Threat Intelligence Aggregator

Aggregate and deduplicate IOCs - IPs, domains, URLs, hashes - search across feeds, look up indicators via OTX and AbuseIPDB, and export CSV, JSON or STIX.

Advertisement

Threat Intelligence Feed Aggregator for Defensive IOC Research

This aggregator collects indicators of compromise (IOCs) — IP addresses, domains, URLs, file hashes and email addresses — into one searchable workspace, removes duplicate indicators, and lets you organise them into collections and export them for an investigation. It is a defensive tool for blue teams, SOC analysts and incident responders who need to pull scattered threat data together, enrich a suspicious indicator, and hand a clean, deduplicated set to a SIEM, a firewall block list or a report. Everything is oriented around research and defence: looking indicators up, not attacking anything.

The daily problem in threat intelligence is fragmentation. Indicators arrive from many feeds in different formats, the same malicious IP shows up in five of them, and analysts waste time reconciling overlaps by hand. Aggregation and deduplication turn that noise into a single authoritative list you can act on.

What the Aggregator Does

  • Aggregate IOCs from stored indicators and a catalog of threat feeds into one view, tagged by type and severity.
  • Deduplicate indicators so the same IP, domain or hash appears once, with its sources merged, rather than many times.
  • Search and filter by indicator value, type (IP, domain, URL, hash, email) and severity, so you can focus on what matters for the current case.
  • Look up an indicator live: when you search a value, the tool can query external providers to enrich it with reputation data.
  • Organise into collections — group related indicators for a specific investigation or campaign.
  • Export the result as CSV, JSON, plain text or STIX, so it drops straight into a SIEM, a block list, a ticket or another threat-intel platform.

Which Sources It Uses

It is important to be precise about where the data comes from. The tool maintains a catalog of well-known threat feeds — including AlienVault OTX, AbuseIPDB, abuse.ch URLhaus, Blocklist.de, SANS ISC and others — that it lists as available sources. For live indicator enrichment, when you look up a specific value, the tool queries AlienVault OTX and AbuseIPDB and merges their results with any indicators already stored. Some feeds in the catalog require your own API credentials to pull from, which is normal for threat intelligence — providers gate bulk access behind keys. Treat the catalog as the set of sources the tool knows about, and OTX plus AbuseIPDB as the ones consulted for on-demand lookups.

How to Use the Aggregator

  1. Search or browse indicators. Enter an IP, domain, URL or hash to search stored IOCs and trigger a live lookup, or browse the aggregated list.
  2. Filter to your case. Narrow by indicator type and severity to cut a large set down to the relevant few.
  3. Enrich a suspicious value. Look it up to pull reputation context from OTX and AbuseIPDB before you decide to block or escalate.
  4. Build a collection. Group the indicators tied to one investigation so they stay together.
  5. Export for action. Choose CSV, JSON, plain text or STIX depending on where the list is going — a firewall, a SIEM, a report or another platform.

Understanding IOC Types

Different indicator types are actioned differently, and mixing them up weakens a response. IP addresses are the most volatile — attackers rotate them quickly, so an IP block is often short-lived. Domains are longer-lived and better for detection and sinkholing. URLs pinpoint a specific malicious page or payload location. File hashes (typically SHA-256) are the most durable and precise: a hash identifies an exact file regardless of where it is hosted, which is why hash-based blocking rarely produces false positives. Email addresses tie indicators to phishing and business-email-compromise campaigns. The aggregator detects and labels each type automatically so you can filter and export the right ones for each control.

Why Deduplication and Export Formats Matter

Deduplication is not cosmetic. A block list with the same indicator repeated dozens of times wastes rule capacity and obscures how many distinct threats you actually face; merging duplicates while preserving the union of their sources gives you both a clean list and full provenance. Export format matters just as much: CSV suits spreadsheets and simple imports, JSON suits scripts and APIs, plain text suits quick block-list ingestion, and STIX is the structured standard that other threat-intelligence platforms understand, so it is the right choice when you are sharing indicators with partners or feeding a TIP. Choosing the format that matches the destination avoids lossy manual reformatting.

Frequently Asked Questions

Is this an offensive tool?

No. It is a defensive research tool. It aggregates, deduplicates, enriches and exports indicators of compromise so defenders can detect and block threats. It does not attack anything.

Which sources does it query for live lookups?

On-demand indicator lookups query AlienVault OTX and AbuseIPDB and merge their reputation data with stored indicators. The broader feed catalog lists additional well-known sources the tool knows about.

What indicator types does it handle?

IP addresses, domains, URLs, file hashes and email addresses. Each is detected and labelled automatically so you can filter and export by type.

What export formats are supported?

CSV, JSON, plain text and STIX. STIX is the structured standard for sharing indicators between threat-intelligence platforms.

Why deduplicate indicators?

Because the same IP, domain or hash appears across many feeds. Deduplication produces one authoritative entry per indicator — with sources merged — so block lists and detections are clean and accurate.

Do I need API keys?

Some feeds in the catalog require your own provider credentials for bulk access, which is standard for threat intelligence. On-demand enrichment via the built-in providers does not require you to configure keys in the interface.

Which hash type should I prefer for blocking?

SHA-256 is the most reliable: it uniquely identifies a file regardless of where it is hosted, so hash-based detection rarely false-positives, unlike volatile IP indicators.

Confidence, Severity and Avoiding False Positives

Aggregating indicators is only half the job; acting on them responsibly is the other half. Not every indicator in a feed deserves an automatic block. Feeds vary in quality, indicators age, and a shared hosting IP or a popular CDN domain can appear on a block list because one tenant misbehaved — blocking it outright can take down legitimate services. This is why the aggregator tracks severity and lets you filter on it, and why enrichment through OTX and AbuseIPDB matters: a second opinion on an indicator's reputation and recency helps you distinguish a high-confidence malicious host from stale or collateral data. A sensible workflow is to auto-block only high-confidence, durable indicators (such as known-bad file hashes), to review medium-confidence network indicators before enforcing them, and to treat single-source, low-severity entries as leads to investigate rather than facts to act on.

Provenance is part of that discipline. Because deduplication merges the sources of an indicator rather than discarding them, you can see how many independent feeds flagged a value — an indicator corroborated by several reputable sources is far more actionable than one that appears in a single low-quality list. Keeping that source information attached through export means the analyst on the receiving end can make the same judgement, rather than inheriting an opaque block list they cannot reason about.

Related Security Tools

Use the IOC extractor to pull indicators out of raw threat reports and logs before aggregating them, and the Nmap command builder when an investigation moves into authorised network verification.

What Is Threat Intelligence Aggregation

Threat intelligence aggregation collects, normalizes, and correlates threat data from multiple sources — open-source feeds, commercial providers, government advisories, industry sharing groups (ISACs), and internal security tools — into a unified view of the threat landscape. Individual threat feeds provide fragments of the picture; aggregation assembles them into actionable intelligence.

Security teams are overwhelmed by the volume of threat data available. Thousands of indicators of compromise (IOCs), vulnerability advisories, and threat reports are published daily. Without aggregation and correlation, analysts cannot distinguish signal from noise or prioritize the threats most relevant to their organization.

Threat Intelligence Sources

Source TypeExamplesData ProvidedCost
Open-source feedsAlienVault OTX, Abuse.ch, PhishTankIOCs, malware hashes, phishing URLsFree
Commercial feedsRecorded Future, Mandiant, CrowdStrikeCurated intelligence, attribution, TTPs$10K-$500K+/year
GovernmentCISA KEV, FBI Flash, NSA advisoriesVulnerability alerts, threat actor TTPsFree
ISACsFS-ISAC, H-ISAC, IT-ISACIndustry-specific threats and indicatorsMembership-based
InternalSIEM alerts, incident data, honeypotsOrganization-specific threat dataExisting infrastructure
Dark webMonitoring servicesLeaked credentials, planned attacks, exploit salesVaries

Common Use Cases

  • IOC enrichment: Aggregate multiple intelligence sources to enrich indicators with context — is this IP associated with known malware families? What threat actor uses this domain?
  • Threat prioritization: Correlate external threat intelligence with your internal asset inventory to prioritize threats that actually affect your technology stack
  • Detection engineering: Feed aggregated IOCs into SIEM, firewall, and EDR systems to create automated detection rules
  • Threat hunting: Use aggregated intelligence to develop hypotheses about threats that may be present in your environment but have not triggered alerts
  • Executive briefings: Synthesize intelligence from multiple sources into concise threat landscape reports for leadership

Best Practices

  1. Quality over quantity — More feeds do not automatically mean better intelligence. Curate sources based on relevance to your industry, technology stack, and threat profile.
  2. Normalize indicator formats — Different sources use different formats for IPs, domains, hashes, and URLs. Normalize to STIX/TAXII or a consistent internal format before correlation.
  3. Apply confidence scoring — Not all intelligence is equally reliable. Assign confidence scores based on source reliability, corroboration, and age. Don't block traffic based on a single low-confidence indicator.
  4. Automate ingestion — Manual copy-paste of IOCs does not scale. Use TAXII feeds, API integrations, and SOAR playbooks to automatically ingest, correlate, and distribute intelligence.
  5. Measure intelligence value — Track metrics like mean time to detect, false positive rates, and actionable intelligence percentage. If a feed produces no actionable alerts, evaluate whether it's worth maintaining.

Frequently Asked Questions

What types of indicators of compromise (IOCs) does this tool support?+

The tool supports five main IOC types: IP addresses, domain names, URLs, file hashes (including MD5, SHA-1, and SHA-256), and email addresses. Each IOC type is automatically detected when you add indicators manually or through bulk import.

How does the bulk import feature work?+

The bulk import feature allows you to paste any text containing threat intelligence, such as security reports or IOC lists. The tool automatically extracts IP addresses, domains, URLs, hashes, and emails from the text using pattern matching, then adds them to your database with medium severity and manual-bulk source tagging.

What export formats are available for IOC data?+

You can export IOCs in four formats: CSV for spreadsheet analysis, JSON for programmatic use, plain text for simple lists, and STIX 2.1 for industry-standard threat intelligence sharing. STIX exports include TLP (Traffic Light Protocol) markings for data classification.

What is the confidence score and how is it determined?+

The confidence score (0-100%) indicates how reliable an IOC is based on its sources. Manually added IOCs receive 75% confidence by default, while bulk imports get 60%. IOCs from multiple sources receive higher confidence scores, and the score is automatically adjusted based on corroboration across different feeds.

How do threat intelligence feeds work in this tool?+

Threat intelligence feeds are external sources that automatically provide updated IOC data. The Feed Management tab shows all configured feeds with their status, last update time, and IOC counts. You can add new feeds, trigger manual updates, and configure feed settings to customize data ingestion.

Can I organize IOCs into collections for different purposes?+

Yes, the Collections feature allows you to group IOCs by campaign, incident, or any custom criteria. Collections help organize your threat intelligence for specific investigations or use cases. Each collection tracks its IOC count and last update time, making it easy to manage multiple concurrent investigations.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.