
May 12, 2026
3.0.0
ThreatQ Versions >= 5.24.0
Intel471 Reports
Overview
The Intel 471 Reports CDF integration enables ThreatQ users to ingest and operationalize intelligence from Intel 471’s report streams, providing access to a wide range of curated Information Reports and Intel Reports. Reports are retrieved based on user-defined filter criteria and are ordered by creation date, ensuring that the most recent intelligence is prioritized for analysis.
The integration provides the following feeds:
- Intel 471 Breach Alerts - queries the Intel 471 breach alert report stream and retrieves the complete details of each breach alert report using its unique identifier.
- Intel 471 FINTEL Reports - queries the Intel 471 FINTEL report stream and retrieves the complete details of each FINTEL report using its unique identifier.
- Intel 471 Geopolitical Reports - queries the Intel 471 geopolitical report stream and retrieves the complete details of each geopolitical report using its unique identifier.
- Intel 471 Information Reports - queries the Intel 471 information report stream and retrieves the complete details of each information report using its unique identifier.
- Intel 471 Spot Reports - queries the Intel 471 spot report stream and retrieves the complete details of each spot report using its unique identifier.
The integration ingests the following system objects:
- Adversary
- Adversary Attributes
- Attack Pattern
- Attack Pattern Attributes
- Indicator
- Indicator Attributes
- Malware
- Malware Attributes
- Report
- Report Attributes