Overview
Threatr is a web-based threat-intelligence aggregation platform designed to unify and normalize data collected from multiple external security sources. It centralizes information from services such as VirusTotal, OTX AlienVault, Shodan, Scarlet Shark, and MISP, and exposes all aggregated intelligence through a simple REST API.
Quick start
Spin up Threatr locally and start asking it about the world's shadiest hashes and IPs.
Local deployment
This section describes the procedure to self-host Threatr locally. It must not
Integrations
In the Threatr administration panel, create new entries for the 3rd-party vendors in the Vendor Credentials menu.
REST API
Threatr propagates user's requests to the different configured services and returns the aggregated entities along with the knowledge graph linking the different entities with the requested one. Threatr stores the results in its internal database and will always return the data already stored unless the attribute force is set to true. By forcing the refresh of the data, Threatr will propagate the user's request to all external services.