Zedmos

Threat intelligence

Indicators you can act on, not a feed you have to triage

Curated indicators with a confidence model, cross-validated across sources before they are promoted, and delivered in the format the firewall already understands.

Corroboration

Not every indicator deserves the same treatment

A domain named by one feed and a domain named by four independent feeds, an active enrichment confirmation and a honeypot are not the same claim. Zedmos tiers them, and only the tiers you choose are enforced.

Verified

289,694

2% · indicators

Multi-source consensus, active confirmation or honeypot ground truth. Safe to block without review.

Trusted

875,673

7% · indicators

Corroborated, but with less independent evidence. Shipped by default alongside verified.

Community

10,741,069

90% · indicators

Single-source or lower-confidence. Available, not enforced unless you ask for it.

Enforced by default: 1,165,367 indicators

What is in it

Domains
10,901,816
IP addresses
924,264
File hashes
62,470
Network ranges
17,789
JA3 fingerprints
97

The last 24 hours

Where the catalogue grew since yesterday.

Gambling
+4,746
Malware
+3,996
Adult
+2,284
Attack infrastructure
+1,733
Phishing
+748
Ransomware
+747

Verification

What we do to it before you enforce it

A large catalogue that blocks a payroll provider costs more than it saves. These are the checks that run against the catalogue itself, and their most recent results.

77%

Cross-validation

700 sampled indicators re-checked against independent sources

0

Allowlist smoke test

54 well-known domains checked for accidental inclusion — leaked

65%

DNS liveness

of catalogued domains resolved and classified as alive, dead or sinkholed

60,012

Cloud false positives caught

addresses inside major cloud ranges held back from the enforced tiers, so a shared IP does not take Microsoft 365 down with it

What it can attribute

Malware families

  • Phishing99,342
  • Other30,045
  • js.clearfake18,578
  • Mirai16,948
  • Mobile C&C11,391
  • Botnet C&C11,143

Threat actors

  • APT28132
  • Hive0163, Rhysida, Vanilla Tempest, TAG-124, ITG23125
  • BengalSEO109
  • APT-C-60102
  • X3D MINER100

Enriched with: greynoise · abuseipdb · virustotal

Delivery

It has to arrive in a form your tools already read

The catalogue is built into snapshots and served in the formats a firewall, a resolver and a SOC pipeline each expect — so it lands without a translation layer you have to maintain.

  • plain
  • suricata
  • pihole
  • opnsense
  • mikrotik
  • unbound-rpz
  • stix-2.1
  • taxii-2.1
  • misp
  • sigma
  • yara

16 TAXII 2.1 collections · 49/87 sources healthy right now

Where the intelligence comes from

Promotion by agreement

An indicator is promoted when independent sources agree on it, which is what keeps a blocklist from turning into an outage.

Standards, not a bespoke format

STIX 2.1 confidence and TAXII delivery, so the same intelligence feeds a SIEM and a firewall without a translation layer in between.

Cloud exceptions that prevent self-harm

Major productivity platforms are protected from over-broad network blocks, because an indicator inside a shared cloud range should not take out a company's mail.