{"service":"threatintel","summary":"Type-agnostic IOC enrichment for SOC/DFIR agents: one indicator (file hash / IP / domain / URL / CVE) → one cited, normalized verdict. Keyless core fuses CIRCL known-file context with our public-source IP/domain reputation; malware-family attribution is an optional licensed abuse.ch upgrade.","sources":[{"id":"circl_hashlookup","name":"CIRCL hashlookup","host":"hashlookup.circl.lu","kind":"known-file / whitelist context","license":"free public API (CIRCL)","attribution":"CIRCL hashlookup (hashlookup.circl.lu) — NSRL RDS + distro package sets","grains":["md5","sha1","sha256"],"keyed":false,"env_var":null,"enabled":true},{"id":"fraud_ip","name":"IP reputation (reused /fraud/ip engine)","host":"(in-memory: iptoasn + Tor + Spamhaus DROP)","kind":"IP reputation / C2-infra context","license":"public datasets (iptoasn public-domain, Tor, Spamhaus DROP attribution)","attribution":"computed by us from iptoasn + Tor exit list + Spamhaus DROP","grains":["ipv4","ipv6"],"keyed":false,"env_var":null,"enabled":true},{"id":"domaintrust","name":"Domain/URL trust (reused /domain/trust engine)","host":"(RDAP + DoH + TLS + Certificate Transparency)","kind":"phishing / domain-trust context","license":"free/public (RDAP, public DoH, live TLS, public CT logs)","attribution":"computed by us from RDAP + DoH + TLS + CT","grains":["domain","url"],"keyed":false,"env_var":null,"enabled":true},{"id":"cve","name":"CVE intelligence (delegated to /cve/lookup)","host":"(NVD + EPSS + CISA-KEV + OSV)","kind":"software-vulnerability reference","license":"public (NVD/EPSS/KEV/OSV)","attribution":"see /cve/lookup","grains":["cve"],"keyed":false,"env_var":null,"enabled":true},{"id":"abusech","name":"abuse.ch commercial feeds (ThreatFox / MalwareBazaar / URLhaus / Feodo)","host":"*.abuse.ch","kind":"malware-family attribution / C2 / malware-URL (LICENSED)","license":"abuse.ch commercial Auth-Key required for for-profit use (env-gated, OFF)","attribution":"abuse.ch (ThreatFox / MalwareBazaar / URLhaus / Feodo Tracker)","grains":["md5","sha1","sha256","ipv4","ipv6","domain","url"],"keyed":true,"env_var":"X402_ABUSECH_AUTH_KEY","enabled":false}],"indicator_types":["md5","sha1","sha256","cve","url","ipv4","ipv6","domain"],"verdicts":["malicious","suspicious","benign_known","unknown"],"abusech_bridge_enabled":false,"disclaimer":"Automated reputation/threat indicators, not a guarantee; for security triage. Absence from a source is not proof of safety, and presence is not proof of malice. Keyless core = known-file context (CIRCL hashlookup) fused with our public-source IP/domain reputation verdicts; malicious-hash and malware-family attribution require a licensed abuse.ch commercial Auth-Key (optional, off by default)."}