[ system :: intel ]

Intel .

Structured threat intelligence with provenance on every record — and an open community feed that gives the same data back.

[ ioc :: domain ] conf · 87
phish-REDACTED.example
first seen 2026-04-12
last seen 2026-05-26 14:08z
tags phishing · credential-theft
// sources
abuse.ch / URLhaus CISA KEV OTX pulses · 4
attribution 3 sources claim APT-29 (claim, not assertion)

[ 00 / brief ]

Threat intelligence has a credibility problem. Records get added on rumor and stay on lists for years. Attribution shows up in marketing decks as fact when the underlying sources said “probably.” Disputes get ignored because the dispute process was a contact form on a vendor’s PR site.

Intel is our answer to that. Every IoC, every actor record, every campaign reference carries the source it came from, when it was seen, and how confident the source was. We never assert attribution as our own; we record what other people claim and we cite them. We run a real takedown process with real SLAs. And the same data we use internally — sanitized of anything customer-specific — is published openly to the community, in the formats the community already uses.

[ 01 / what’s covered ]

  1. Always-cite-source — Every record in Intel carries the feed source, the ingestion timestamp, and the source-reported confidence. Nothing exists in the platform without a traceable origin. Consumer apps and the outbound feed preserve provenance end-to-end.

  2. Attribution as claim, never assertion — When sources attribute a campaign to a threat actor, we record the claim and who made it. We never write “Censored attributes this to APT-X” — we write “five sources, listed and dated, attribute it,” and we leave the next move to the practitioner reading the record.

  3. Confidence with decay — Per-source confidence rolls up into an aggregate, weighted by how much we trust the source. Aggregates decay over time without re-confirmation. The IoC that was hot three months ago doesn’t get to keep its score if nobody’s seen it since.

  4. The open community feed — A free, no-auth, no-signup outbound feed in the formats the community already runs on: MISP, STIX/TAXII, JSON, CSV. Same data we use internally. Customer-derived signals are aggressively sanitized before they leave the platform — no customer identifiers, no per-customer specifics, no signals that could re-identify an environment.

  5. A real takedown process — A monitored dispute mailbox where anyone whose IP, domain, or hash got listed can request review. 48-hour acknowledgment SLA. Five-business-day resolution. Retractions and annotations appear in a public changelog so anyone consuming the feed can update downstream.

  6. CVE intel done properly — CVSS, CISA KEV listing, public exploit status, active exploitation, patch availability, workaround availability, vendor advisory state — all pulled from authoritative sources, kept current, queryable by CVE ID. The structured view that practitioners actually need at three in the morning.

  7. Built to interoperate — MISP-compatible storage so we can exchange intel with the communities that already use it. Censored-native API for consumers who’d rather not deal with MISP’s legacy surface. Both, on purpose.

[ 02 / who this is for ]

  • SOC analysts at the customers we already serve through Grid — Intel is what enriches every alert before it reaches a human.
  • Independent security practitioners who want a free, well-cited intel feed that doesn’t require a contract or a sign-up form.
  • Other SOC providers, MSSPs, and internal security teams who want to peer with a community feed in standard formats.
  • Researchers and journalists working on attribution, vulnerability disclosure, or campaign tracking who want a structured source of claims with provenance intact.
  • Anyone who’s been listed and shouldn’t be. The dispute process is real and the mailbox is monitored.

[ 03 / how it fits ]

  • Intel enriches Grid. Every alert that lands in front of a Grid analyst has already been cross-referenced — IoCs, actor links, campaign context, CVE state — without the analyst having to leave the case screen.
  • Pulse cross-references Intel. Pulse news topics about specific CVEs or actors render Intel’s structured data directly into the topic page. Pulse stays a news surface; Intel stays the data layer.
  • Comply uses Intel for CVE context. When Comply surfaces a control gap related to a CVE, Intel tells you whether that CVE has a public exploit, active exploitation, or a patch waiting.
  • Lens correlates against Intel when it surfaces a vulnerability. “This finding has known exploitation activity this week” versus “this finding is a CVSS 9 with no public exploit and a patch from 2023” — different conversations, same scan.

[ 04 / where we are ]

The platform is running. The internal enrichment API is in production behind Grid. The public read API is feeding Pulse’s structured overlays. Tier-one sources — Abuse.ch, CISA KEV, NVD, US-CERT, MISP communities, Spamhaus, Tor exit lists — are flowing.

The open community feed and the public site are invite-only right now. We’re working through a small group of peering partners and source contributors before opening the doors wider. The dispute mailbox is monitored today; if you’ve been listed and want a record reviewed, the address below works whether or not you’ve got an invite.

[ ready :: contact ]

Talk to us.

Working with the feed and want to talk about it? Sitting on a source we should be pulling? Looking for an invite? For takedown requests, use intel-disputes@censoredsystems.com.