Intelligence standards
CTP247 is a first-class citizen of the intel ecosystem — it reads the standards in and serves them back out.
Indicators, actors, and relationships as standard objects
Built-in read-only server — your tools poll CTP247 directly
Technique tagging on alerts, cases, and hunts — latest bundle, auto-synced
Exchange events with your existing MISP instances
Feed your knowledge graph from the CTP247 IOC store
Detection & enrichment
Indicators flow to where detection happens, and context flows back in.
Push IOCs into your XDR ruleset
Network detection fed from the same IOC truth
Internet-noise context on every IP indicator
Exposure enrichment during investigation pivots
Notifications & paging
Alerts route to the channel the right team actually watches — with SSRF-guarded webhooks for everything custom.
Channel routing by severity and module
Cards with alert context and links
Page on-call for critical findings
Alert lifecycle synced both ways
SMTP and Jasmin SMS for the channels that always work
JSON to any endpoint, with SSRF guards built in
Takedown providers
The Brand Defender drafts the takedown; these adapters carry it. Five today, pluggable by design.
REST API submission with evidence pack
RFC-822 formatted abuse submission
RFC-822 formatted abuse submission
Jira via SMTP for in-house takedown teams
Operator-driven with the same evidence and tracking
LLM providers
The agents speak prompt; you choose the model. Swap providers with an environment variable — including fully self-hosted.
Claude models via API
GPT models via API
Keep inference inside your AWS boundary
Ollama-class local models — zero outbound calls
Intelligence feeds
27 bundled sources, normalized into one pipeline — and your commercial subscriptions plug into the same one.
NVD, EPSS, CISA KEV
AlienVault OTX, GreyNoise, AbuseIPDB
URLhaus, ThreatFox, Feodo Tracker
Cloudflare Radar, RIPE RIS Live
Certificate transparency, WHOIS
Tor, I2P, Telegram, Matrix, leak sites, stealer markets
Don't see your tool?
Between TAXII 2.1, webhooks, and a Postgres you own, most integrations are an afternoon — not a roadmap item. Ask us on the call.