Using the Threat Feed
Master the threat feed - filters, sorting, categories, and personalization.
The threat feed is ThreatCluster's primary interface. It surfaces clustered threat intelligence from 8,000+ sources, ranked and filtered to help you focus on what matters.
Feed Types
Switch between feed types using the tabs at the top of the feed.
Trending
The default view. Clusters are ranked by a weighted combination of recency and article count. A cluster with 30 articles published over the last 12 hours will rank higher than one with 30 articles spread across a week.
Hot
Highlights clusters experiencing a sudden burst of activity. Useful for catching breaking incidents -- a cluster that jumped from 2 to 20 articles in the last few hours will surface here even if its total count is lower than older stories.
Latest
Pure reverse-chronological order. Every cluster appears based on when its most recent article was published. Use this when you want an unfiltered, time-ordered view.
My Feed
A personalized feed driven by your tracked keywords, selected industries, countries, and platforms from onboarding. Only clusters matching your interests appear here.
Time Filters
Control how far back the feed reaches:
| Filter | Shows clusters with activity in the last... |
|---|---|
| 1h | 1 hour |
| 24h | 24 hours (default) |
| 7d | 7 days |
| 30d | 30 days |
| 60d | 60 days |
| 90d | 90 days |
Time filters apply to the cluster's most recent article timestamp, not when the cluster was first created.
Content Type Filters
Filter what appears in your feed:
- All -- shows both clusters and standalone articles.
- Clusters only -- hides standalone articles, showing only grouped threat clusters.
- Articles only -- shows individual articles without clustering.
Category Sections
Clusters are automatically assigned to categories based on their content. Categories group related threats together in the feed, making it easy to scan by topic area. Examples include ransomware, vulnerability disclosures, nation-state activity, and data breaches.
Each category section shows its clusters ranked by the active feed type (trending, hot, or latest).
Hero Grid
The top of the feed displays a hero grid featuring the three highest-scoring threats. These cards are larger, include AI-generated summaries, and auto-rotate to cycle through top stories.
The hero grid only appears on the first page of the feed and pulls from whichever feed type is currently active.
Trending Entities Sidebar
On the right side of the feed, the trending entities sidebar shows entities that are spiking in mention volume. This includes threat actors, malware families, CVEs, and tools that are appearing across multiple clusters.
Click any entity in the sidebar to filter the feed to clusters containing that entity, or visit the entity's dedicated page to see its full history.
Understanding Cluster Cards
Each cluster card in the feed displays:
| Element | Meaning |
|---|---|
| Threat Score | A 0-100 score reflecting severity, activity volume, and recency. Displayed as a color-coded bar (green/yellow/orange/red). Rounded to the nearest 10. |
| Title | AI-generated summary title describing the cluster's topic. |
| Entity Badges | Extracted entities (APT groups, malware, CVEs, etc.) shown as clickable badges. |
| Source Count | Number of unique articles in the cluster. More sources generally means higher confidence and broader impact. |
| Timestamp | When the most recent article in the cluster was published. |
| Category | The cluster's assigned category label. |
Threat Score Breakdown
| Range | Color | Meaning |
|---|---|---|
| 80-100 | Red | Critical -- active exploitation, major breaches, zero-days |
| 60-79 | Orange | High -- significant threats with broad coverage |
| 40-59 | Yellow | Medium -- notable but limited impact or early-stage reporting |
| 0-39 | Green | Low -- informational, minor, or historical |
Inside a Cluster
Click any cluster card to open its detail view. Inside you'll find:
- All related articles -- every source reporting on this threat, with links to originals.
- Extracted entities -- full list of threat actors, malware, CVEs, tools, and other entities mentioned across all articles.
- AI summary -- a generated overview synthesizing key details from all sources.
- Timeline -- a chronological view showing when each article was published, so you can see how the story developed.
- Entity relationships -- how entities in this cluster connect to other clusters and threats.
Tips for Effective Monitoring
- Start with Trending for your daily briefing -- it balances recency with significance.
- Check Hot periodically throughout the day to catch breaking incidents early.
- Use My Feed as your primary view once you've configured keywords and onboarding preferences.
- Combine time filters with feed types -- for example, Hot + 1h shows threats that spiked in the last hour.
- Click entity badges to pivot from one cluster into the broader context of a threat actor or vulnerability.