Skip to main content

Malicious File and Infrastructure (TCF-2001) — Spectra Intelligence

Malicious File and Infrastructure feeds deliver structured threat intelligence covering malicious file hashes, domains, IP addresses, and URLs, enriched with malware context, confidence scoring, and indicator relationships.

Common Use Cases

IOC Feed (TCF-2001)

  • Block malicious files at the endpoint — Retrieve SHA-256 file hashes classified as malicious, enriched with malware family names and confidence scores, for use in endpoint detection and blocking rules.
  • Block malicious network infrastructure — Get malicious domains, IP addresses, and URLs with associated confidence levels and threat classifications for DNS sinkholes, firewall rules, or proxy blocklists.
  • Enrich a threat intelligence platform — Ingest structured IOCs with MITRE ATT&CK technique mappings, threat actor attributions, malware family labels, and indicator relationships to enrich your TIP or SIEM.
  • Incrementally consume new indicators — Use the continuous feed (Start and Pull) to retrieve only indicators published since your last request, without re-downloading the full dataset.

All Malicious File and Infrastructure Feeds