Threadlinqs Intelligence — Platform Statistics

Threadlinqs Intelligence is a free, public cyber-threat-intelligence corpus. Each profiled threat carries deployable detection logic in Splunk SPL, Microsoft KQL and Sigma, extracted indicators of compromise, enriched CVE references and MITRE ATT&CK technique mapping. The figures below describe the entire corpus, not a sample.

Data as of . Corpus counts are recomputed nightly; last recomputed .

  • 2,313 profiled threats
  • 21,256 detection rules across SPL, KQL and Sigma
  • 59,186 indicators of compromise (IOCs)
  • 669 attributed threat actors
  • 826 distinct techniques observed — 788 MITRE ATT&CK techniques plus 38 MITRE ATLAS (adversarial-ML) techniques
  • 698 techniques observed on more than one threat, the basis of cross-threat correlation
  • 1,670 prioritized CVEs in the live vulnerability feed

Corpus composition

Share of the 2,313 profiled threats by assessed severity:

SeverityThreatsShare of corpus
CRITICAL71530.9%
HIGH1,33457.7%
MEDIUM2279.8%
LOW110.5%
Other (informational or unrated)261.1%

By threat category

The eight largest categories by threat count:

CategoryThreatsShare of corpus
VULNERABILITY70530.5%
MALWARE60626.2%
SUPPLY CHAIN24210.5%
PHISHING1667.2%
RANSOMWARE1506.5%
APT1416.1%
THREAT INTEL1295.6%
DATA BREACH572.5%

Sources and related views: daily debriefs, live CVE feed, ATT&CK coverage map. Programmatic access via the MCP server and REST API (Purple tier). Free machine-readable feeds: STIX 2.1, MISP and a C2 blocklist.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats