Threat intelligence

See which threats matter to the systems you run.

SecurityAlert matches your assets, technology, and user accounts to relevant threat actors, vulnerabilities, ransomware activity, and indicators. Each priority includes the information your team needs to understand why it is there.

895 actor profilesMITRE ATT&CK groups plus reviewed ransomware and open-source intelligence.
390,664 CVEsLocal NVD mirror enriched with KEV, EPSS, ransomware, and ATT&CK context.
56 threat campaignsCampaign timelines, attributed actors, targets, sources, and related research.
23 live publisher feedsChecked throughout the day and joined with 5 structured intelligence datasets.
Source coverage

New threat reporting, collected throughout the day

SecurityAlert keeps the publisher, original link, publication time, and collection time with every item. Official advisories and established research carry more weight than community posts.

Government

Warnings from national cyber agencies

UK NCSCCERT-EU

Official threat reports and security advisories are checked every 15 minutes.

Security news

Reporting that helps confirm a developing story

BleepingComputerThe Hacker NewsDark ReadingSecurityWeek

Headlines are retained with their original source and never presented as first-party findings.

Security research

Technical research from established teams

Google Threat IntelligenceUnit 42SentinelLABSElasticESETRapid7

Research is connected to known actors, campaigns, CVEs, malware, and techniques when the evidence supports it.

Vulnerability data

Structured records and coordinated disclosures

NVDCISA KEVFIRST EPSSMITRE ATT&CKabuse.chCERT/CC

These sources supply vulnerability, exploitation, technique, and indicator context beyond general reporting.

Vendor advisories

Get security advisories straight from the vendor

Microsoft MSRCCitrixCisco PSIRTPalo Alto PSIRTFortinet PSIRTIvantiDelineaUbuntu SecurityAWS Security

We keep the advisory ID, severity, affected products, CVEs, dates, and fix guidance, then match each update to the technology you watch.

Community signals

Early discussion, kept separate from verified reporting

Reddit r/netsec

Community posts can surface a lead, but they cannot establish attribution or prove that your environment is affected.

Relevant threats

Why a threat appears on your list

SecurityAlert only marks a threat as relevant when it can connect that threat to information about your environment. Activity in your industry is still useful, but it is shown as background rather than as a finding about your company.

Relevant threats

Threats connected to your environment

See which of your assets, technologies, or accounts connects to a CVE, threat actor, indicator, or ransomware report.

Threat actors

One profile for each threat actor

Review names, relationships, campaigns, victims, infrastructure, malware, tools, techniques, CVEs, and dated activity in one place.

Campaigns

Follow a campaign from first sighting to current activity

Review the timeline, attributed actors, targets, and source material. Actor-level CVEs, techniques, malware, and indicators are clearly labeled as context.

Vulnerabilities

What raises a CVE's risk

Compare CVSS with CISA KEV, EPSS probability, known ransomware use, affected software, actor links, ATT&CK techniques, and recent activity.

Ransomware

Ransomware groups and their victims

Follow leak-site operators across two sources. SecurityAlert merges duplicate reports and keeps observed dates separate from dates claimed by an operator.

Identity

Security events tied to an account

Match authorized directory details with events for a specific account. Unattributed domain-wide counts are shown separately as background.

Infrastructure

Find domains on related infrastructure

Search our registrant, WHOIS, passive DNS, and nameserver data, then watch that infrastructure for newly registered domains.

Organization context

Explain what your team cares about

Add your important technologies, regions, suppliers, and threat priorities. Verified assets still decide whether a threat affects you.

Monitors

Watch a narrow question over time

Monitor campaigns, actors, CVEs, malware, sectors, or indicators by keyword and condition, then see exactly what changed.

Briefings

Build the update your audience needs

Save evidence as you investigate, add an analyst conclusion, and require review before a briefing can be delivered.

Public research

Investigate a threat without leaving the site

Our public catalog includes permanent actor and CVE pages, ATT&CK views you can filter by industry, free research tools, sourced news, WHOIS, and infrastructure searches.

You can explore our threat data for free.

Research campaigns, actors, CVEs, ransomware activity, ATT&CK, security news, and investigation tools. A Business workspace connects that research to your environment and lets you monitor, investigate, and brief your team.