Cyber Threat Intelligence API

The Edgewatch Cyber Threat Intelligence (CTI) API delivers real-time, structured, and enriched threat data directly from our global honeypot sensor network. It empowers security professionals with access to high-fidelity attacker data, malware hashes, and contextual threat intelligence enriched with MITRE ATT&CK and shared using STIX/TAXII standards. Each event represents a real attack observed on our honeypots.

Download free, ready-to-use threat intelligence feeds. For REST API usage details and endpoint specifications, visit the API Docs or consult our Knowledge Base. STIX 2.1 feeds are also available via our TAXII 2.1 server.

Galaxy Unique Attackers (90d): Loading... Active Threats (24h): Loading... Today's New: Loading... Top Attack: Loading...

Loading threat activity...

Loading cumulative statistics...

Top Attack Vectors
Loading attack vectors...
Trending Exploits

Anomaly-detected threats with unusual activity spikes

Detecting anomalies...
Threat Categories
Loading categories...

Loading data...

This service is subject to our Terms of Use and Privacy Policy.