Getting Started 5 min read

Using the Threat Feed

Master the threat feed - filters, sorting, categories, and personalization.

The threat feed is ThreatCluster's primary interface. It surfaces clustered threat intelligence from 8,000+ sources, ranked and filtered to help you focus on what matters.

Feed Types

Switch between feed types using the tabs at the top of the feed.

The default view. Clusters are ranked by a weighted combination of recency and article count. A cluster with 30 articles published over the last 12 hours will rank higher than one with 30 articles spread across a week.

Hot

Highlights clusters experiencing a sudden burst of activity. Useful for catching breaking incidents -- a cluster that jumped from 2 to 20 articles in the last few hours will surface here even if its total count is lower than older stories.

Latest

Pure reverse-chronological order. Every cluster appears based on when its most recent article was published. Use this when you want an unfiltered, time-ordered view.

My Feed

A personalized feed driven by your tracked keywords, selected industries, countries, and platforms from onboarding. Only clusters matching your interests appear here.

Tip: If My Feed feels too narrow, add broader keywords or revisit your onboarding selections in Settings.

Time Filters

Control how far back the feed reaches:

Filter Shows clusters with activity in the last...
1h 1 hour
24h 24 hours (default)
7d 7 days
30d 30 days
60d 60 days
90d 90 days

Time filters apply to the cluster's most recent article timestamp, not when the cluster was first created.

Content Type Filters

Filter what appears in your feed:

  • All -- shows both clusters and standalone articles.
  • Clusters only -- hides standalone articles, showing only grouped threat clusters.
  • Articles only -- shows individual articles without clustering.
Note: Most users prefer "Clusters only" for a cleaner view. Switch to "All" when investigating a specific topic where you want every source visible.

Category Sections

Clusters are automatically assigned to categories based on their content. Categories group related threats together in the feed, making it easy to scan by topic area. Examples include ransomware, vulnerability disclosures, nation-state activity, and data breaches.

Each category section shows its clusters ranked by the active feed type (trending, hot, or latest).

Hero Grid

The top of the feed displays a hero grid featuring the three highest-scoring threats. These cards are larger, include AI-generated summaries, and auto-rotate to cycle through top stories.

The hero grid only appears on the first page of the feed and pulls from whichever feed type is currently active.

Tip: Click any hero card to jump directly into the full cluster view with all related articles and entities.

On the right side of the feed, the trending entities sidebar shows entities that are spiking in mention volume. This includes threat actors, malware families, CVEs, and tools that are appearing across multiple clusters.

Click any entity in the sidebar to filter the feed to clusters containing that entity, or visit the entity's dedicated page to see its full history.

Understanding Cluster Cards

Each cluster card in the feed displays:

Element Meaning
Threat Score A 0-100 score reflecting severity, activity volume, and recency. Displayed as a color-coded bar (green/yellow/orange/red). Rounded to the nearest 10.
Title AI-generated summary title describing the cluster's topic.
Entity Badges Extracted entities (APT groups, malware, CVEs, etc.) shown as clickable badges.
Source Count Number of unique articles in the cluster. More sources generally means higher confidence and broader impact.
Timestamp When the most recent article in the cluster was published.
Category The cluster's assigned category label.

Threat Score Breakdown

Range Color Meaning
80-100 Red Critical -- active exploitation, major breaches, zero-days
60-79 Orange High -- significant threats with broad coverage
40-59 Yellow Medium -- notable but limited impact or early-stage reporting
0-39 Green Low -- informational, minor, or historical

Inside a Cluster

Click any cluster card to open its detail view. Inside you'll find:

  • All related articles -- every source reporting on this threat, with links to originals.
  • Extracted entities -- full list of threat actors, malware, CVEs, tools, and other entities mentioned across all articles.
  • AI summary -- a generated overview synthesizing key details from all sources.
  • Timeline -- a chronological view showing when each article was published, so you can see how the story developed.
  • Entity relationships -- how entities in this cluster connect to other clusters and threats.
Note: The article list inside a cluster is sorted by publication time. The newest reporting appears first.

Tips for Effective Monitoring

  • Start with Trending for your daily briefing -- it balances recency with significance.
  • Check Hot periodically throughout the day to catch breaking incidents early.
  • Use My Feed as your primary view once you've configured keywords and onboarding preferences.
  • Combine time filters with feed types -- for example, Hot + 1h shows threats that spiked in the last hour.
  • Click entity badges to pivot from one cluster into the broader context of a threat actor or vulnerability.