// resources

Threadlinqs Resources

Last reviewed:

Reference material, role-based guides, and platform comparisons to help you understand modern threat intelligence and detection engineering — and how Threadlinqs fits your workflow.

Threadlinqs is a threat intelligence platform built for security operations, detection engineering, and threat hunting teams, and this resources section is where the platform's underlying concepts, workflows, and market context live outside the product itself. The glossary below explains the vocabulary security teams need before evaluating any detection or intelligence tool: what indicators of compromise and TTPs are, how detection engineering differs from writing one-off alerts, and how the MITRE ATT&CK framework maps adversary behavior to coverage. The solutions guides describe how three different roles — SOC analysts, detection engineers, and threat hunters — actually use a unified threat feed day to day. The comparison pages set Threadlinqs against the vendors security teams already evaluate. And the free, no-account surfaces near the bottom of this page let you check platform-wide statistics, ATT&CK coverage, and the live CVE feed before you ever create an account.

New to the terminology? Start with the glossary. Comparing vendors before you commit to one? Jump to the platform comparisons. Want to see detection coverage without signing up? Go straight to the MITRE ATT&CK coverage map or the live CVE feed — both are free, no account required.

Glossary

Plain-English definitions of the concepts behind modern threat intelligence and detection engineering — indicators of compromise, the intelligence cycle, MITRE ATT&CK, and the query languages SOC teams use to hunt. Each entry explains what the term means, why it matters operationally, and where the concept shows up inside a live intelligence platform.

The Threadlinqs Platform

Threadlinqs itself, broken down by capability: real-time threat intelligence and CVE enrichment, detection engineering across SPL, KQL, and Sigma, the MITRE ATT&CK coverage map, actor attribution, attack simulations for validating detections safely, and the MCP server that connects AI coding agents directly to the feed.

Solutions by Role

How security teams use Threadlinqs depending on what they do day to day — SOC analysts triaging alerts, detection engineers closing MITRE ATT&CK coverage gaps, and threat hunters pivoting across indicators and actor infrastructure to catch campaigns before they're reported publicly.

Platform Comparisons

Threadlinqs combines threat intelligence with deployable detection logic in one workflow — most competitors do one or the other. These pages compare feed breadth, detection output, and pricing against the vendors security teams already evaluate before choosing an intelligence platform.

Threat Research Blog

In-depth analysis of active campaigns, vulnerabilities, and adversary tradecraft, published with the detection logic to act on it. The TLQL reference documents the query language used to filter and search the live threat feed inside the platform.

Free, Live Machine Data

Parts of the platform that don't require an account: aggregate corpus statistics, the MITRE ATT&CK coverage map, the live CVE feed, and the MCP server documentation for connecting AI agents to real threat data.

Explore the Platform

Real-time threat feed, detection library, and MITRE coverage map — free on the Blue tier.

[ open_platform ]