Skip to content

Sekoia Intelligence (CTI) for security operations

Availability

Sekoia Intelligence is available in the Sekoia SOC platform with a Sekoia Defend license, or as a standalone Cyber Threat Intelligence (CTI) product delivered through API integration.

Sekoia Intelligence gives security teams current, contextualized threat intelligence for detection, investigation, and threat hunting. Each intelligence record includes explicit validity timestamps and is updated as new evidence emerges. Analysts can distinguish active threat activity from expired indicators and focus on intelligence that applies to their environment.

The Intelligence Center combines analyst research, threat publications, and a searchable CTI knowledge base. Teams can monitor developing threats, investigate attacker infrastructure, and follow campaigns across sectors and geographies.

Sekoia Intelligence draws on more than 500 sources to track over 200 threat actor groups and their infrastructure worldwide. Sekoia analysts process and assess this material, adding context for strategic planning, detection engineering, and incident response.

Intelligence Center features

Access and investigate threat intelligence

Use the Intelligence Center to research threat actors, malware, infrastructure, campaigns, and related activity. The database combines external sources with research produced by Sekoia analysts, giving strategic and operational teams a shared intelligence resource.

  • Search the intelligence database: Find current intelligence enriched with analyst research and contextual analysis. See Intelligence database.
  • Set up custom feeds: Follow topics relevant to your organization and receive updates when reports change. See Feeds.
  • Explore relationships: Use Graph Explorations to investigate connections between threat actors, infrastructure, malware, and cases.

Tailor intelligence to your priorities

Filter intelligence by sector, activity, source, or geography. Create custom feeds around the threats and regions most relevant to your organization.

  • Filter the content you see in the database by setting up feeds.

Monitor and report on threat activity

Use dashboards and widgets to track threat activity, research output, and changes in your intelligence database. Teams can create views around the key performance indicators (KPIs) that matter to their security operations.

  • Create and edit your dashboards to monitor sectors, research output, or the evolution of your threat database.