Makondoo threat intelligence guides
These pages are written for this product, not copied from a US vendor glossary. They exist so search engines can read Makondoo CTI without executing the dashboard JavaScript.
- What is threat intelligence? — Threat intelligence is analyzed evidence about cyber adversaries. See how Makondoo turns public IOC feeds and Threatr lookups into a live dashboard, API, and attack-surface BOM.
- What is an IOC (indicator of compromise)? — An IOC is a technical clue that a system may be compromised: IP, domain, URL, hash, email, or CVE. See which IOC types Makondoo ingests from public threat feeds.
- What is a threat intelligence platform? — A TIP collects, stores, enriches, and shares cyber threat intelligence. Makondoo is a Threatr-backed TIP with a live IOC dashboard, investigate, BOM, and a public API.
- Free threat intelligence API — Public REST API for live IOCs, Threatr lookup, stats, BOM scans, HIBP Pwned Passwords k-anonymity, and the latest public breach catalog. No Bearer key for reads. 100 requests/hour/IP.
- Attack-surface BOM tracker — Discover hostnames for a domain from crt.sh certificate-transparency logs, match them against live Threatr IOCs, and upload a CycloneDX or SPDX SBOM for OSV findings.
- Cyber threat intelligence from Kenya — Makondoo Inc runs a public Threatr-backed threat intelligence platform from Kenya: live IOCs, investigate, BOM, and a free adapter API. Built for defenders who cannot buy Recorded Future.
- Threat intelligence feeds we ingest — Makondoo ingests URLhaus, ThreatFox, Feodo Tracker, OpenPhish, Emerging Threats, SSLBL, and blocklist.de into Threatr every 12 hours. No extra vendor bill.
People also ask
What does threat intel do?
Threat intelligence turns raw signals — malicious IPs, phishing URLs, malware hashes, attacker infrastructure — into something a defender can act on. On Makondoo, that means a live IOC dashboard from Threatr, an investigate panel for a single observable, and an attack-surface BOM built from certificate-transparency logs.
What is threat intelligence in simple terms?
It is evidence about who is attacking, how they attack, and which indicators to block. Data without context is a blocklist. Intelligence is that data plus source, timing, and how it relates to your assets.
What are the five stages of the threat intelligence lifecycle?
Direction (what you need to know), collection (feeds and lookups), processing (normalize and dedupe), analysis (what it means for you), and dissemination (dashboard, API, BOM). Makondoo covers collection through dissemination for public CTI; direction stays with your security team.
What is a threat intel platform?
A threat intelligence platform (TIP) stores indicators, enriches them, and exposes them to analysts and tools. Makondoo is a Threatr-backed TIP: ingested open feeds, cached vendor enrichment, a public adapter API, and BOM/SBOM matching — not a SIEM and not an EDR.
What is Threat Intelligence?
Cyber threat intelligence (CTI) is analyzed information about adversaries and their infrastructure. Strategic CTI is for leaders. Operational CTI is about campaigns. Technical CTI is IOCs you can put in a firewall. This site publishes technical CTI from public feeds and Threatr.
Is Makondoo threat intelligence free?
The public dashboard, investigate lookups (without forcing vendor refresh), BOM scans, and adapter API are free to use, rate-limited at 100 requests per hour per IP. Team and Enterprise are contact-sales for private ingest and hosted Threatr.