Skip to content

Looking for the threat feed? It now lives at threatcluster.io/threats.

20,000 sources collapsed into one scored record per incident, queryable by your code or your agent.

Connect any MCP client to one URL, or call the REST API directly. Clustered incident reporting, validated IOCs, vulnerability intelligence and first-party dark-web collection behind one free key.

As seen on

Associated Press ABC News CBS News International Business Times NOAH

Three ways to tap into threat intelligence

Threat intelligence for the agentic era

LLMs know the past, not this year. We asked eight leading models about 20 ransomware groups that appeared this summer: not one answer was right, and every one was confident. Connected to ThreatCluster, every answer was right.

0 of 150Correct without ThreatClusterEight leading models, 20 ransomware groups that first appeared June to September 2026.
158 of 158Correct with ThreatClusterSame models, same questions, one record supplied.
225Fake indicators inventedFive of eight models made up IP addresses and hashes when asked for IOCs. None were real.
5x cheaperThan an LLM with web search$0.002 per answer against $0.012, and no citations to re-verify.
5x fasterAbout one second per answerWeb-search models averaged 5.2 seconds.
We found this IP in an alert, is it malicious? 210.1.231.13

Yes. Treat it as malicious, high confidence.

210.1.231.13 is a validated IOC, first and last seen 15 Sep 2026. It resolves turbo.c2iznja.com, a BambooToken command-and-control subdomain: the resolution for the C2, not an incidental mention. Source: Lumen Black Lotus Labs, corroborated by BleepingComputer and The Hacker News.

BambooToken is a Windows/Linux implant that uses MQTT for C2. It is unusual enough that most egress monitoring ignores it, common enough in IoT estates that it is not automatically suspicious. Active since Feb 2023, targeting finance and government across Asia and South America.

Triage

  • Direction and port. Outbound to 1883 or 8883 from an internal host is the signal. Inbound scanning is not.
  • Pivot on the domains. Infrastructure rotates, so the IP may go cold while *.c2iznja.com and *.chat5188.tk stay live. Hunt DNS for both.
  • Sweep related infrastructure: 202.144.192.13, 202.144.192.23, 210.1.226.163, 43.245.198.195, 38.180.150.19.

A block is safe; a compromise verdict is not. This rests on one research publication, and C2 infrastructure in an alert does not mean the host is infected. That depends on direction, volume and whether a session was established. Outbound and sustained: isolate.

Get a free API keyConnect via MCPhttps://threatcluster.io/mcp

What the API returns

70+ endpoints over incidents, IOCs, entities, vulnerabilities, the dark web, and the feeds, alerts and webhooks you run through the API. Pick an endpoint and a language, and see the real response.

Incident records, deduplicated from every source that covered them

GET /threats?time_filter=24h
{
  "threats": [
    {
      "cluster_id": "5f578c75-abf8-4fbd-915b-d4037386092f",
      "title": "Iranian cyber spies target aviation, fintech developers with new malware",
      "ai_title": "Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware",
      "ai_summary": "The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across…",
      "timeline": [
        {
          "date": "2026-09-01",
          "event": "New malware families identified",
          "detail": "Kaspersky reported on the discovery of NodeRabbit and PollCat used by Mirage Kitten to ta…",
          "source": "Securelist"
        }
      ],
      "article_count": 3,
      "threat_score": 78.5,
      "severity_score": 80.0,
      "urgency_level": "medium",
      "keywords": [
        "malware",
        "iranian"
      ],
      "sources": [
        "Thehackernews",
        "Therecord.Media"
      ],
      "date_range_latest": "2026-09-01T13:08:58+00:00",
      "articles": [
        {
          "title": "Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new m…",
          "source": "Securelist",
          "pub_date": "2026-09-01T07:00:26+00:00",
          "url": "https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/"
        }
      ],
      "entities": {
        "apt_group": [
          "Iranian Dream Job",
          "Lazarus Group"
        ],
        "attack_type": [
          "Malware",
          "Phishing"
        ]
      },
      "slug": "mirage-kitten-targets-aviation-and-fintech-with-new-cross-pl-7386092f",
      "ioc_count": 12
    },
    {
      "cluster_id": "afb356a7-d498-4c89-920a-44025c9b39fa",
      "title": "CPAI-2026-10671 - Check Point Software",
      "ai_title": "Multiple Remote Code Execution Vulnerabilities Identified in Check Point Software",
      "ai_summary": "Check Point Software has issued advisories for two critical remote code execution vulnerabilities. The first, CVE-2026-53576, was published on June 2…",
      "timeline": [
        {
          "date": "2026-06-11",
          "event": "CVE-2026-44495 published",
          "detail": "Check Point disclosed a remote code execution vulnerability affecting its Security Gatewa…",
          "source": "Advisories.Checkpoint"
        }
      ],
      "article_count": 2,
      "threat_score": 74.0,
      "severity_score": 80.0,
      "urgency_level": "medium",
      "keywords": [
        "protection",
        "update"
      ],
      "sources": [
        "Advisories.Checkpoint"
      ],
      "date_range_latest": "2026-08-31T18:52:57+00:00",
      "articles": [
        {
          "title": "CPAI-2026-10476 - Check Point Software",
          "source": "Advisories.Checkpoint",
          "pub_date": "2026-08-30T19:04:16+00:00",
          "url": "https://advisories.checkpoint.com/defense/advisories/public/2026/cpai-2026-10476.html"
        }
      ],
      "entities": {
        "attack_type": [
          "Zero-Day Exploit"
        ],
        "cve": [
          "CVE-2026-44495",
  …

The API, in numbers

Incident records22,192+651 this week
Validated indicators16,955+2,020 this week
Leak-site victims20,926+184 this week
Entities118,182+7,843 this week
Articles227,195+7,590 this week
Lead over the trade press5.1 daysHow we measure it

Build into your existing workflow

The API speaks the formats your tools already read. Each link is a short setup guide.

Terminal

pipx install threatcluster-cli, or plain curl. Drop-in for cron, CI and shell pipelines.

BashcurlWindows TerminalVS Code

SIEM, firewall, TIP

Point the ingestor at the IOC feed, or import STIX bundles and the MISP manifest.

Microsoft SentinelSplunkElastic

Agents

Per-session agent keys with scoped budgets, tool definitions from the OpenAPI spec, and cost headers the model can read to pace itself.

ClaudeOpenAICursorMCP server

Start from your industry

We ingest news, vendor research, government advisories, CVE and exploit data and ransomware leak sites, then tag every incident with the sectors it hit. Pick yours to see what is aimed at it right now.

Every sector we track →

Pricing

Every account gets a free key. Paid plans add history, headroom and the write endpoints. Cancel any time.

Free $0 100 credits a day, the last 7 days
  • Every read endpoint: incidents, IOCs, entities, vulnerabilities, dark web
  • 30 requests a minute, 25 rows a request
  • Public feeds and the IOC blocklist need no key at all
Get a free key
Starter $19.99/ month 1,000 credits a day, 90 days of history
  • 120 requests a minute, 50 rows a request
  • Custom feeds and alert rules over the API
  • Internal business use
Choose Starter
Growth $99/ month 5,000 credits a day, the full archive
  • 240 requests a minute, 100 rows a request
  • Everything in Starter
  • The complete corpus back to launch, not a rolling window
Choose Growth
Business From $399/ month No daily budget, unlimited rows
  • 600 requests a minute, per-key overrides
  • Managed customers: per-client feeds, alerts and branded digests
  • Org sharing. Redistribution by agreement
Talk to us

Need more on a given day? Credit packs: 2,000 for $10 or 12,000 for $50. One-off, never expire, spent after the daily allowance. A request that finds nothing costs nothing. Full pricing and what each request costs.

FAQ

What does the free key include?

Every read scope over the last 7 days with 100 credits a day: incidents, IOCs, entities, vulnerabilities and dark web. Records are trimmed to the short summary, 3 timeline events and 25 rows per list.

Most calls cost 1 credit. The heavier ones cost more: unified search is 5, STIX bundles and bulk indicator pulls are 3, and a fully enriched leak-site victim record is 10. The budget resets daily.

How fresh is it?

Incidents form within minutes of the first credible report and indicators are validated on ingest.

The lead-time number is measured, not estimated: for every incident that later appeared in the trade press, we compare the timestamp our record was created with the earliest matching trade-press article, and take the median across the matched pairs over the last 90 days. Right now that is 5.1 days, from 82 matched incidents.

How does an incident record get made?

Articles from 20,000+ sources are deduplicated into one cluster per incident as reports arrive. Each record carries a rewritten title and summary, the extracted entities (actors, malware, CVEs, victims), a sourced timeline and a threat score, and it keeps updating as coverage grows. One id to follow instead of twenty headlines.

Where does the dark-web data come from?

Our own Tor collection of leak sites, markets and underground postings, with screenshots, extracted data sizes and negotiation state. Not resold from a broker.

What formats can I pull?

JSON everywhere, STIX 2.1 bundles per incident, MISP feeds, and CSV or plain-text blocklists from the indicator feeds. The public feeds are also available as RSS, and incident pages exist as .md and .json for LLM context windows.

Are there code examples?

Yes. The GitHub repository has a daily-refreshed OpenAPI snapshot, a small Python client and real request/response pairs for every major endpoint, and the live spec is browsable as Swagger UI.

Can I redistribute the data?

The free feeds are TLP:CLEAR, redistribute with attribution. Keyed responses are for your own tooling. Embedding them in a product you sell, or redistributing them to your own customers, is by agreement on the Business plan.

Can I cancel?

Plans are monthly with no minimum term. Cancel from settings and the key keeps working until the end of the period. The free key never expires.

Get started

The whole surface is in the spec: 70+ endpoints over incidents, IOCs, entities, vulnerabilities and the dark web. Mint a free key and make the first call in a minute.