ThreatConnect TAXII from Q-Feeds
ThreatConnect already drives your intelligence and response workflows. Add Q-Feeds over TAXII and those workflows run on curated indicators from more than 2,500 sources.
- 2,500+Intelligence sources
- 20 minUpdate interval
- 5 minTo full integration
- 100%Made in Europe
What is the Q-Feeds and ThreatConnect integration?
ThreatConnect brings intelligence, analysis and response together in one place. Q-Feeds supplies the raw material: one curated stream drawn from more than 2,500 commercial, OSINT and governmental sources, filtered for false positives and refreshed every 20 minutes.
ThreatConnect ingests Q-Feeds with the TAXII app from its own catalogue, so there is no development work and no playbook to write. Indicators arrive as native ThreatConnect types, which means your existing tags, scoring and automation apply to them from the first run.
Each collection you subscribe to is added as its own source, so ransomware, botnet and phishing intelligence stay apart and you can report on what each one contributed. TAXII is part of the Enterprise licence.
Added from the app catalogue
Your administrator installs ThreatConnect's own TAXII app once, then points it at the Q-Feeds collections you subscribe to. It is the vendor's supported route, so keeping it current is their job and not yours.
- Supported ingestion, no bespoke code
- Set up once, then add collections as you need them
Scored, tagged and automated
Because Q-Feeds indicators land as native types, they inherit the tags, scoring and playbooks you already run. Analysts see our context on an indicator without leaving ThreatConnect.
- Category and MITRE ATT&CK context per indicator
- Works with the playbooks you have today
What we offer
Always ahead
Intelligence that updates every 20 minutes, so you are always ahead of the attackers.
Automatic response
Trust automated response actions and reduce the manual work needed to stop the latest threats.
Categories
Focus on what matters most, phishing, botnets, dark web and more crafted categories.
Knowledge
Knowledge is power when fighting threats. We take the knowledge part off your hands.
Easy implementation
You never did an implementation this easy. Follow our concise implementation guide and you are good to go.
Fewer false positives
We filter out false positives, so you never waste valuable resources chasing noise.
Add Q-Feeds to ThreatConnect in 4 steps
Create your free account
Sign up on the Q-Feeds Threat Intelligence Portal and choose the collections that match your risk. Your TAXII credentials are waiting for you there.
Install the TAXII app
ThreatConnect publishes a supported TAXII app in its own catalogue. Your administrator installs it once, and nothing has to be developed in house.
Add each collection
Point the app at a Q-Feeds collection and it becomes its own source in ThreatConnect. Repeat for each collection so you can keep them apart and report on them separately.
Let your workflows run
New indicators pick up your tags and scoring and feed the playbooks you already have, so detection and response happen without extra work from your team.
Explore other TI platform integrations
Frequently asked questions about the ThreatConnect integration
What does Q-Feeds add to ThreatConnect?
Intelligence worth acting on. More than 2,500 commercial, OSINT and governmental sources are consolidated into one prioritised stream, filtered for false positives and refreshed every 20 minutes.
Do we need custom development?
No. ThreatConnect offers a supported TAXII app in its own catalogue and Q-Feeds publishes over TAXII 2.1, so there is no bespoke code and no playbook needed to get the data in.
Which indicators do we get?
Malicious IP addresses, domains, URLs and file hashes, mapped to native ThreatConnect indicator types with their category and MITRE ATT&CK context.
Can we keep collections apart?
Yes. Every Q-Feeds collection is added as its own source, so ransomware, botnet and phishing intelligence stay separate and you can measure the value of each.
Which licence do we need?
TAXII is part of the Enterprise licence. The ThreatConnect setup guide in our knowledge base takes an administrator through the whole configuration.
Evaluate our intelligence today!
Simplify your security operations, start your free Q-Feeds trial and experience the difference.
Activate free access