Makondoo Inc
Makondoo threat intelligence
Live IOC dashboard · Learn · API

What is threat intelligence?

Threat intelligence is not a feed dump. It is analyzed evidence about who is attacking networks, which infrastructure they use, and which indicators a defender should treat as hostile. Security teams call it CTI — cyber threat intelligence — to distinguish it from generic “intel” marketing.

Three layers show up in every serious programme:

Makondoo publishes the technical layer in public. The live site at threat-intel.makondoo.org is a Threatr-backed IOC dashboard: URLhaus, ThreatFox, Feodo Tracker, OpenPhish, Emerging Threats, SSLBL, and blocklist.de are ingested on a 12-hour cadence. Investigate an observable and you get cached Threatr entities plus free OSINT (Hudson Rock infostealer data, Shodan InternetDB, CIRCL hashlookup). Lookups never force a paid vendor refresh.

Threat intelligence vs a blocklist

A blocklist is a list. Intelligence adds source, first-seen, relationships, and whether the indicator still matters. If you only ingest IPs and never look them up, you have collection without analysis. That is why this platform exposes a lookup API and a knowledge graph, not only a table of rows.

Where Makondoo sits

We are not CrowdStrike, IBM, or Google Threat Intelligence. Those products wrap endpoint telemetry, closed collections, and huge research orgs. Makondoo is a Kenya-built, open-ingest CTI console in front of Threatr. Community use is free. If you need private workspaces or a dedicated Threatr tenant, contact sales.

The lifecycle, without the slideware

  1. Direction — decide which assets and threats you care about (your job).
  2. Collection — we pull public malware and phishing feeds into Threatr.
  3. Processing — observables are typed (IP, domain, URL, hash, email, CVE) and stored.
  4. Analysis — investigate returns related entities, events, and relations from cache.
  5. Dissemination — dashboard, BOM tracker, and the public adapter API.

Next: what an IOC is, what a TIP is, and CTI from Kenya.

People also ask

What does threat intel do?

Threat intelligence turns raw signals — malicious IPs, phishing URLs, malware hashes, attacker infrastructure — into something a defender can act on. On Makondoo, that means a live IOC dashboard from Threatr, an investigate panel for a single observable, and an attack-surface BOM built from certificate-transparency logs.

What is threat intelligence in simple terms?

It is evidence about who is attacking, how they attack, and which indicators to block. Data without context is a blocklist. Intelligence is that data plus source, timing, and how it relates to your assets.

What are the five stages of the threat intelligence lifecycle?

Direction (what you need to know), collection (feeds and lookups), processing (normalize and dedupe), analysis (what it means for you), and dissemination (dashboard, API, BOM). Makondoo covers collection through dissemination for public CTI; direction stays with your security team.

What is a threat intel platform?

A threat intelligence platform (TIP) stores indicators, enriches them, and exposes them to analysts and tools. Makondoo is a Threatr-backed TIP: ingested open feeds, cached vendor enrichment, a public adapter API, and BOM/SBOM matching — not a SIEM and not an EDR.

What is Threat Intelligence?

Cyber threat intelligence (CTI) is analyzed information about adversaries and their infrastructure. Strategic CTI is for leaders. Operational CTI is about campaigns. Technical CTI is IOCs you can put in a firewall. This site publishes technical CTI from public feeds and Threatr.

Is Makondoo threat intelligence free?

The public dashboard, investigate lookups (without forcing vendor refresh), BOM scans, and adapter API are free to use, rate-limited at 100 requests per hour per IP. Team and Enterprise are contact-sales for private ingest and hosted Threatr.