{
  "generated_at": "2026-06-10T16:17:48.510Z",
  "window_days": 7,
  "cap": 5000,
  "feeds": [
    {
      "slug": "misp-domains",
      "title": "MISP — Suspicious Domains",
      "description": "Domain indicators from the MISP threat intelligence feed (CIRCL OSINT), trailing rolling window. Raw indicator list for SIEM ingest; see /sigma/ for translatable detection rules.",
      "source": "misp",
      "ioc_type": "domain",
      "format": "csv",
      "url": "/intel/csv/misp-domains.csv",
      "indicator_count": 5000,
      "generated_at": "2026-06-10T16:17:48.510Z"
    },
    {
      "slug": "misp-domains",
      "title": "MISP — Suspicious Domains",
      "description": "Domain indicators from the MISP threat intelligence feed (CIRCL OSINT), trailing rolling window. Raw indicator list for SIEM ingest; see /sigma/ for translatable detection rules.",
      "source": "misp",
      "ioc_type": "domain",
      "format": "misp-json",
      "url": "/intel/misp/misp-domains.json",
      "indicator_count": 5000,
      "generated_at": "2026-06-10T16:17:48.510Z"
    },
    {
      "slug": "misp-domains",
      "title": "MISP — Suspicious Domains",
      "description": "Domain indicators from the MISP threat intelligence feed (CIRCL OSINT), trailing rolling window. Raw indicator list for SIEM ingest; see /sigma/ for translatable detection rules.",
      "source": "misp",
      "ioc_type": "domain",
      "format": "stix",
      "url": "/intel/stix/misp-domains.json",
      "indicator_count": 5000,
      "generated_at": "2026-06-10T16:17:48.510Z"
    },
    {
      "slug": "misp-ips",
      "title": "MISP — Flagged IPs",
      "description": "IP address indicators (ip-src and ip-dst attributes) from the MISP threat intelligence feed, trailing rolling window. Raw indicator list for SIEM ingest.",
      "source": "misp",
      "ioc_type": "ip",
      "format": "csv",
      "url": "/intel/csv/misp-ips.csv",
      "indicator_count": 1082,
      "generated_at": "2026-06-10T16:17:48.510Z"
    },
    {
      "slug": "misp-ips",
      "title": "MISP — Flagged IPs",
      "description": "IP address indicators (ip-src and ip-dst attributes) from the MISP threat intelligence feed, trailing rolling window. Raw indicator list for SIEM ingest.",
      "source": "misp",
      "ioc_type": "ip",
      "format": "misp-json",
      "url": "/intel/misp/misp-ips.json",
      "indicator_count": 1082,
      "generated_at": "2026-06-10T16:17:48.510Z"
    },
    {
      "slug": "misp-ips",
      "title": "MISP — Flagged IPs",
      "description": "IP address indicators (ip-src and ip-dst attributes) from the MISP threat intelligence feed, trailing rolling window. Raw indicator list for SIEM ingest.",
      "source": "misp",
      "ioc_type": "ip",
      "format": "stix",
      "url": "/intel/stix/misp-ips.json",
      "indicator_count": 1082,
      "generated_at": "2026-06-10T16:17:48.510Z"
    },
    {
      "slug": "urlhaus-urls",
      "title": "URLhaus — Malware Distribution URLs",
      "description": "Raw malware distribution URLs flagged by URLhaus (abuse.ch), trailing rolling window. Full URLs as-published; for hostname-only matching see urlhaus-domains.",
      "source": "urlhaus",
      "ioc_type": "url",
      "format": "csv",
      "url": "/intel/csv/urlhaus-urls.csv",
      "indicator_count": 4222,
      "generated_at": "2026-06-10T16:17:48.510Z"
    },
    {
      "slug": "urlhaus-urls",
      "title": "URLhaus — Malware Distribution URLs",
      "description": "Raw malware distribution URLs flagged by URLhaus (abuse.ch), trailing rolling window. Full URLs as-published; for hostname-only matching see urlhaus-domains.",
      "source": "urlhaus",
      "ioc_type": "url",
      "format": "misp-json",
      "url": "/intel/misp/urlhaus-urls.json",
      "indicator_count": 4222,
      "generated_at": "2026-06-10T16:17:48.510Z"
    },
    {
      "slug": "urlhaus-urls",
      "title": "URLhaus — Malware Distribution URLs",
      "description": "Raw malware distribution URLs flagged by URLhaus (abuse.ch), trailing rolling window. Full URLs as-published; for hostname-only matching see urlhaus-domains.",
      "source": "urlhaus",
      "ioc_type": "url",
      "format": "stix",
      "url": "/intel/stix/urlhaus-urls.json",
      "indicator_count": 4222,
      "generated_at": "2026-06-10T16:17:48.510Z"
    },
    {
      "slug": "urlhaus-domains",
      "title": "URLhaus — Malware Distribution Domains",
      "description": "Hostnames extracted from URLhaus malware distribution URLs, trailing rolling window. IPv4-literal hosts excluded; hostnames lowercased and deduplicated at ingestion (Phase I).",
      "source": "urlhaus",
      "ioc_type": "domain",
      "format": "csv",
      "url": "/intel/csv/urlhaus-domains.csv",
      "indicator_count": 649,
      "generated_at": "2026-06-10T16:17:48.510Z"
    },
    {
      "slug": "urlhaus-domains",
      "title": "URLhaus — Malware Distribution Domains",
      "description": "Hostnames extracted from URLhaus malware distribution URLs, trailing rolling window. IPv4-literal hosts excluded; hostnames lowercased and deduplicated at ingestion (Phase I).",
      "source": "urlhaus",
      "ioc_type": "domain",
      "format": "misp-json",
      "url": "/intel/misp/urlhaus-domains.json",
      "indicator_count": 649,
      "generated_at": "2026-06-10T16:17:48.510Z"
    },
    {
      "slug": "urlhaus-domains",
      "title": "URLhaus — Malware Distribution Domains",
      "description": "Hostnames extracted from URLhaus malware distribution URLs, trailing rolling window. IPv4-literal hosts excluded; hostnames lowercased and deduplicated at ingestion (Phase I).",
      "source": "urlhaus",
      "ioc_type": "domain",
      "format": "stix",
      "url": "/intel/stix/urlhaus-domains.json",
      "indicator_count": 649,
      "generated_at": "2026-06-10T16:17:48.510Z"
    }
  ]
}
