Threat intelligence feeds
Threat intelligence feeds built for active malware defense
High-confidence, curated feeds covering the malware families, C2 frameworks and ransomware used in real intrusions — ready to drop into your SIEM, firewall and threat-hunting workflow. Follow an indicator into the malware and infrastructure we've mapped around it, and pivot to the wider activity.
15-day free trial · no credit card · reply within one business day
Live from the feeds
Curated indicators, the moment they surface
High-confidence C2 and malware indicators, updated as often as every minute and verified with custom YARA rules.
FreeThe full ClickFix feed is free, forever —get it free →
| First seen | Indicator | Type | Confidence |
|---|---|---|---|
| - | Loading live indicators… | Pending | Medium |
| - | Loading live indicators… | Pending | Medium |
| - | Loading live indicators… | Pending | Medium |
| - | Loading live indicators… | Pending | Medium |
| - | Loading live indicators… | Pending | Medium |
Choose by use case
Find the feeds that match your workflow
Whether you're blocking infrastructure, enriching alerts or evaluating integrations, start with the outcome your team needs first.
Block active malware infrastructure
Prioritize C2 domains, malicious IPs and payload URLs tied to real intrusion activity.
Browse infrastructure feeds →Infostealer detectionFollow infostealers from sample to infrastructure
Get malware hashes, payload URLs, domains and C2 IPs tied to the infostealer activity PrecisionSec discovers.
Explore infostealer intelligence →SOC enrichmentAdd context to alerts and investigations
Give analysts high-confidence malware-family and framework context inside their existing workflow — and where we've mapped it, one alert opens onto the related samples, infrastructure and campaign.
See integrations →Triage & verificationCheck a single indicator on demand
Look up any IP, domain or hash against our live data when you do not need a full feed subscription. Free, in your browser, no signup.
Try Indicator Search →Operational deliveryPush indicators into your stack fast
Operationalize feed data through STIX/TAXII, MISP, Microsoft Sentinel, CSV, JSON and REST API access.
Explore delivery options →Feed directory
Browse curated threat intelligence feeds
Explore coverage by malware family, C2 framework and malicious infrastructure type. Every feed detail page includes context for how the intelligence is collected, classified and delivered, and how indicators connect to the activity around them.
ClickFix
FreeClickFix is a fast-growing social-engineering technique that tricks users into running malicious commands themselves. PrecisionSec's ClickFix feed tracks active lure domains, distribution URLs and C2 infrastructure in real time.
View feedCobalt Strike
FeaturedDetection of Cobalt Strike is often the last warning before ransomware. PrecisionSec's curated Cobalt Strike feed tracks active Beacon C2 infrastructure in real time.
View feedRansomware
FeaturedRansomware is the highest-impact threat most organizations face. PrecisionSec tracks active ransomware families and the precursor malware that leads to them, so you can break the attack chain before encryption.
View feedAgent Tesla
Agent Tesla is a .NET keylogger and credential stealer. PrecisionSec's curated Agent Tesla feed tracks active C2 and distribution infrastructure in real time.
View feedAZORult
AZORult is an information stealer and downloader. PrecisionSec's curated AZORult feed tracks active C2 and distribution infrastructure in real time.
View feedLokibot
Lokibot is an information-stealing trojan. PrecisionSec's curated Lokibot feed tracks active C2 and distribution infrastructure in real time.
View feedNanocore RAT
Nanocore is a .NET remote access trojan with a plugin architecture. PrecisionSec's curated Nanocore feed tracks active C2 and distribution infrastructure in real time.
View feednjRAT
njRAT (Bladabindi) is a .NET remote access trojan. PrecisionSec's curated njRAT feed tracks active C2 and distribution infrastructure in real time.
View feedMalicious IP Feed
FeaturedReal-time IP addresses tied to active malware distribution, C2 and phishing infrastructure. Every IP is attributed to a specific family and campaign, so you can block at the network perimeter with confidence.
View feedMalicious Domain Feed
FeaturedHigh-fidelity C2, malware-distribution and phishing domain intelligence tied to active campaigns, updated hourly. Every indicator is attributed to a specific family, framework or campaign so your team knows what it's blocking.
View feedMalware URL Feed
FeaturedReal-time malicious URL intelligence covering payload-distribution sites, C2 endpoints and phishing pages. Every URL is attributed to a specific family or campaign, so you can block the exact path without taking down a shared host.
View feedMalware Hash Feed
Real-time malware file hashes (MD5, SHA-1, SHA-256) for detection, blocking and enrichment. Every hash is attributed to a specific family and campaign, so a single match tells you what the file is, not just that it's bad.
View feedNo feeds match your search.
Built to deploy
Deliver intelligence where your team already works
PrecisionSec feeds are designed for operational security teams, from SIEM enrichment and TIP workflows to firewall blocking and analyst-led investigations.
- Microsoft SentinelCurated, high-confidence indicators delivered into Sentinel's threat intelligence, each carrying the malware, C2 and phishing context your analysts need to triage a match fast.
- MISPHigh-confidence, curated indicators for malware, C2 and phishing infrastructure, delivered as native MISP feeds so your analysts correlate real threats instead of triaging noise.
- OpenCTIEvery indicator arrives linked to the malware and campaign it belongs to, with stable STIX IDs so it merges into your existing entities instead of piling up duplicates.
- MaltegoPivot from IOCs to malware families, C2 and phishing infrastructure, and related context inside Maltego investigations.
- FortiGatePrecisionSec supplies curated IP, domain and SHA-256 hash threat feeds that FortiGate pulls in through native External Connectors, so your firewall blocks freshly-seen malicious infrastructure without manual list maintenance.
- STIX/TAXIIDeliver standards-based threat intelligence to TAXII-compatible SIEM, TIP and security tools.
Evaluate PrecisionSec feeds in your workflow
Start a 15-day trial and test curated malware, C2, IP, domain and URL intelligence in your SIEM, TIP or threat-hunting process.