










IoCs often lack reliable context. They're either unattributed or misattributed, forcing CTI analysts to spend time validating intelligence before they can act. Feedly's Real-Time Threat Graph and MISP verification automates IOC context enrichment and helps reduce false positives.
With Feedly's enhanced IoC capabilities, you can:
Feedly now tracks more IoC types (adding SHA-1, SHA-256, MD5 hashes, and IPv6 addresses) with better validation and greater context. Customers report 5X faster research and fewer wasted validation cycles.
Researching IoCs that lack reliable context is often a bottleneck to validation. Unattributed or misattributed intelligence forces you to manually verify each IoC before you can act on it, turning what should be quick research into time-consuming investigative work. These validation cycles drain resources and delay response when speed matters most.
Feedly's enhanced IoC capabilities automate context enrichment across more indicator types, including SHA-1, SHA-256, MD5 hashes, and IPv6 addresses. The Real-Time Threat Graph and MISP Warning List verification connect threat actors, malware, and cyberattacks to IoCs while minimizing false positives. Whether you're doing manual research or running automated workflows in SOAR, Feedly helps you validate and triage faster.
Enter an IoC into Ask AI Research to instantly see its connections mapped across data from 10,000+ sources. Our automated enrichment surfaces related threat actors, malware families, and campaigns, and lets you jump directly to VirusTotal or Shodan for additional verification. You get verified context that eliminates guesswork, not a raw list of indicators.



Integrate IoC enrichment directly into your existing workflows through Feedly's API. Query any hash or IP address programmatically and receive structured intelligence about associated threat actors, malware, and cyberattacks. Push enriched intelligence into your TIP, SIEM, or SOAR via STIX-formatted feeds, providing automated context for your detection and response tools. Your team gets consistent, verified attribution without switching interfaces or manual work.

IoC research no longer needs to be a time sink. Feedly's enhanced IoC capabilities give you automated context enrichment across more indicator types, verified attribution through the Real-Time Threat Graph, and seamless integration with your existing security stack. Now you can deliver enriched IoCs with higher confidence for the threats that matter.
We currently cover the following IoC types: IP addresses, URLs, domains, email addresses, hashes and registry keys. Find more information about these types and their subtypes in our Feedly AI Library: https://feedly.com/ai/models/threat-intelligence
The validation of an IoC is made of multiple steps to ensure the highest rate of true positives over the number of predictions, also known as the “precision” metric:
• First, we validate IoCs based on the MISP Warnings Lists.
• Second, we infer from the semantics of how that ioc is mentioned in the article if the context is indeed malicious or not, with a mix of NLP models (BERT and LLM) fine-tuned and rigorously tested on a manually annotated train/test dataset, with a couple of manual rules for the edge cases.
Documentation here: https://docs.feedly.com/article/842-how-does-feedly-validate-iocs
Shodan doesn’t cover all IoC types, hence the limitation.
For now, there’s no other way to find information about IoCs coming from VirusTotal and Shodan other than by opening these links.
We currently attribute IoCs to three entity types: threat actors, malware, and cyber attacks.
Yes, you can copy and paste as many IoCs as you want in Ask AI in order to get results about them all at once.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。