One reputation service returning nothing on an address means that service has not seen it, which analysts routinely over-read as clean. Fanning the same indicator across sources turns a lookup into a judgement. Treat the attribution output with more caution than the enrichment: naming a threat actor from indicator overlap is genuinely hard, and a confident label is easier to produce than to justify. Useful as a starting hypothesis, not a conclusion.
A threat intelligence server that takes an indicator of compromise, queries several sources, and produces an attributed, reportable result.
- Multi-source analysis of an indicator rather than a single lookup
- Attribution against known threat actor groups
- Interactive reporting on the findings
Python at the version the README names; also published as a Docker image and on PyPI. Apache licensed.
One command plus a key — pip install fastmcp-threatintel, then supply credentials
