Threat intelligence
that arrives as
detections.

Threats arrive with Splunk SPL, Microsoft KQL and Sigma rules, about nine per threat, mapped to MITRE ATT&CK. Read all of it free; a free account unlocks the query text.

Blue is free, no card. Teams can book a demo.

23,000+ detection rules · 63,000+ IOCs · 840+ ATT&CK techniques · refreshed nightly

Sigma 7,800+SPL 7,700+KQL 7,500+
Fig. 00 · Signal → rulesAbout nine rules per threat
Threat weatheras of 28 Sep, 08:51 UTC

Threat levelSevere, score 22 of 25

  • Threat volume6 of 6
  • Avg severity5 of 7
  • Avg CVSS6 of 7
  • Tag signal5 of 5
23 threats since 2026-09-27 00:00 ET
Each point on the left is a threat; each point on the right is a detection rule, in proportion to the corpus: about nine rules per threat across Sigma, SPL and KQL.

The corpus is the argument.

Counted from the corpus itself, in the snapshot we rebuild every night.

2,500+
threats in the corpus, readable without an account
23,000+
detection rules, about nine per threat Sigma 7,800+SPL 7,700+KQL 7,500+
63,000+
indicators of compromiseValues unlock on Red.
840+
ATT&CK techniques observed across Enterprise, ICS and ATLASMost seen: T1027 · 1,100+ threats
720+
actors and groups trackedMost tracked: TeamPCP · 44 threats
1,700+
CVEs enriched360+ on CISA’s Known Exploited Vulnerabilities list

Fig. 01 · One point per threat in the nightly snapshot. The six arms are the largest categories (vulnerability 770+, malware 660+, supply chain 250+, phishing 180+, ransomware 160+, APT 150+); the core holds every other category.

Detection languages

Sigma · SPL · KQL

23,000+ rules across 2,500+ threats

  • Sigma7,800+33.9%
  • Splunk SPL7,700+33.5%
  • Microsoft KQL7,500+32.5%

Rule names are public; a free account unlocks the query text.

Known exploited

CISA KEV catalog
21%

360+ of the 1,700+ CVEs we track are on CISA’s Known Exploited Vulnerabilities catalog.

150+ public PoC110+ ransomware-linked360+ critical

Severity mix

Whole corpus · refreshed nightly
  • Critical760+30.5%
  • High1,400+57.5%
  • Medium260+10.5%
  • Low120.5%
  • Other271.1%

Corpus counts from the nightly snapshot. CVE figures as of 28 Sep 2026.

From a new threat to a deployed detection.

A recent threat from the corpus, as of 28 Sep 2026, followed layer by layer from the first report to rules you can deploy.

Specimen · TL-2026-2726

01 · Reported

asec.ahnlab.com publishes. The report enters the corpus as TL-2026-2726, rated critical.

CriticalVulnerability · Activepublished 28 Sep 2026 · updated 02:02 UTC

CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers

asec.ahnlab.comcites twelve sources
  • nvd.nist.gov
  • cisa.gov
  • redcanary.com
  • bishopfox.com
  • github.com
  • threatprotect.qualys.com

02 · Enriched

Two CVEs, CVSS 9.8, CWE-502. On CISA’s KEV list since Nov 2021.

9.8CVSS 3.1
AV
N
AC
L
PR
N
UI
N
S
U
C
H
I
H
A
H

Fixed in 2020.1.114 (R1 2020) and laterOn CISA KEV since 3 Nov 2021

6.9 years from CVE reservation to this campaign

03 · Mapped

Sixteen ATT&CK techniques across nine of the fifteen Enterprise tactics.

16 techniques across 9 of 15 Enterprise tactics

  • T1595.002
  • T1190
  • T1059.003
  • T1505.003
  • T1134.001
  • T1620
  • T1082
  • T1033
  • T1057
  • T1071.001
  • +6

04 · Detected

Nine rules: 3 Splunk SPL, 3 Microsoft KQL, 3 Sigma.

9 rules · 3 behavioursSPLKQLSigmaTelerik RadAsyncUpload CVE-2019-18935 Deserialization Exploit + w3wp.exe Command ShellPrint Spooler Named-Pipe Impersonation and w3wp.exe Discovery Commands (SweetPotato/Godzilla Post-Exploitation)Outbound Connections to Telerik Exploit C2/Recon Infrastructure and Telegram Bot API Exfiltration
12 data sources
  • DeviceProcessEvents
  • W3CIISLog
  • windows_security
  • DeviceEvents
  • DeviceNetworkEvents
  • sysmon
  • network_connection
  • iis_w3c_logs
  • +4

Query text · withheldunlocks with a free account

05 · Ready to deploy

Every rule names its data sources, false positives and tuning notes. A free account unlocks the query text.

Splunk SPLTL-2026-2726-SPL-001Critical severity · high confidence

Splunk SPLTL-2026-2726-SPL-001Critical severity · high confidence

Telerik RadAsyncUpload CVE-2019-18935 Deserialization Exploit + w3wp.exe Command Shell

Detects HTTP requests to the Telerik UI RadAsyncUpload handler / Telerik.Web.UI.WebResource.axd endpoint carrying an encrypted rauPostData parameter (the CVE-2017-11317/CVE-2019-18935 exploit chain against RadAsyncUpload's AssemblyInstaller deserialization gadget), correlated with the IIS worker process w3wp.exe spawning cmd.exe shortly afterward — the observable signature of successful remote code execution in the AhnLab ASEC-documented attack cases.

Data sources

  • iis_w3c_logs
  • sysmon
  • windows_security

ATT&CK

  • T1190
  • T1059.003
  • T1620

False positives Custom ASP.NET diagnostic or health-check pages that legitimately invoke rauPostData-style upload handlers or shell out from w3wp.exe for approved administrative tooling

Tuning Baseline legitimate RadAsyncUpload usage on patched (2020.1.114+) hosts first; scope the w3wp.exe->cmd.exe join to a 5-minute correlation window and exclude known application-pool identities that run inventoried maintenance scripts.

Create a free accountUnlocks SPL, KQL and Sigma text for every threat. No card needed.

As of 28 Sep 2026Open the full record

Create a free account

The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server.

Never a bare score.

Two threats are related for reasons you can inspect. Six evidence channels, each with a published weight, blend into one score, decay with age and must clear 0.12. Re-blend it:

Correlation · readout

As of 28 Sep 2026

Pairs over the 0.12 threshold under each weight preset:

Production1 pair
Infra hunter1 pair
TTP analyst1 pair
Vuln driven10 pairs

Vuln driven weights, per evidence channel:

  • Technique member0.10
  • IOC member0.05
  • Context0.10
  • CVE0.35
  • Product0.25
  • CWE member0.15
Pairs over 0.1210 of 276
Strongest pairTL-2026-2711 and TL-2026-2703
0.365 · over

score = Σ weight × evidence × (0.5 + 0.5 × decay) · threshold 0.12

Preview: the engine's formula, approximated in your browser on the public fields of the 24 newest threats (CVE, product and context evidence). Technique, IOC and CWE evidence is scored server-side for members and reads as zero here.

Strongest pairs

Vuln driven · 10 over 0.12
  1. TL-2026-2711 and TL-2026-27030.365CVE-led CVE-2026-88771 +1 · NetScaler ADC +1 · same category
  2. TL-2026-2711 and TL-2026-26930.147Product-led NetScaler ADC +1 · same category
  3. TL-2026-2711 and TL-2026-26880.147Product-led NetScaler ADC +1 · same category
  4. TL-2026-2711 and TL-2026-26820.147Product-led NetScaler ADC +1 · same category
  5. TL-2026-2703 and TL-2026-26930.147Product-led NetScaler ADC +1 · same category
Fig. 03 · Evidence graph24 threats · 8 shared
  • Threat, by severity
  • CVE
  • Product
  • Context
  • Pair over 0.12
The 24 newest threats, joined by the public evidence they share. Links brighten with their channel's weight; white lines are pairs that clear the threshold. Hover or tap a threat for its strongest link.Scored on the snapshot of 28 Sep 2026.

The full engine, with technique, IOC and CWE evidence and the evidence chain behind every link, is on Red.

Subscribe to Red · $4.99/mo

One honest heatmap.

840+ ATT&CK techniques observed across Enterprise, ICS and ATLAS, each mapped from a real threat. Where a column is short, that is a gap, and we show it.

ATT&CK EnterpriseFifteen tactics, in kill-chain order

Tallest columnStealth (formerly Defense Evasion)TA0005148 techniques2,181 threats

ATT&CK Enterprise: techniques and threats observed per tactic
TacticIDTechniques observedThreats
ReconnaissanceTA004341992
Resource DevelopmentTA0042511,684
Initial AccessTA0001252,247
ExecutionTA0002532,155
PersistenceTA0003901,791
Privilege EscalationTA0004501,009
Stealth (formerly Defense Evasion)TA00051482,181
Defense ImpairmentTA0112411,086
Credential AccessTA0006621,876
DiscoveryTA0007541,911
Lateral MovementTA000822990
CollectionTA0009571,878
Command and ControlTA0011431,877
ExfiltrationTA0010221,389
ImpactTA0040481,463
fig. 04 · One square for each ATT&CK technique observed under a tactic, stacked from a shared baseline; brightness is the tactic's share of threats in the corpus. Refreshed nightly.

Most observed techniques

Threats using each technique, and their share of the corpus

  1. T1027Obfuscated Files or Information1,156 threats46%
  2. T1005Data from Local System1,153 threats46%
  3. T1082System Information Discovery1,129 threats45%
  4. T1059Command and Scripting Interpreter1,038 threats41%
  5. T1190Exploit Public-Facing Application924 threats37%

Unflinching about the gaps.

Shortest columns: Lateral Movement (22 techniques), Exfiltration (22) and Initial Access (25). Each is a place where our coverage is thinner, printed at its real height.

Prioritised by exploitation.

1,700+ CVEs enriched with CVSS, EPSS and CISA KEV status. 360+ are known exploited, and 510+ already have detection coverage in the corpus.

CVE counts

  • 1,700+CVEs enriched510+ cited by threats
  • 360+on CISA's KEV list21% of tracked CVEs
  • 150+with a public PoC9% of tracked CVEs
  • 110+ransomware-linked31% of the KEV entries

CVE arrivals, by month

2510022540034523

From Oct 2024 to Sep 2026, 1,499 tracked CVEs were published and 206 CVEs were added to CISA KEV. In Sep 2026 so far: 345 published, 23 added to KEV.

Square-root scale. Sep 2026 is the month to date.

Trending CVE

CVE-2026-63030 Critical

9.8CVSS base score

98.4thEPSS percentile

  • CISA KEV
  • Public PoC
  • Exploit
  • Nuclei template
Open CVE-2026-63030 →Published 7 days ago

EPSS distribution

  1. EPSS below 10%: 1,274 CVEs
  2. EPSS 10 to 20%: 25 CVEs
  3. EPSS 20 to 30%: 20 CVEs
  4. EPSS 30 to 40%: 15 CVEs
  5. EPSS 40 to 50%: 12 CVEs
  6. EPSS 50 to 60%: 15 CVEs
  7. EPSS 60 to 70%: 14 CVEs
  8. EPSS 70 to 80%: 17 CVEs
  9. EPSS 80 to 90%: 34 CVEs
  10. EPSS 90% and above: 112 CVEs

Modelled 30-day exploitation probability, on a square-root scale. 112 of 1,538 scored CVEs sit above 90%.

Top weaknesses by CVE count

  1. CWE-22Path Traversal106 CVEs
  2. CWE-79Cross-site Scripting89 CVEs
  3. CWE-89SQL Injection80 CVEs
  4. CWE-94Code Injection69 CVEs
  5. CWE-416Use After Free68 CVEs

Detection coverage

511of 1,734 tracked CVEs (29%) have detection rules in the corpus

  • Sigma803
  • Splunk SPL712
  • Microsoft KQL594

Rules on the threats that reference these CVEs, by language.

CVE figures as of 28 Sep 2026, 08:50 UTC, enriched from CVE.org, NVD, GitHub security advisories, FIRST EPSS and the CISA KEV catalog.

Built for agents.

Give any MCP client the corpus as tools. Your agent reads threats, pulls detections and exports rules the way an analyst would, and every result carries a threat ID you can open.

81 tools. 25 prompts. 14 resources.

One square per tool, grouped as the server groups them. Lit: called in this session.

npx -y intelthreadlinqs-mcp

Server 8.2 on npm and the official MCP registry (com.threadlinqs/intelthreadlinqs-mcp), or connect to the remote endpoint over Streamable HTTP with OAuth 2.1. Included with Purple.

Start 7-day trial

Purple · $11.99/mo

Agent sessionthreadlinqs-intelligence 8.2.0

Illustrative session. Every tool name is real and every result is composed from live corpus data.

  1. youWhat changed overnight that my SOC should act on?
  2. callget_threat_level()
  3. resultSevere: 22 of 25. 23 threats since 27 Sep, 00:00 ET.
  4. callget_recent_threats(limit: 3)
  5. resultTL-2026-2726CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS ServersTL-2026-2729Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT DeploymentsTL-2026-2723MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto Wallet Campaign
  6. callget_detections(threat_id: "TL-2026-2726", type: "kql")
  7. resultThree KQL rules. First: Telerik RadAsyncUpload CVE-2019-18935 Deserialization Exploit + w3wp.exe Command Shell.
  8. callexport_detection(detection_id: "TL-2026-2726-KQL-001", format: "kql")
  9. resultQuery text returned, ready to paste into Microsoft Sentinel. (Withheld on this page.)
  10. agentStart with TL-2026-2726. CVE-2019-18935 is on CISA’s KEV list and Telerik UI for ASP.NET AJAX is the target. Upgrade to 2020.1.114 (R1 2020) or later, then deploy TL-2026-2726-KQL-001 to Sentinel; it covers T1190, T1059.003 and T1620.
As of 28 Sep 2026, 08:51 UTCOpen TL-2026-2726

All 81 tools in the catalog

In the server’s nineteen groups. Lit: the four this session called.

  • Landscape get_threat_level get_landscape_briefing get_daily_theme get_platform_stats
  • Detections get_detections export_detection search_detections get_detection_detail
  • Threats get_recent_threats search_threats get_threat get_threat_enrichment get_similar_threats get_threat_bundle get_threat_hunting_bundle bulk_get_threats list_threat_categories get_threat_transcripts
  • Hunt hunt hunt_schema search_corpus_semantic
  • Pivots get_malware_intelligence get_tool_intelligence get_campaign_intelligence list_campaigns resolve_entity get_entity_aliases get_entity_profile
  • Simulations get_threat_simulations list_simulations
  • Attack flows get_attack_flow get_flow_similar_threats get_flow_coverage get_d3fend_posture get_atlas_intelligence
  • IOCs search_iocs get_ioc_intelligence get_ioc_dns
  • OSINT get_osint search_xscan_indicators get_osint_trends get_community_campaigns
  • Graph get_ioc_blast_radius get_infrastructure_pivots explain_correlation get_correlation_path get_pivotal_entities get_graph_campaigns get_correlation_subgraph
  • Attribution get_attribution_evidence get_attribution_coverage
  • C2 get_c2 generate_c2_blocklist get_c2_dns_intel
  • Correlations get_correlations get_enrichment_overview get_technique_rules get_engine_status
  • ATT&CK get_mitre_coverage get_mitre_technique predict_mitre_transitions get_mitre_gap_analysis
  • Vulnerabilities get_cve get_cwe search_vulnerabilities get_cve_intelligence bulk_get_cves
  • Actors get_actor search_actors get_actor_intelligence get_actor_relationships
  • Debriefs list_debriefs get_debrief get_latest_debrief get_daily_intel_bundle
  • Exports export_stix export_attack_navigator
  • Platform get_started health get_roadmap get_changelog

Intelligence without detection is research. Detection without intelligence is noise. We build both.

Six surfaces, one corpus.

Every surface reads the same enriched corpus, so a CVE you open in one is already attributed, mapped and detected in the next.

Detect

Detections you deploy, not translate.

Rule languagesWhole corpus · nightly
  • Sigma 33.9%
  • Splunk SPL 33.5%
  • Microsoft KQL 32.5%

Top technique across the corpus1,100+ threats

T1027 Obfuscated Files or Information

Detection engineering

Operate

Delivered where your team already works.

DeliveryFree to Gold
  • 230+daily debriefs, every morningFree
  • 81MCP tools for any agentPurple
  • Alerts to Slack, Teams, email and signed webhooksGold

MCP integration

Still comparing vendors? Read the platform comparisons, browse the resource library, see every solution, or go straight to plans and pricing.

Chatbots answer. Analysts act.

SecOS is a desktop for security work in your browser: seven skins, a window manager, every Threadlinqs instrument one launcher away, and OS.ai, an agent that opens the right app instead of answering inline. Purple and Gold members can open it today; everyone else can join the waitlist.

SecOS · desktopIllustration, not a screenshot
Watch the preview
Loads from youtube-nocookie.com on play

Join the SecOS waitlist.

Seven skins ship today: Signal, Cupertino for macOS and iOS, Fluent, Phosphor, Material and Chicago. Access opens in waves; join with the email on your Threadlinqs account and we’ll write when your slot is ready. No account yet? Create a free one first.

Already have access? Open SecOS

Deploy nothing. Ship us no data.

A private team workspace scoped to what you defend. Set it once. Every dashboard, alert, feed and graph re-scopes to it, live.

We only store references to public catalog entities, never your assets, logs or regulated data.

Intelligence profileExample · Gold
Sectors
FinanceHealthcare
Threat actors
APT29FIN7Scattered Spider
Vendors
MicrosoftFortinetVMware
Alerts
Critical and high, to Slack and Teams
Feeds
STIX 2.1, MISP and TAXII 2.1, filtered to the profile
Set once. Every surface re-scopes to it.

Eleven apps. One question each.

  1. crosshairsLive threats, actors and KEV CVEs targeting your exact tech stack.
  2. red_mirrorWho targets organisations like yours, and the detections to catch them.
  3. nightwatchWhat changed for your sector and stack since yesterday, with SIEM/SOAR pull.
  4. blind_spotsYour riskiest detection gaps, weighted by real-world exploitation.
  5. triagePaste indicators and learn who is behind them. Nothing is stored.
  6. war_roomWar-game a real adversary with a facilitator-ready exercise.
  7. proving_groundEmulate a real threat with each step paired to a validating detection.
  8. breach_wireSEC-disclosed peer breaches cross-referenced to our corpus, plus board briefs.
  9. doppelgangerEarly warning on brand impersonation and phishing domains.
  10. tracerFollow a Cobalt Strike operator and auto-block its rotating infrastructure.
  11. trust_cardA scan-free, shareable exposure narrative for questionnaires and boards.

One subscription. One profile. Every answer scoped to you.

Already onboarded? · Or write to contact@threadlinqs.com

Gold TAXII 2.1 server
Your platform polls the corpus over the standard TAXII 2.1 API.
Purple and above STIX 2.1 export and MISP feed
STIX 2.1 bundles per threat, and a MISP feed your instance subscribes to.
Gold Alert connectors
Slack, Microsoft Teams, email and signed webhooks.
Gold Organisation AI, bring your own key
Use the platform’s research model, grounded on the corpus, or bring your own NVIDIA, OpenAI or Anthropic key, stored encrypted and injected server-side.

Standards-native in, standards-native out.

No agents to install, no schema to invent. Every format is labelled with the plan that opens it.

  • Splunk SPLBlue
  • Microsoft KQLBlue
  • SigmaBlue
  • STIX 2.1Purple
  • MISP feedPurple
  • TAXII 2.1Gold
  • Signed webhooksGold
  • RSSFree
  • MCPPurple

What landed in the last 30 days.

334 new threats reached the corpus in the 30 days to 28 Sep 2026, and the daily debriefs carried 4,050 detection rules for new and updated threats. Every morning one debrief sums up the day: 230+ so far.

30 Aug to 28 Sep 2026334 new threats4,050 detection rules

New threats a dayPeak 22

Detection rules in each debriefPeak 342

New threats and detection rules in each daily debrief, 30 Aug to 28 Sep 2026
DayNew threatsDetection rules
30 Aug 202610144
31 Aug 202614153
1 Sep 202612180
2 Sep 202612162
3 Sep 202615153
4 Sep 2026899
5 Sep 2026563
6 Sep 202610153
7 Sep 20269117
8 Sep 202610144
9 Sep 20269135
10 Sep 2026999
11 Sep 20267108
12 Sep 202612126
13 Sep 202614153
14 Sep 20268126
15 Sep 202612126
16 Sep 202611117
17 Sep 2026772
18 Sep 202616171
19 Sep 2026899
20 Sep 2026663
21 Sep 202616144
22 Sep 202612108
23 Sep 202613117
24 Sep 2026872
25 Sep 202618162
26 Sep 202620342
27 Sep 202622333
28 Sep 2026, so far19
Fig. 10 · One bar per daily debrief, oldest to newest. The lit bar is the last full day, the one in the card. Point at or tap any day to read it.

Last full day

27 Sep 2026

22new threats

15updated

Detection rules
333
ATT&CK techniques
229
Indicators, counted
790

Severity, 37 threats14 critical17 high6 medium

Get the daily debrief, free

A free Blue account, with the debrief email switched on.

Plans built for security teams.

The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server.

Blue

Analyst

Free

forever · no card

REST API50 a day
DNS enrichmentNot included
  • The whole corpus, readable
  • Detection query text: Splunk SPL, Microsoft KQL, Sigma
  • Daily debriefs, view and email
  • ATT&CK map and statistics

Red

Professional

$4.99

per month

cve.lens add-on: $3.99/mo

REST API500 a day
DNS enrichment100 a day
  • Everything in Blue, plus
  • Indicator (IOC) values
  • Actor attribution explorer and API
  • Correlation engine, intel graph and blast radius
  • Research Lab

Purple

SME7-day free trial

$11.99

per month

cve.lens included

REST API5,000 a day
DNS enrichment1,000 a day
  • Everything in Red, plus
  • MCP server: 81 tools
  • Attack simulations
  • Wild C2 intelligence
  • STIX 2.1 export and MISP feed
  • Advanced correlations
  • SecOS

Gold

Team workspace

By inquiry

14-day trial, no card

REST API25,000 a day
DNS enrichmentUnlimited
  • Everything in Purple, plus
  • Team workspace and intelligence profile
  • Gold Suite: 11 apps
  • TAXII 2.1 server
  • Alert connectors: Slack, Teams, email, signed webhooks
  • Organisation AI / bring your own key

Prices in US dollars. Paid plans are month-to-month. The quota meters use a log scale: each segment is about ten times the one before.

Compare every feature
Every feature and daily quota, by plan
FeatureBlueFreeRed$4.99Purple$11.99GoldBy inquiry
In every plan
The whole corpus, readableIncludedIncludedIncludedIncluded
Detection query text: Splunk SPL, Microsoft KQL, SigmaIncludedIncludedIncludedIncluded
Daily debriefs, view and emailIncludedIncludedIncludedIncluded
ATT&CK map and statisticsIncludedIncludedIncludedIncluded
Added in Red
Indicator (IOC) valuesNot includedIncludedIncludedIncluded
Actor attribution explorer and APINot includedIncludedIncludedIncluded
Correlation engine, intel graph and blast radiusNot includedIncludedIncludedIncluded
Research LabNot includedIncludedIncludedIncluded
Added in Purple
MCP server: 81 toolsNot includedNot includedIncludedIncluded
Attack simulationsNot includedNot includedIncludedIncluded
Wild C2 intelligenceNot includedNot includedIncludedIncluded
STIX 2.1 export and MISP feedNot includedNot includedIncludedIncluded
Advanced correlationsNot includedNot includedIncludedIncluded
SecOSNot includedNot includedIncludedIncluded
cve.lensNot includedAdd-on, $3.99/moIncludedIncluded
Added in Gold
Team workspace and intelligence profileNot includedNot includedNot includedIncluded
Gold Suite: 11 appsNot includedNot includedNot includedIncluded
TAXII 2.1 serverNot includedNot includedNot includedIncluded
Alert connectors: Slack, Teams, email, signed webhooksNot includedNot includedNot includedIncluded
Organisation AI / bring your own keyNot includedNot includedNot includedIncluded
Daily quotas
REST API calls505005,00025,000
DNS enrichmentsNot included1001,000Unlimited

Questions, answered plainly.

Ten answers about plans, data and access, each in a paragraph.

Still stuck? contact@threadlinqs.com

What is Threadlinqs?

A threat-intelligence platform where threats arrive with deployable detections: curated threats with Splunk SPL, Microsoft KQL and Sigma rules, MITRE ATT&CK mapping, indicators of compromise, CVE and CWE enrichment, adversary attribution and attack simulations, plus an MCP server for AI agents.

Is there a free tier?

Yes. Blue is free, with no card. The whole corpus is readable without an account; a free Blue account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma, the daily debrief email and a REST API key with 50 calls a day.

What do the plans include?

The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server.

Red ($4.99/mo) adds indicator values, attribution and the correlation engine. Purple ($11.99/mo, 7-day trial) adds the MCP server, attack simulations, STIX and MISP export and SecOS. Gold is a private team workspace, priced by inquiry. Compare the plans.

What detection formats do you ship?

Splunk SPL, Microsoft KQL (Sentinel and Defender XDR) and Sigma: about nine rules per threat across the three, each with data sources, false positives, tuning notes and ATT&CK mapping. A free account unlocks the query text.

Do you have an API and an MCP server?

Yes. Every account gets a REST API key: 50 calls a day on Blue, 500 on Red, 5,000 on Purple and 25,000 on Gold. The MCP server (81 tools, 25 prompts, 14 resources) is included with Purple: run npx -y intelthreadlinqs-mcp or connect to the remote endpoint over OAuth 2.1. See the MCP and API docs.

Which feeds and standards do you support?

STIX 2.1 export and a MISP feed on Purple; a TAXII 2.1 server, signed webhooks and alert connectors on Gold; an RSS feed for everyone; and detections in SPL, KQL and Sigma.

Where does the intelligence come from?

Primary reporting and public sources, enriched with CVE and CWE data, ATT&CK mapping and adversary attribution. We publish quickly, then verify deliberately, and when the evidence is thin we say Unattributed rather than guess. Our editorial standards explain the process and how AI is used.

How current is the data?

New threats are added through the day. The counts on this page come from a snapshot we rebuild every night, so they can trail the live feed by a day. A daily debrief sums up each day.

How do I get team access?

Gold is a private team workspace. Book a demo or start a 14-day trial with no card, or email contact@threadlinqs.com, and we will scope a workspace to your organisation. Already onboarded? Use .

Can I cancel anytime?

Yes. Paid plans are month-to-month with no contracts — cancel anytime from your profile settings.

See what’s already
pointed at you.

The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server.