# Unified Threat Intelligence

Copy as Markdown[Open in ChatGPT](https://chatgpt.com/?q=Read%20https%3A%2F%2Fcoralogix.com%2Fdocs%2Fuser-guides%2Fenrichment_rules%2Funified_threat_intelligence.md%20and%20help%20me%20with%20my%20question%20about%20this%20Coralogix%20documentation%20page.)[Open in Claude](https://claude.ai/new?q=Read%20https%3A%2F%2Fcoralogix.com%2Fdocs%2Fuser-guides%2Fenrichment_rules%2Funified_threat_intelligence.md%20and%20help%20me%20with%20my%20question%20about%20this%20Coralogix%20documentation%20page.)

Malware detection is an essential capability for modern businesses that helps them identify threats and malicious activity posing a risk to their environments, investigate them, and respond quickly.

Threat intelligence feeds are trusted sources of information about potential cyber threats, such as malicious activity. With that said, incorporating threat feeds into your data to detect suspicious activity can require complex configuration, often leading to the sub-utilization of this important source of information.

The Coralogix **Unified Threat Intelligence** relies on our [Streama© technology](https://coralogix.com/how-it-works/) to provide you with built-in seamless integration with some of the world’s leading threat intelligence feeds with hundreds of thousands threat entities curated by our security experts.

Coralogix does not require any API integration, special syntax, or format change. It automatically enriches your data with malicious indicators in real-time as they are streamed, allowing you to query, visualize, and alert on potential threats.

Enriched information is then stored to your own remote storage. This allows you to query directly from Coralogix with infinite retention and even research the data with external tools.

## What you need[​](#what-you-need "Direct link to What you need")

* `SECURITY-ENRICHMENT:READCONFIG`: view Unified Threat Intelligence Enrichment configuration (Data Admin, Observability Lead, Platform Admin, Security User).
* `SECURITY-ENRICHMENT:UPDATECONFIG`: create or manage Unified Threat Intelligence Enrichment (Data Admin, Platform Admin, Security User).

## How can the Unified Threat Intelligence help to improve my security?[​](#how-can-the-unified-threat-intelligence-help-to-improve-my-security "Direct link to How can the Unified Threat Intelligence help to improve my security?")

Take a look at these use-cases to get a feel for the many ways that our **Unified Threat Intelligence** can serve you.

Use-Case 1: Detection of Phishing Attempts

Phishing is a social engineering attack practice, causing people to share credentials, sensitive information or install malware by impersonating a legitimate website. The **Unified Threat Intelligence** helps you detect any network activity from your organization’s environment to a reported phishing website, allowing you to identify which users were involved and investigate the impact.

Use-Case 2: Detection of Browsing of Malicious Websites

Phishing is the number one attack vector to infiltrate your organization by obtaining user credentials. The **Unified Threat Intelligence** helps you detect any user visiting a phishing site (through domain/URL) or a phishing site that is hosted on your infrastructure.

Use-Case 3: Detection of Potential Data Exfiltration

Malware installed on an internal machine in your environment may gain access to your sensitive data and exfiltrate it by uploading this data to an attacker’s website. The **Unified Threat Intelligence** helps you to immediately detect network activities to such websites reported as malicious, block them, and assess the data leakage that may have occurred.

Use-Case 4: Bot Detection by Command and Control Communication Monitoring

Hackers use bots to perform large scale attacks. These include denial of service (DDoS) attacks that can flood a website with connection requests, causing it to stop serving legitimate customers, distribute spam emails, make fraudulent purchases, and more. C\&C communication is used by hackers to send the operation commands to the bots. The **Unified Threat Intelligence** allows you to detect this command and control communication by inspecting your network activity logs and discovering communication to/from command and control servers. Using this feature, you can easily see which machines perform this network activity and are infected with bots.

Use-Case 5: Detection of Brute-Force Scanning

Hackers use brute-force scanning to scan your network environment and find exposed resources which allow them to penetrate your environment and attack it. The **Unified Threat Intelligence** allows you to detect incoming network traffic coming from IPs and servers reported as malicious. With this improved security posture, you can block those requests, assess any risk and its impact, and immediately decide upon mitigation steps.

## How it works[​](#how-it-works "Direct link to How it works")

Coralogix operates a dedicated Threat Intel Platform that collects indicators of compromise (IOCs) from multiple source classes, then validates, scores, and maintains them before they are used for enrichment.

The flow has three stages:

1

<!-- -->

.

**Collection.** Open-source feeds, security research publications, internal incident investigations, and structured threat reports are polled continuously for new indicators.

2

<!-- -->

.

**Processing.** The Threat Intel Platform removes duplicate IOCs, applies AI-based context enrichment, assigns each indicator a confidence score from 0 to 100, and applies a time-based decay rule so stale intelligence loses weight over time.

3

<!-- -->

.

**Enrichment and detection.** Scored indicators are pushed to the Coralogix platform, where incoming logs are normalized, matched against the indicator set, and enriched in real time. Enriched logs feed the out-of-the-box alerts and dashboards described below.

## Threat intelligence sources[​](#threat-intelligence-sources "Direct link to Threat intelligence sources")

Indicators are collected from four complementary source classes. All sources are aggregated, de-duplicated, and validated before they reach your account.

| Source class                   | Description                                                                                                                                     |
| ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------- |
| Open-source feeds              | Continuously polled public IOC feeds covering IP addresses, domains, URLs, and file hashes.                                                     |
| Security research publications | More than 70 vendor and independent research blogs, monitored for fresh IOCs from emerging campaigns.                                           |
| Internal incident collection   | Indicators surfaced by Snowbit MDR investigations and live incident response.                                                                   |
| Threat reports and CISA KEV    | Structured threat reports and the [CISA Known Exploited Vulnerabilities catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog). |

### Monitored open-source feeds[​](#monitored-open-source-feeds "Direct link to Monitored open-source feeds")

| Feed                                                                     | Focus                                                                                                       |
| ------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------- |
| [ThreatFox](https://threatfox.abuse.ch/)                                 | Community-shared malware and botnet C2 indicators: IPs, domains, URLs, and hashes with malware family tags. |
| [URLhaus](https://urlhaus.abuse.ch/)                                     | Malicious URLs used for malware distribution and payload delivery.                                          |
| [LevelBlue Open Threat Exchange (OTX)](https://otx.alienvault.com/)      | Community threat-sharing platform, formerly AlienVault OTX, covering all indicator types.                   |
| [Feodo Tracker](https://feodotracker.abuse.ch/)                          | Botnet C2 IP addresses associated with banking trojans and loaders.                                         |
| [Criminal IP C2-Daily-Feed](https://github.com/criminalip/C2-Daily-Feed) | Daily malicious and C2 IP addresses from the Criminal IP threat-hunting engine.                             |
| [drb-ra C2IntelFeeds](https://github.com/drb-ra/C2IntelFeeds)            | Automated C2 IP, domain, and URL feeds covering Cobalt Strike, Sliver, Mythic, and other frameworks.        |
| [VX Vault](http://vxvault.net/ViriList.php)                              | Malware distribution URLs with payload hashes.                                                              |
| [Red Flag Domains](https://red.flag.domains/)                            | Daily lists of probably malicious newly registered domains.                                                 |
| [Emerging Threats](https://rules.emergingthreats.net/)                   | Proofpoint ET Open IDS rulesets and block IP lists across broad threat categories.                          |
| [TweetFeed](https://tweetfeed.live/)                                     | IOCs published by the infosec community on X (Twitter): URLs, domains, IPs, and hashes.                     |
| [OpenPhish](https://openphish.com/)                                      | Automated phishing URL detection with targeted-brand metadata.                                              |
| [Tor Bulk Exit List](https://check.torproject.org/torbulkexitlist)       | The Tor Project's official list of current Tor exit node IP addresses.                                      |
| [Binary Defense banlist](https://www.binarydefense.com/banlist.txt)      | Attacker and scanner IPs from the Binary Defense Artillery honeypot network.                                |
| Coralogix in-built C2 tracker                                            | Automated C2 IP tracking that covers a variety of trending C2 frameworks used by adversaries.               |

## Supported indicator types[​](#supported-indicator-types "Direct link to Supported indicator types")

Six indicator types are scored, contextualized, and matched against your telemetry in real time.

| Indicator type  | Description                                                                                          |
| --------------- | ---------------------------------------------------------------------------------------------------- |
| IP address      | Malicious source and destination addresses, including botnet nodes and Tor exit nodes.               |
| Domain          | Known-bad and newly registered domains used for phishing, malware delivery, and command and control. |
| URL             | Phishing, command and control, and malware-hosting links.                                            |
| File hash       | Malware sample hashes (MD5 and SHA families).                                                        |
| JA3 fingerprint | TLS client fingerprints used to identify command and control tooling.                                |
| JA4 fingerprint | Next-generation TLS fingerprints with improved resistance to evasion.                                |

## How confidence scores are assigned[​](#how-confidence-scores-are-assigned "Direct link to How confidence scores are assigned")

The initial confidence score reflects the threat category the indicator belongs to. Confirmed command and control infrastructure receives the highest scores, while uncorroborated or aging intelligence starts low and must earn a higher score through additional reporting. The scores in the table below are normalized to a 0 to 10 band.

| Score | Category                      | Examples                                                          | Rationale                                                                         |
| ----- | ----------------------------- | ----------------------------------------------------------------- | --------------------------------------------------------------------------------- |
| 10    | APT / C2                      | UNC6771, APT36, Cobalt Strike, Havoc, Brute Ratel, Sliver, Mythic | Active command and control frameworks on confirmed malicious infrastructure.      |
| 9     | Offensive security tools      | Metasploit, Meterpreter, PoshC2, Empire, Covenant                 | Known attack frameworks found on open ports; a strong indicator of compromise.    |
| 9     | Remote access trojans         | AsyncRAT, Remcos, QuasarRAT, NjRAT, DarkComet                     | Remote access trojans with confirmed C2 panels.                                   |
| 8     | Malware hosting               | Domains serving FakeApp, ClearFake                                | Confirmed malicious domains distributing malware.                                 |
| 8     | Phishing kits / campaigns     | Gophish, Evilginx, Modlishka                                      | Detected phishing infrastructure.                                                 |
| 8     | Information stealers          | RedLine, Raccoon, Vidar, LummaC2, StealC                          | Stealer families with active C2.                                                  |
| 7     | Exploit kits and fake updates | ClearFake, SocGholish, fake browser update campaigns              | Drive-by download infrastructure.                                                 |
| 7     | Cryptominers                  | XMRig and other Monero miners on servers                          | Unauthorized mining activity that indicates compromise.                           |
| 6     | Botnet C2                     | Mirai, Mozi, and Gafgyt command servers                           | Botnet command servers, as opposed to the devices they control.                   |
| 5     | Botnet-infected devices       | Mirai-infected devices, IoT bots                                  | Infected endpoints; often victims rather than attackers.                          |
| 5     | Scanner activity              | Port scanners, SSH brute force, web scanners                      | May be attackers or legitimate security researchers.                              |
| 4     | Suspicious                    | Single-source report with no corroboration                        | Requires more evidence; the score rises as additional feeds report the indicator. |
| 3     | Unverified                    | Aged IOCs, expired domains, inactive IPs                          | May no longer be relevant; subject to decay and revocation.                       |

Scores are not static. An indicator reported by multiple independent feeds gains confidence, while an indicator that stops appearing in fresh intelligence decays toward the revoke threshold and is eventually retired.

## Risk scoring and indicator lifecycle[​](#risk-scoring-and-indicator-lifecycle "Direct link to Risk scoring and indicator lifecycle")

Every indicator carries a risk score that reflects current confidence in its maliciousness.

* **Initial score.** When an indicator is created, it receives a score on a 0 to 100 scale, assigned from the incoming feed or set by the Snowbit Threat Intel team.
* **Time-based decay.** A decay rule steadily lowers the score as the intelligence ages. New corroborating evidence raises the score again.
* **Revocation.** When an indicator's score falls below the revoke threshold, it is retired from the active set. This keeps the indicator set current and cuts alert noise from stale intelligence.
* **Normalization on ingestion.** When indicators are pushed into Coralogix, the score is normalized to a 0 to 10 band, which simplifies alert thresholds.

For example, an IP address reported by a C2 tracker might enter the platform with a score of 8. If no further sightings occur, decay reduces the score toward the revoke threshold over the following weeks. If a new report confirms the address is still active, the score rises again and the indicator remains in the active set.

[![Indicator risk score rising on new sightings and decaying toward the revoke threshold over time](/docs/assets/images/indicator-lifecycle-84b64fbf546e9f21ebd2bfdc26ce463b.webp)](https://coralogix.com/docs/assets/images/indicator-lifecycle-84b64fbf546e9f21ebd2bfdc26ce463b.webp)

## Enriched fields[​](#enriched-fields "Direct link to Enriched fields")

If an IP, URL, or domain value in your log is reported as malicious, a new field named `<key_name>_suspected` is added to the relevant log, with `key_name` serving as the original log key. The field records the matched value, the number of feeds that reported it, and per-feed detail.

The `<key_name>_suspected` field contains the following fields:

| Field            | Description                                                                                                           |
| ---------------- | --------------------------------------------------------------------------------------------------------------------- |
| malicious\_value | Actual value reported to be malicious                                                                                 |
| reporting\_feeds | List of feeds that reported this value as malicious                                                                   |
| total\_feeds     | Includes the number of the feeds in **reporting\_feeds** and can be used in queries and alerts as a confidence level. |

Feeds that supply adversary context add the following detail to their entry under `reporting_feeds`:

```
{

  "adversary": {

    "confidence_level": 8,

    "date_identified": "2026-07-26",

    "feed_name": "Coralogix",

    "industry": "Multi-sector",

    "ioc_source": "blog",

    "malware_family": "AdaptixC2",

    "notes": "Traffic seen on port 4321",

    "reference": "",

    "tags": [

      "confidence:high",

      "status:unclassified",

      "type:ipv4"

    ],

    "targeted_countries": [

      "Global"

    ],

    "type": "IPv4"

  }

}
```

This enrichment is executed automatically while your logs are being streamed into Coralogix. All you need to do is to define which log keys contain IPs, URLs, or domains that should be looked up in the threat intelligence feeds and enriched upon a match.

To get the best value, it is **recommended** to create alerts based on these enriched logs, to be notified as soon as possible upon detection of potential malicious network traffic and respond immediately.

## Get started[​](#get-started "Direct link to Get started")

1

<!-- -->

.

Navigate to **Data Flow**, then **Data Enrichment**.

2

<!-- -->

.

Select **Enrich threat intelligence** to open the editor.

3

<!-- -->

.

Select the JSON keys containing IPs, URLs, or domains to look up and enrich with malicious activity indicators.

4

<!-- -->

.

Select **Add Key**.

Note

If your logs don’t have a dedicated field for IP, URL, or domain, or your data isn’t JSON-formatted, you can use our [parsing rules](https://coralogix.com/docs/user-guides/data-transformation/parsing/log-parsing-rules.md) to extract these precise values from your log record into a dedicated key, to be looked up in the threat intelligence fields and enriched if they match.

From that point on, every incoming log with a value in a selected key is checked against the indicator set and enriched automatically.

## Query enriched logs[​](#query-enriched-logs "Direct link to Query enriched logs")

Use [DataPrime](https://coralogix.com/docs/dataprime/introduction/welcome-to-the-dataprime-reference.md) to explore enriched logs.

Find all logs where an IP was flagged as malicious:

```
source logs

| filter $d.cx_security.source_ip_suspected != null
```

Surface the most frequently seen malicious values so you can prioritize investigation:

```
source logs

| filter $d.cx_security.source_ip_suspected != null

| groupby $d.cx_security.source_ip_suspected.malicious_value aggregate count() as hits

| orderby hits desc

| limit 10
```

Focus on high-confidence matches only:

```
source logs

| filter $d.cx_security.source_ip_suspected.reporting_feeds.Coralogix.confidence_level >= 7
```

## Dashboards[​](#dashboards "Direct link to Dashboards")

Unified Threat Intelligence ships with dashboards that answer both executive and analyst questions.

* **Executive overview.** A single-pane summary of threat activity across your environment: match volumes, trends, and the most active threat types.

[![Executive overview dashboard summarizing threat match volumes, trends, and the most active threat types](/docs/assets/images/dashboard-executive-overview-d5fd89e7e212a2ad240b6fdc5579a77a.webp)](https://coralogix.com/docs/assets/images/dashboard-executive-overview-d5fd89e7e212a2ad240b6fdc5579a77a.webp)

* **Threat type deep dive.** Drill into individual threat families, from ransomware and malware variants to connection-level source and destination mapping per threat type.

[![Threat type deep dive dashboard breaking down individual threat families and their connections](/docs/assets/images/dashboard-threat-type-deep-dive-3d36bbc9e00d86fd74dcdffcd6637c3d.webp)](https://coralogix.com/docs/assets/images/dashboard-threat-type-deep-dive-3d36bbc9e00d86fd74dcdffcd6637c3d.webp)

* **Geo intelligence maps.** World-map views aggregate malicious source and destination IPs by geography for fast attribution and region-based awareness.

[![World map aggregating malicious source and destination IP addresses by country](/docs/assets/images/dashboard-geo-intelligence-20cf7c2918db3bb5700eae5361e56708.webp)](https://coralogix.com/docs/assets/images/dashboard-geo-intelligence-20cf7c2918db3bb5700eae5361e56708.webp)

* **Most targeted ports.** Identifies which services attackers probe most, useful for prioritizing exposure reduction.

[![Dashboard panel ranking the ports most frequently targeted by malicious traffic](/docs/assets/images/dashboard-most-targeted-ports-1638ac7068aad90ca26fc8d06c1799ea.webp)](https://coralogix.com/docs/assets/images/dashboard-most-targeted-ports-1638ac7068aad90ca26fc8d06c1799ea.webp)

* **Network threat activity.** Time-series charts and enriched connection logs track malicious IPs, Tor exit nodes, and targeted destinations with application-level context.

[![Network threat activity dashboard with time-series charts and enriched connection logs](/docs/assets/images/dashboard-network-threat-activity-e5d226847ea734856915ac3d796f6c10.webp)](https://coralogix.com/docs/assets/images/dashboard-network-threat-activity-e5d226847ea734856915ac3d796f6c10.webp)

You can also build your own [custom dashboards](https://coralogix.com/docs/user-guides/custom-dashboards/introduction.md) by querying logs that contain the enriched `<key_name>_suspected` field.

## Bring your own intelligence[​](#bring-your-own-intelligence "Direct link to Bring your own intelligence")

The platform is fully extensible. You can layer your own intelligence and enrichment on top of everything Coralogix delivers.

**Custom threat intelligence.** Ingest commercial feeds, ISAC and sharing-group intelligence, and internal IOC lists via [STIX](https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html) and [TAXII](https://docs.oasis-open.org/cti/taxii/v2.1/os/taxii-v2.1-os.html). Your indicators are scored and decayed alongside Coralogix sources.

## Out-of-the-box alerts[​](#out-of-the-box-alerts "Direct link to Out-of-the-box alerts")

Pre-built Unified Threat Intelligence alerts fire the moment enriched telemetry matches a malicious indicator.

| Alert                              | Triggers when                                                                        |
| ---------------------------------- | ------------------------------------------------------------------------------------ |
| Outgoing traffic to Malicious IP   | A log records a connection from your environment to a known-malicious IP address.    |
| Incoming traffic from Malicious IP | A log records a connection into your environment from a known-malicious IP address.  |
| Malicious URL detected             | A log contains a URL that matches a malicious indicator.                             |
| Malicious domain detected          | A log contains a domain that matches a malicious indicator.                          |
| Malicious JA3 fingerprint detected | A TLS connection log carries a JA3 hash that matches known malicious tooling.        |
| Malicious JA4 fingerprint detected | A TLS connection log carries a JA4 fingerprint that matches known malicious tooling. |
| Malicious file hash detected       | A log contains a file hash that matches a known malware sample.                      |

Some of the extensions, such as "Snowbit STA", automatically configure their product log keys to be enriched by the **Unified Threat Intelligence**, as well as add predefined alerts to notify you immediately upon detection of malicious activity.

## Additional resources[​](#additional-resources "Direct link to Additional resources")

![Simplify Threat Detection with Unified Threat Intelligence](https://img.youtube.com/vi/r6T8MX1Ndwc/mqdefault.jpg)

Simplify Threat Detection with Unified Threat Intelligence

## Next steps[​](#next-steps "Direct link to Next steps")

Add geographic location data to your logs based on IP addresses with [Geo enrichment](https://coralogix.com/docs/user-guides/enrichment_rules/geo_enrichment.md).
