UTMStack

Know at once when a known bad address, domain or file shows up

UTMStack checks every event against threat intelligence from ThreatWinds and raises an alert the moment a known bad indicator appears. Analysts can look up any indicator, or ask the research workspace to investigate it and come back with a verdict, a dossier and a relationship graph.

UTMStack · Threat Intelligence
The Threat Intelligence screen: a research workspace that investigates an indicator step by step and returns a verdict with its dossier and relationship graph, plus indicator matches by type and a table of indicators with reputation, tags and last-seen dates.
  • Research workspace

    Ask about an IP address, domain, file hash or web address. The analyst agent looks it up, pulls entity details and relations, checks your cases and watchlists, and writes a verdict with the evidence.

  • Checked on every event

    The threat intelligence engine matches each incoming event against lists of malicious IP addresses, domains and file hashes.

  • Look up any indicator

    Search an IP address, domain, file hash, web address or CVE and see its reputation, tags and when it was last seen.

  • Threat actors

    Browse known threat actors and the indicators linked to them.

  • Hourly updates

    Threat intelligence rules are updated every hour, so new indicators reach your detections quickly.

  • Add your own feeds

    Bring in other sources, such as MISP or OpenCTI, with a plugin built on the open source development kit.

Investigate an indicator in one question

The research workspace, powered by the ThreatWinds analyst, runs the lookups an analyst would: reputation and accuracy, first and last sightings, related infrastructure, and whether the indicator is already in your cases or watchlists. Each result opens as a window on the canvas, with a dossier and a graph of linked addresses, domains and hashes that you can click through.

  • Verdict with reputation, accuracy and the best and worst scores on record
  • Relationship graph colored by malicious, unknown and benign
  • Conversations saved so you can return to an investigation

Intelligence where detection happens

Threat intelligence in UTMStack is not a separate lookup tool on the side. The same engine that correlates your logs checks each event against known indicators, so a match raises an alert in real time. Empty field values are ignored when matching, which cuts false matches.

Context for every alert

UTMStack adds location data to IP addresses, including country, city and the network that owns the address. It can also map internal addresses to departments and how critical they are. Analysts see at a glance whether a match hit a test laptop or a payment server.

Feeds you can see

The Threat Intelligence page lists the active feeds, how many indicators of each type matched over time, and the details behind each match. Analysts can open an indicator and check its reputation before deciding what to block.

Questions buyers ask

Where does the threat intelligence come from?

UTMStack uses feeds from ThreatWinds that cover IP addresses, domains and file hashes linked to malware, botnets, spam, brute force attacks and scanning. You can add other sources with a custom plugin.

Is threat intelligence included in every edition?

Threat intelligence matching is built into the platform. UTMStack Enterprise adds more frequent threat intelligence updates.

Can I look up an indicator I received from a partner or an advisory?

Yes. Paste the IP address, domain, file hash, web address or CVE into the lookup to see its reputation and whether it has appeared in your data.

Protect your organization this week, not next quarter

Talk to an engineer today, or start using UTMStack in minutes.

Need to extend your SOC team?

Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.

Want to try UTMStack?

Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.