Call a Specialist Today! (02) 9388 1741

Threat Intelligence
Unique Intel, Stronger Defenses

ESET Products
Threat Intelligence – Standalone Services
ESET APT Reports
In-depth technical analysis and activity summaries on advanced persistent threat groups, with a direct line to an ESET cybersecurity professional.
Threat Intelligence
Status: Standalone Service
ESET Intelligence Feeds
Curated, machine-readable feeds covering malicious files, domains, botnets, URLs, IPs and APT indicators of compromise (IoCs).
Threat Intelligence
Status: Standalone Service

Not sure which Threat Intelligence service is right for you? Ask us

Why It Matters

Why customers appreciate ESET Threat Intelligence

Unique visibility into where today's most sophisticated attackers operate, backed by decades of research.

Unique visibility

ESET draws on a wide range of intelligence sources and deep field experience to help organizations counter increasingly sophisticated attacks.

Stay ahead of adversaries

ESET closely tracks the regions where advanced persistent threat (APT) groups targeting Western organizations are known to operate, surfacing new threats early.

Faster, better decisions

Comprehensive reports and curated feeds help you anticipate threats and reduce exposure, backed by expert analysis rather than raw data alone.

Common Scenarios

Common use cases

See how ESET Threat Intelligence strengthens the way your team detects and responds to threats.

Worried about

Strengthening your security posture?

Informed by ESET's intelligence, teams can sharpen threat hunting and remediation, block APTs and ransomware, and improve overall security architecture.

Worried about

Manual threat investigation?

ESET's technology continuously searches for threats across multiple layers, from pre-boot through to resting state, drawing on telemetry from every country where ESET detects emerging activity.

Worried about

Integrating with your existing tools?

ESET Threat Intelligence is built to plug into your existing TIP, SIEM or SOAR, with a full API and standardized formats such as JSON and STIX.

Technology Deep Dive

What's included

Two services, one goal: turning ESET's global research into intelligence you can act on.

ESET APT Reports

Private, in-depth technical analysis of advanced persistent threat activity, curated by ESET's research team into a human-readable, actionable format.

  • Private, in-depth technical analysis reports
  • APT activity summary reports
  • Monthly summary for C-level executives
  • Direct access to an ESET cybersecurity professional
  • Access to ESET's MISP server
  • Up to 4 hours/month with an ESET analyst (Premium package)
ESET Intelligence Feeds

Curated, machine-readable feeds built on ESET's global telemetry, designed to enrich your view of the threat landscape and let you block indicators of compromise quickly.

  • Highly curated data with low false positives
  • Actionable, frequently updated content
  • Comprehensive API
  • Delivered in JSON and STIX formats
Compatibility

System requirements

Formats and integrations supported by ESET Threat Intelligence.

Supported data formats

  • JSON
  • STIX (2.0 / 2.1) via TAXII

Documented integrations

ESET provides step-by-step integration manuals, including for:

IBM QRadar Anomali MS Azure Sentinel OpenCTI ThreatQuotient

A comprehensive API with full documentation is available for integration into your TIP, SIEM or SOAR. Contact us to confirm compatibility with your specific environment.

Documentation

Documentation

Download the full Threat Intelligence overview or a sample APT report.

Download ESET Threat Intelligence Overview (PDF)

Unable to display PDF inline. Open in new tab.

A sample APT report is also available on request – contact us for a copy.

ESET Products
Threat Intelligence – Standalone Services
ESET APT Reports
In-depth technical analysis and activity summaries on advanced persistent threat groups, with a direct line to an ESET cybersecurity professional.
Threat Intelligence
Status: Standalone Service
ESET Intelligence Feeds
Curated, machine-readable feeds covering malicious files, domains, botnets, URLs, IPs and APT indicators of compromise (IoCs).
Threat Intelligence
Status: Standalone Service