CAPABILITIES
Threat Intelligence
Native to Stellar Cyber and working out of the box for free, the Threat
Intelligence Platform automatically aggregates multiple threat
intelligence feeds and distributes them in near real-time aggregations to
all deployments where data is enriched and threats are detected. Bring
your own feeds to customize for your mission.
How It Works
Stellar Cyber’s cloud-based Threat Intelligence Platform (TIP) aggregates multiple commercial, open-source, and government threat-intelligence feeds together in near real-time. The aggregated results are then distributed to every deployment of Stellar Cyber, on-premises or in the cloud. Each deployment uses the latest threat intelligence to enrich data as it is ingested for the most
efficient and effective detection and response.
The Threat Intelligence Platform is a key part of the enrichment backbone for creating Interflow – Stellar Cyber’s normalized and enriched data model.
Key Features
Multiple Feeds Included
Stellar Cyber’s TIP automatically aggregates multiple commercial, open-source, and government threat-intelligence feeds together with the ones from Stellar Cyber security research or those shared amongst deployments. Examples of included feeds are Proofpoint, DHS, OTX, OpenPhish and PhishTank. Feeds are prioritized based on security research so security data is only enriched once after threat intelligence aggregation.
Bring Your Own Feed
If Stellar Cyber does not have certain threat intelligence critical for your mission, you can integrate additional feeds directly into the platform with standards like STIX/TAXII. The added threat intelligence is contained to your deployment only.
Near Real-Time
The latest threat intelligence updates from all sources are automatically and constantly distributed to all Stellar Cyber deployments.
Near Real-Time
All included threat intelligence feeds and the Threat Intelligence Platform itself are provided at no additional cost.
Automatic
The Threat Intelligence Platform is always working in the background without any administrative overhead. It continuously collects, aggregates, prioritizes, and distributes feeds, and enriches data with them.