Getting Started 4 min read

Getting Started with ThreatCluster

Set up your account, complete onboarding, and start tracking threats in under 5 minutes.

ThreatCluster aggregates and clusters articles from 8,000+ cybersecurity sources, giving you a real-time view of the threat landscape. This guide walks you through setup and core concepts.

Creating Your Account

  1. Go to threatcluster.com and click Sign Up.
  2. Register with your email address or use SSO (Google, Microsoft, GitHub).
  3. Confirm your email to activate your account.
Tip: SSO users are automatically verified and can skip the email confirmation step.

Completing Onboarding

After signing in for the first time, the onboarding wizard helps ThreatCluster tailor your experience. You'll select:

  • Industries -- the sectors you monitor (e.g., Finance, Healthcare, Energy).
  • Countries -- geographic regions relevant to your threat model.
  • Platforms -- operating systems and infrastructure you care about (Windows, Linux, cloud providers, etc.).
  • Organizations -- specific companies or agencies you want to track.

These selections power your personalized My Feed and influence which clusters surface first.

Note: You can update all of these later from your account settings.

Understanding the Threat Feed

The feed is the main view in ThreatCluster. It shows clusters -- groups of related articles about the same threat, incident, or topic -- ranked by different criteria.

Four feed modes are available:

Mode What it shows
Trending Clusters weighted by recency and article volume
Hot Clusters with a recent burst of new articles
Latest All clusters in reverse chronological order
My Feed Personalized feed based on your tracked keywords and onboarding selections

The top of the feed features a hero grid highlighting the three highest-priority threats. Below it, clusters are listed as cards with threat scores, entity badges, and source counts.

Clusters vs. Articles

  • A cluster is a group of articles that cover the same threat event or topic. ThreatCluster automatically groups related reporting together so you see one unified view instead of dozens of duplicate stories.
  • An article is a single piece from one source. Click into any cluster to see every article it contains, along with a timeline showing how coverage evolved.
Tip: Cluster titles are AI-generated summaries. The original article headlines are preserved inside each cluster.

Exploring Entities

ThreatCluster automatically extracts entities from articles and links them to clusters. Entity types include:

Type Examples
APT Groups APT29, Lazarus Group, Sandworm
Malware QakBot, Cobalt Strike, BlackCat
CVEs CVE-2024-3400, CVE-2023-34362
Tools Mimikatz, Impacket, Brute Ratel
Campaigns Operation Triangulation, MOVEit exploitation
Countries Russia, China, Iran, North Korea
Industries Financial Services, Healthcare, Government
Platforms Windows, Linux, VMware ESXi, Cisco IOS
Companies Microsoft, CrowdStrike, Mandiant

Click any entity badge on a cluster card or entity page to see all clusters and articles associated with it.

Setting Up Tracked Keywords

Tracked keywords let you monitor specific terms across all incoming articles.

  1. Go to Settings > Keywords.
  2. Add keywords such as threat actor names, CVE IDs, product names, or any term you want to watch.
  3. When new articles match your keywords, they appear in My Feed and can trigger alerts if you have alert rules configured.
Note: Keywords are case-insensitive. Use specific terms for better signal -- "LockBit" will produce more relevant results than "ransomware."

Plan Tiers

ThreatCluster offers four tiers:

Feature Free Researcher Business MSSP
Threat feed access Full Full Full Full
Tracked keywords 5 50 Unlimited Unlimited
Alert rules 1 10 Unlimited Unlimited
Report generation -- 5/month Unlimited Unlimited
IOC export -- Yes Yes Yes
Custom feeds -- 3 Unlimited Unlimited
Webhooks & workflows -- -- Yes Yes
API rate limit 30/min 120/min 600/min 1200/min
Organization RBAC -- -- Yes Yes
Multi-tenant orgs -- -- -- Yes
Tip: The free tier gives you full access to the threat feed. Upgrade when you need alerts, exports, or automation.

Next Steps

  • Using the Threat Feed -- master filters, sorting, and personalization.
  • Set up your first alert rule to get notified when specific threats appear.
  • Explore the entity graph to see relationships between threat actors, malware, and vulnerabilities.