Threadlinqs Intelligence — Platform Statistics
Threadlinqs Intelligence is a free, public cyber-threat-intelligence corpus. Each profiled threat carries deployable detection logic in Splunk SPL, Microsoft KQL and Sigma, extracted indicators of compromise, enriched CVE references and MITRE ATT&CK technique mapping. The figures below describe the entire corpus, not a sample.
Data as of . Corpus counts are recomputed nightly; last recomputed .
- 2,313 profiled threats
- 21,256 detection rules across SPL, KQL and Sigma
- 59,186 indicators of compromise (IOCs)
- 669 attributed threat actors
- 826 distinct techniques observed — 788 MITRE ATT&CK techniques plus 38 MITRE ATLAS (adversarial-ML) techniques
- 698 techniques observed on more than one threat, the basis of cross-threat correlation
- 1,670 prioritized CVEs in the live vulnerability feed
Corpus composition
Share of the 2,313 profiled threats by assessed severity:
| Severity | Threats | Share of corpus |
|---|---|---|
| CRITICAL | 715 | 30.9% |
| HIGH | 1,334 | 57.7% |
| MEDIUM | 227 | 9.8% |
| LOW | 11 | 0.5% |
| Other (informational or unrated) | 26 | 1.1% |
By threat category
The eight largest categories by threat count:
| Category | Threats | Share of corpus |
|---|---|---|
| VULNERABILITY | 705 | 30.5% |
| MALWARE | 606 | 26.2% |
| SUPPLY CHAIN | 242 | 10.5% |
| PHISHING | 166 | 7.2% |
| RANSOMWARE | 150 | 6.5% |
| APT | 141 | 6.1% |
| THREAT INTEL | 129 | 5.6% |
| DATA BREACH | 57 | 2.5% |
Sources and related views: daily debriefs, live CVE feed, ATT&CK coverage map. Programmatic access via the MCP server and REST API (Purple tier). Free machine-readable feeds: STIX 2.1, MISP and a C2 blocklist.
Threadlinqs Intelligence — Real-Time Threat Detection Platform
// threat_feed
$ sort --newest
Showing all threats