Last reviewed:
Reference material, role-based guides, and platform comparisons to help you understand modern threat intelligence and detection engineering — and how Threadlinqs fits your workflow.
Threadlinqs is a threat intelligence platform built for security operations, detection engineering, and threat hunting teams, and this resources section is where the platform's underlying concepts, workflows, and market context live outside the product itself. The glossary below explains the vocabulary security teams need before evaluating any detection or intelligence tool: what indicators of compromise and TTPs are, how detection engineering differs from writing one-off alerts, and how the MITRE ATT&CK framework maps adversary behavior to coverage. The solutions guides describe how three different roles — SOC analysts, detection engineers, and threat hunters — actually use a unified threat feed day to day. The comparison pages set Threadlinqs against the vendors security teams already evaluate. And the free, no-account surfaces near the bottom of this page let you check platform-wide statistics, ATT&CK coverage, and the live CVE feed before you ever create an account.
New to the terminology? Start with the glossary. Comparing vendors before you commit to one? Jump to the platform comparisons. Want to see detection coverage without signing up? Go straight to the MITRE ATT&CK coverage map or the live CVE feed — both are free, no account required.
Plain-English definitions of the concepts behind modern threat intelligence and detection engineering — indicators of compromise, the intelligence cycle, MITRE ATT&CK, and the query languages SOC teams use to hunt. Each entry explains what the term means, why it matters operationally, and where the concept shows up inside a live intelligence platform.
Definition, types, the intelligence cycle, and IOCs vs TTPs.
Turning intelligence into testable, version-controlled detection logic.
Tactics, techniques, and procedures — and how to map coverage.
The vendor-agnostic detection format and how it converts to SIEMs.
Splunk's Search Processing Language for detecting threats in log data.
All definitions in one place.
Threadlinqs itself, broken down by capability: real-time threat intelligence and CVE enrichment, detection engineering across SPL, KQL, and Sigma, the MITRE ATT&CK coverage map, actor attribution, attack simulations for validating detections safely, and the MCP server that connects AI coding agents directly to the feed.
Real-time tracked threats, enriched CVEs, IOC feeds, and automated daily debriefs.
Production-ready detection rules in SPL, KQL, and Sigma, mapped to MITRE ATT&CK.
Drill from tactic to technique to threat to detection in one split-panel view.
Nation-state and criminal actor dossiers with technique profiling and cross-actor correlation.
Atomic-style simulations for tracked threats — Windows, Linux, and Python — with detection validation.
Connect Claude Code, Cursor, and other MCP clients directly to the threat feed.
How security teams use Threadlinqs depending on what they do day to day — SOC analysts triaging alerts, detection engineers closing MITRE ATT&CK coverage gaps, and threat hunters pivoting across indicators and actor infrastructure to catch campaigns before they're reported publicly.
Triage faster with severity-classified threats, enriched CVEs, and ready-to-deploy detections.
Export SPL, KQL, and Sigma mapped to MITRE ATT&CK and close coverage gaps.
Pivot across IOCs, actor infrastructure, and correlations to find emerging campaigns.
Threadlinqs combines threat intelligence with deployable detection logic in one workflow — most competitors do one or the other. These pages compare feed breadth, detection output, and pricing against the vendors security teams already evaluate before choosing an intelligence platform.
In-depth analysis of active campaigns, vulnerabilities, and adversary tradecraft, published with the detection logic to act on it. The TLQL reference documents the query language used to filter and search the live threat feed inside the platform.
Parts of the platform that don't require an account: aggregate corpus statistics, the MITRE ATT&CK coverage map, the live CVE feed, and the MCP server documentation for connecting AI agents to real threat data.
Live corpus-wide counts: threats, detections, IOCs, and actor coverage.
Browse ATT&CK tactics and techniques with live detection coverage, no account required.
Enriched vulnerabilities with CVSS, EPSS, and CISA KEV status, browsable without signing up.
Tool catalog and setup guide for connecting AI agents to the platform via MCP.
Real-time threat feed, detection library, and MITRE coverage map — free on the Blue tier.
[ open_platform ]