Zedmos

Threat intelligence

Indicators you can act on, not a feed you have to triage

Curated indicators with a confidence model, cross-validated across sources before they are promoted, and delivered in the format the firewall already understands.

Corroboration

Not every indicator deserves the same treatment

A domain named by one feed and a domain named by four independent feeds, an active enrichment confirmation and a honeypot are not the same claim. Zedmos tiers them, and only the tiers you choose are enforced.

Verified

314,330

3% · indicators

Multi-source consensus, active confirmation or honeypot ground truth. Safe to block without review.

Trusted

880,822

7% · indicators

Corroborated, but with less independent evidence. Shipped by default alongside verified.

Community

10,855,605

90% · indicators

Single-source or lower-confidence. Available, not enforced unless you ask for it.

Enforced by default: 1,195,152 indicators

What is in it

Domains
11,017,004
IP addresses
946,785
File hashes
69,065
Network ranges
17,806
JA3 fingerprints
97

The last 24 hours

Where the catalogue grew since yesterday.

Gambling
+7,829
Malware
+1,714
Scanners
+944
File sha256 malware
+940
Attack infrastructure
+752
Phishing
+362

Verification

What we do to it before you enforce it

A large catalogue that blocks a payroll provider costs more than it saves. These are the checks that run against the catalogue itself, and their most recent results.

79%

Cross-validation

700 sampled indicators re-checked against independent sources

0

Allowlist smoke test

54 well-known domains checked for accidental inclusion — leaked

73%

DNS liveness

of catalogued domains resolved and classified as alive, dead or sinkholed

17,563

Cloud false positives caught

addresses inside major cloud ranges held back from the enforced tiers, so a shared IP does not take Microsoft 365 down with it

What it can attribute

Malware families

  • Phishing99,342
  • Other30,029
  • js.clearfake19,529
  • Mirai18,391
  • Mobile C&C11,391
  • Botnet C&C11,138

Threat actors

  • SilkParasite144
  • REF9334135
  • APT28132
  • Hive0163, Rhysida, Vanilla Tempest, TAG-124, ITG23125
  • BengalSEO109

Enriched with: greynoise · abuseipdb · virustotal

Delivery

It has to arrive in a form your tools already read

The catalogue is built into snapshots and served in the formats a firewall, a resolver and a SOC pipeline each expect — so it lands without a translation layer you have to maintain.

  • plain
  • suricata
  • pihole
  • opnsense
  • mikrotik
  • unbound-rpz
  • stix-2.1
  • taxii-2.1
  • misp
  • sigma
  • yara

16 TAXII 2.1 collections · 50/87 sources healthy right now

Where the intelligence comes from

Promotion by agreement

An indicator is promoted when independent sources agree on it, which is what keeps a blocklist from turning into an outage.

Standards, not a bespoke format

STIX 2.1 confidence and TAXII delivery, so the same intelligence feeds a SIEM and a firewall without a translation layer in between.

Cloud exceptions that prevent self-harm

Major productivity platforms are protected from over-broad network blocks, because an indicator inside a shared cloud range should not take out a company's mail.

Read it in full

This page makes the argument. These say how it is actually done, screen by screen and setting by setting.