Threat Intelligence
Unique Intel, Stronger Defenses
In-depth technical analysis and activity summaries on advanced persistent threat groups, with a direct line to an ESET cybersecurity professional.
Status: Standalone Service
Curated, machine-readable feeds covering malicious files, domains, botnets, URLs, IPs and APT indicators of compromise (IoCs).
Status: Standalone Service
Not sure which Threat Intelligence service is right for you? Ask us
Why customers appreciate ESET Threat Intelligence
Unique visibility into where today's most sophisticated attackers operate, backed by decades of research.
ESET draws on a wide range of intelligence sources and deep field experience to help organizations counter increasingly sophisticated attacks.
ESET closely tracks the regions where advanced persistent threat (APT) groups targeting Western organizations are known to operate, surfacing new threats early.
Comprehensive reports and curated feeds help you anticipate threats and reduce exposure, backed by expert analysis rather than raw data alone.
Common use cases
See how ESET Threat Intelligence strengthens the way your team detects and responds to threats.
Strengthening your security posture?
Informed by ESET's intelligence, teams can sharpen threat hunting and remediation, block APTs and ransomware, and improve overall security architecture.
Manual threat investigation?
ESET's technology continuously searches for threats across multiple layers, from pre-boot through to resting state, drawing on telemetry from every country where ESET detects emerging activity.
Integrating with your existing tools?
ESET Threat Intelligence is built to plug into your existing TIP, SIEM or SOAR, with a full API and standardized formats such as JSON and STIX.
What's included
Two services, one goal: turning ESET's global research into intelligence you can act on.
Private, in-depth technical analysis of advanced persistent threat activity, curated by ESET's research team into a human-readable, actionable format.
- Private, in-depth technical analysis reports
- APT activity summary reports
- Monthly summary for C-level executives
- Direct access to an ESET cybersecurity professional
- Access to ESET's MISP server
- Up to 4 hours/month with an ESET analyst (Premium package)
Curated, machine-readable feeds built on ESET's global telemetry, designed to enrich your view of the threat landscape and let you block indicators of compromise quickly.
- Highly curated data with low false positives
- Actionable, frequently updated content
- Comprehensive API
- Delivered in JSON and STIX formats
System requirements
Formats and integrations supported by ESET Threat Intelligence.
Supported data formats
- JSON
- STIX (2.0 / 2.1) via TAXII
Documented integrations
ESET provides step-by-step integration manuals, including for:
A comprehensive API with full documentation is available for integration into your TIP, SIEM or SOAR. Contact us to confirm compatibility with your specific environment.
Documentation
Download the full Threat Intelligence overview or a sample APT report.
Download ESET Threat Intelligence Overview (PDF)
A sample APT report is also available on request – contact us for a copy.
In-depth technical analysis and activity summaries on advanced persistent threat groups, with a direct line to an ESET cybersecurity professional.
Status: Standalone Service
Curated, machine-readable feeds covering malicious files, domains, botnets, URLs, IPs and APT indicators of compromise (IoCs).
Status: Standalone Service
