Anomali ThreatStream TAXII feeds
ThreatStream already scores and dedupes your observables. Add Q-Feeds over TAXII and it does that against curated indicators from more than 2,500 sources.
- 2,500+Intelligence sources
- 20 minUpdate interval
- 5 minTo full integration
- 100%Made in Europe
What is the Q-Feeds and ThreatStream integration?
ThreatStream is built to turn many suppliers into one picture. Q-Feeds is a strong addition to that mix: a single curated stream drawn from more than 2,500 commercial, OSINT and governmental sources, filtered for false positives and refreshed every 20 minutes.
Because Q-Feeds publishes over TAXII 2.1, ThreatStream ingests it with the feed setup it already supports. Nothing is custom built, and our indicators keep their own source label, so you can see exactly what Q-Feeds contributed to a verdict.
Malicious IP addresses, domains, URLs and file hashes arrive as observables your analysts and playbooks can act on straight away, each with its category and MITRE ATT&CK mapping. TAXII is part of the Enterprise licence.
One source, added once
Register Q-Feeds once and every collection you subscribe to becomes available from it. You choose how often ThreatStream fetches, and it keeps that source current from then on.
- One source for all the collections you take
- Fetch interval you control
Ready for scoring and response
Q-Feeds indicators become observables in ThreatStream, so they pass through the same confidence scoring and deduplication as the rest of your intelligence and turn up in investigations on their own.
- Scored and deduplicated with your other sources
- Available to the playbooks you already run
What we offer
Always ahead
Intelligence that updates every 20 minutes, so you are always ahead of the attackers.
Automatic response
Trust automated response actions and reduce the manual work needed to stop the latest threats.
Categories
Focus on what matters most, phishing, botnets, dark web and more crafted categories.
Knowledge
Knowledge is power when fighting threats. We take the knowledge part off your hands.
Easy implementation
You never did an implementation this easy. Follow our concise implementation guide and you are good to go.
Fewer false positives
We filter out false positives, so you never waste valuable resources chasing noise.
Add Q-Feeds to ThreatStream in 4 steps
Create your free account
Sign up on the Q-Feeds Threat Intelligence Portal and pick the collections that match your risk. Your TAXII credentials are waiting for you there.
Register Q-Feeds as a source
In ThreatStream your administrator adds Q-Feeds once with those credentials. Every collection you subscribe to then shows up ready to use.
Choose what you take
Add the collections you want and set how often ThreatStream fetches them, so you only ingest the intelligence that is relevant to your organisation.
Score, investigate, respond
New observables run through your existing scoring and playbooks, and analysts see Q-Feeds context on an indicator without leaving ThreatStream.
Explore other TI platform integrations
Frequently asked questions about the ThreatStream integration
What does Q-Feeds add to ThreatStream?
One more source worth scoring. More than 2,500 commercial, OSINT and governmental sources are consolidated into a single prioritised stream, filtered for false positives and refreshed every 20 minutes.
Do we need a custom integration?
No. Q-Feeds publishes over TAXII 2.1, which ThreatStream ingests with its standard feed setup. Your administrator adds it in minutes and there is nothing bespoke to maintain.
Which indicators do we get?
Malicious IP addresses, domains, URLs and file hashes, each with its category and MITRE ATT&CK mapping so analysts can see why it is on the list.
Can we evaluate it first?
Yes. Any TAXII 2.1 client reads the same collections, and the free Community edition gives you the IP and domain lists through our feeds and API, so you can judge the quality before it goes into production.
Which licence do we need?
TAXII is part of the Enterprise licence. The ThreatStream setup guide in our knowledge base walks an administrator through the configuration.
Evaluate our intelligence today!
Simplify your security operations, start your free Q-Feeds trial and experience the difference.
Activate free access