Intelligence Sources and Indicators

We ingest threat data from more than 200 sources, including dozens unique to us and our federal partners, and we carefully distill it down to the highest impact indicators for our members. Intelligence sharing can be bi-directional with this service. While we’ll always share information with all of our members, any members who are able can also share intelligence with us to benefit the broader community.

The MS- and EI-ISAC feeds contain the following types of indicators:

Domains
IPs (both v4 and v6)
Full URLs (references to specific web resources)
Email addresses
File hashes
Unique HTTP requests


As the data set grows and the feeds evolve, additional context surrounding these indicators will also be shared. This includes information such as registration information, relationships between indicators, associated threat groups, and more.