Know at once when a known bad address, domain or file shows up
UTMStack checks every event against threat intelligence from ThreatWinds and raises an alert the moment a known bad indicator appears. Analysts can look up any indicator, or ask the research workspace to investigate it and come back with a verdict, a dossier and a relationship graph.
Research workspace
Ask about an IP address, domain, file hash or web address. The analyst agent looks it up, pulls entity details and relations, checks your cases and watchlists, and writes a verdict with the evidence.
Checked on every event
The threat intelligence engine matches each incoming event against lists of malicious IP addresses, domains and file hashes.
Look up any indicator
Search an IP address, domain, file hash, web address or CVE and see its reputation, tags and when it was last seen.
Threat actors
Browse known threat actors and the indicators linked to them.
Hourly updates
Threat intelligence rules are updated every hour, so new indicators reach your detections quickly.
Add your own feeds
Bring in other sources, such as MISP or OpenCTI, with a plugin built on the open source development kit.
Questions buyers ask
Where does the threat intelligence come from?
UTMStack uses feeds from ThreatWinds that cover IP addresses, domains and file hashes linked to malware, botnets, spam, brute force attacks and scanning. You can add other sources with a custom plugin.
Is threat intelligence included in every edition?
Threat intelligence matching is built into the platform. UTMStack Enterprise adds more frequent threat intelligence updates.
Can I look up an indicator I received from a partner or an advisory?
Yes. Paste the IP address, domain, file hash, web address or CVE into the lookup to see its reputation and whether it has appeared in your data.
Related capabilities
- Threat detection600+ detection rules mapped to MITRE ATT&CK run on every event in real time. Tag false positives, mute noisy rules and see who is attacking whom.
- Log ExplorerSearch all your security logs with filters or SQL, save your searches, see related events and query cold data without restoring snapshots.
- Dark web monitoringMonitor the dark web for leaked staff credentials and company data, using InsecureWeb's 19 billion+ records, and act before attackers log in.
- AI assistantAsk questions about your security data, triage alerts, write rules and build dashboards with the UTMStack AI assistant. Use any of 10 model providers.
Protect your organization this week, not next quarter
Talk to an engineer today, or start using UTMStack in minutes.
Need to extend your SOC team?
Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.
Want to try UTMStack?
Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.