# Threadlinqs Intelligence > Live cyber-threat-intelligence platform: 2524+ profiled threats, 23155+ detections (Splunk SPL, Microsoft KQL, Sigma), 63536+ IOCs, 2219+ enriched CVEs, MITRE ATT&CK coverage and daily debriefs. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Usage: free to read, quote and cite, with attribution to Threadlinqs Intelligence and a link back to the page the material came from. Bulk redistribution of the corpus as a dataset is not permitted. Freshness: this file was generated 2026-09-28T06:00:28.847Z. The corpus counts above were computed 2026-09-28T06:00:28.314Z and are refreshed on ingest (at most 25h old). ## Threat intelligence (public, crawlable) - Threat pages: https://intel.threadlinqs.com/threat/TL-YYYY-NNNN (append `.md` for clean Markdown) - CVE pages: https://intel.threadlinqs.com/cve/CVE-YYYY-NNNN (append `.md` for Markdown) - Threat-actor pages: https://intel.threadlinqs.com/actor/ (append `.md` for Markdown) - Daily debrief: https://intel.threadlinqs.com/debrief (Markdown twin: https://intel.threadlinqs.com/debrief.md) - Live CVE feed: https://intel.threadlinqs.com/vulnerabilities - Platform statistics: https://intel.threadlinqs.com/statistics - ATT&CK coverage: https://intel.threadlinqs.com/coverage - Sitemap index: https://intel.threadlinqs.com/sitemap-index.xml - RSS (latest threats): https://intel.threadlinqs.com/feed.xml · JSON Feed: https://intel.threadlinqs.com/feed.json - Filtered feeds (swap `.xml` for `.json` for JSON Feed): https://intel.threadlinqs.com/feed/severity/.xml · https://intel.threadlinqs.com/feed/category/.xml · https://intel.threadlinqs.com/feed/actor/.xml ( as in the actor page URL) ### Example entities (live, fetchable now) - Threat: https://intel.threadlinqs.com/threat/TL-2026-0002 (Markdown twin: /threat/TL-2026-0002.md) - Threat: https://intel.threadlinqs.com/threat/TL-2026-0004 - CVE: https://intel.threadlinqs.com/cve/CVE-2024-3400 (Markdown twin: /cve/CVE-2024-3400.md) - CVE: https://intel.threadlinqs.com/cve/CVE-2021-44228 - Threat actor: https://intel.threadlinqs.com/actor/Lazarus%20Group (Markdown twin: /actor/Lazarus%20Group.md) ## Free machine-readable feeds - STIX 2.1 + TAXII 2.1 + native MISP feeds: see https://intel.threadlinqs.com/mcp for endpoints - Free C2 blocklist: generated from live C2 tracking (see MCP docs) ## MCP — AI-agent access (v8.2.0, Purple tier) - Official MCP registry: com.threadlinqs/intelthreadlinqs-mcp - Source (MIT): https://github.com/threadlinqs-cmd/intelthreadlinqs-mcp - npm: intelthreadlinqs-mcp — `npx -y intelthreadlinqs-mcp` (stdio, THREADLINQS_API_KEY) - Remote: POST https://intel.threadlinqs.com/mcp (Streamable-HTTP, OAuth 2.1) - Manifest: https://intel.threadlinqs.com/.well-known/mcp.json - Docs: https://intel.threadlinqs.com/mcp (Markdown twin: /mcp.md) - Agent skill: https://intel.threadlinqs.com/mcp/skill.md (single file) · https://intel.threadlinqs.com/skills/intelthreadlinqs-mcp-skill.zip - Machine catalog (no key required): https://intel.threadlinqs.com/mcp/catalog.json 81 tools and 25 analyst-playbook prompts: search_threats, get_threat, hunt (TLQL over a 106k-row observation index), search_detections, search_iocs, get_cve_intelligence, get_actor, get_attribution_evidence, explain_correlation, get_mitre_coverage, get_c2, get_correlations, get_osint_trends, list_debriefs, export_stix and more. Purple or Gold subscription required (tier >= 3). ## Company, reference and blog (threadlinqs.com) - About: https://threadlinqs.com/about - Editorial standards: https://threadlinqs.com/editorial - Security and disclosure: https://threadlinqs.com/security - Platform overview: https://threadlinqs.com/platform/ - Glossary: https://threadlinqs.com/resources/glossary/ - Blog (in-depth reports with SPL/KQL/Sigma detections): https://threadlinqs.com/blog/ ## Pricing, access and contact - Pricing and tiers (Blue free, Red, Purple $11.99/mo, Gold enterprise): https://threadlinqs.com/pricing (Markdown twin: https://intel.threadlinqs.com/pricing.md) - Contact: contact@threadlinqs.com - Enterprise / Gold enquiries: https://threadlinqs.com/contact ## Legal - Privacy: https://threadlinqs.com/privacy - Terms: https://threadlinqs.com/terms - Cookies: https://threadlinqs.com/cookies - Do not sell my personal information: https://threadlinqs.com/do-not-sell ## Sitemaps - Marketing site: https://threadlinqs.com/sitemaps/marketing.xml - Blog: https://threadlinqs.com/sitemaps/blog.xml - Intelligence corpus (index): https://intel.threadlinqs.com/sitemap-index.xml ## Companion files - Full bundle (this index plus live corpus extracts): https://intel.threadlinqs.com/llms-full.txt - The other host's index: https://threadlinqs.com/llms.txt