Threat intelligence feeds

Threat intelligence feeds built for active malware defense

High-confidence, curated feeds covering the malware families, C2 frameworks and ransomware used in real intrusions — ready to drop into your SIEM, firewall and threat-hunting workflow. Follow an indicator into the malware and infrastructure we've mapped around it, and pivot to the wider activity.

15-day free trial · no credit card · reply within one business day

Live from the feeds

Curated indicators, the moment they surface

High-confidence C2 and malware indicators, updated as often as every minute and verified with custom YARA rules.

FreeThe full ClickFix feed is free, forever —get it free →

Live feedUpdated 41s ago
First seenIndicatorTypeConfidence
-Loading live indicators…PendingMedium
-Loading live indicators…PendingMedium
-Loading live indicators…PendingMedium
-Loading live indicators…PendingMedium
-Loading live indicators…PendingMedium
Live indicators straight from our feed, shown defanged for safe browsing — the ↗ icon opens the full record in Indicator Search, free. Raw, real-time data via the REST API or a free trial.Explore the feeds →

Feed directory

Browse curated threat intelligence feeds

Explore coverage by malware family, C2 framework and malicious infrastructure type. Every feed detail page includes context for how the intelligence is collected, classified and delivered, and how indicators connect to the activity around them.

ClickFix

Free
Social engineeringInitial access

ClickFix is a fast-growing social-engineering technique that tricks users into running malicious commands themselves. PrecisionSec's ClickFix feed tracks active lure domains, distribution URLs and C2 infrastructure in real time.

View feed

Cobalt Strike

Featured
C2 frameworkBeacon

Detection of Cobalt Strike is often the last warning before ransomware. PrecisionSec's curated Cobalt Strike feed tracks active Beacon C2 infrastructure in real time.

View feed

Ransomware

Featured
RansomwareInfrastructure

Ransomware is the highest-impact threat most organizations face. PrecisionSec tracks active ransomware families and the precursor malware that leads to them, so you can break the attack chain before encryption.

View feed

Agent Tesla

Malware familyCredential theft

Agent Tesla is a .NET keylogger and credential stealer. PrecisionSec's curated Agent Tesla feed tracks active C2 and distribution infrastructure in real time.

View feed

AZORult

Malware familyInfostealer

AZORult is an information stealer and downloader. PrecisionSec's curated AZORult feed tracks active C2 and distribution infrastructure in real time.

View feed

Lokibot

Malware familyCredential theft

Lokibot is an information-stealing trojan. PrecisionSec's curated Lokibot feed tracks active C2 and distribution infrastructure in real time.

View feed

Nanocore RAT

RATC2

Nanocore is a .NET remote access trojan with a plugin architecture. PrecisionSec's curated Nanocore feed tracks active C2 and distribution infrastructure in real time.

View feed

njRAT

RATC2

njRAT (Bladabindi) is a .NET remote access trojan. PrecisionSec's curated njRAT feed tracks active C2 and distribution infrastructure in real time.

View feed

Malicious IP Feed

Featured
InfrastructureIPs

Real-time IP addresses tied to active malware distribution, C2 and phishing infrastructure. Every IP is attributed to a specific family and campaign, so you can block at the network perimeter with confidence.

View feed

Malicious Domain Feed

Featured
InfrastructureDomains

High-fidelity C2, malware-distribution and phishing domain intelligence tied to active campaigns, updated hourly. Every indicator is attributed to a specific family, framework or campaign so your team knows what it's blocking.

View feed

Malware URL Feed

Featured
InfrastructureURLs

Real-time malicious URL intelligence covering payload-distribution sites, C2 endpoints and phishing pages. Every URL is attributed to a specific family or campaign, so you can block the exact path without taking down a shared host.

View feed

Malware Hash Feed

File hashesMD5/SHA-256

Real-time malware file hashes (MD5, SHA-1, SHA-256) for detection, blocking and enrichment. Every hash is attributed to a specific family and campaign, so a single match tells you what the file is, not just that it's bad.

View feed

Evaluate PrecisionSec feeds in your workflow

Start a 15-day trial and test curated malware, C2, IP, domain and URL intelligence in your SIEM, TIP or threat-hunting process.

Request a 15-day trial