STIX 2.1 / TAXII 2.1 Threat Intel Feed

Live Indicators of Compromise (IoCs) and APT intelligence feeds for European telecommunications operators.

OASIS STIX 2.1 / TAXII 2.1 Threat Feed API

Real-time indicators of compromise for 5G Core, SEPP Roaming, Subsea Backhaul, and BGP Route Leaks.

Active Indicators of Compromise (IoC Stream)

Indicator NameSTIX PatternConfidenceLabels / TagsTimestamp

SIEM / SOAR Ingestion Quickstart

Integrate this feed directly into your Security Operations Center (SOC) telemetry.

Splunk Add-on for TAXII
taxii_version = 2.1
discovery_url = https://app.telcosec.eu/api/v1/stix/feed
collection_name = telcosec-eu-telecom-iocs
auth_header = Bearer <YOUR_API_KEY>
Microsoft Sentinel STIX/TAXII Connector
TAXII 2.1 Server URL: https://app.telcosec.eu/api/v1/stix/feed
Collection ID: telecom-threat-intel
Authentication Type: API Key / Bearer Token