OPEN THREAT INTELLIGENCE PLATFORM

Raw IOCs are noise.
Remediation is signal.

VEKTORA is a free, community-driven threat intelligence platform. 12 live feeds. Stack-specific playbooks for your firewall, EDR, and SIEM. No account. No paywall. No catch.

GET LIVE FEED API DOCS → VIEW FEEDS ↓
root@vektora:~
$curl vektora.info/api/v1/feed/latest
CONNECTING TO INTELLIGENCE PIPELINE...
SOURCES ACTIVE: 14/14
IOCs TODAY: FETCHING...
CRITICAL: --   HIGH: --
STACKS: PALO ALTO · CROWDSTRIKE · SPLUNK · SENTINEL
$
14M+
IOCs processed daily
14
Active threat feed sources
4
Security stack integrations
$0
Cost — free forever
KEY CAPABILITIES

What VEKTORA gives your blue team

01 — INGEST
14 live threat feeds
Feodo, URLhaus, ThreatFox, MalwareBazaar, CISA KEV, OTX, MISP, Emerging Threats, Blocklist.de, OpenPhish, CINS Army, VXVault, AbuseIPDB, and Palo Alto Unit42 — all normalized into one schema.
02 — CORRELATE
97% noise reduction
Cross-source dedup, confidence scoring, severity classification, and IOC type detection. Only what matters reaches your team.
03 — MAP
MITRE ATT&CK auto-tagging
Every IOC mapped to TTPs automatically. Understand the full adversary kill chain — not just what to block, but why the attack matters.
04 — REMEDIATE
Stack-specific playbooks
Palo Alto CLI. CrowdStrike Falcon API. Splunk SPL. Sentinel KQL. Exact commands for your tools — no translation needed.
05 — EXPORT
EDL & firewall-ready lists
Plain-text blocklists your firewall polls directly. Point your PA EDL at /v1/edl/ipv4 and forget about it.
06 — OPEN
No auth. No rate limits.
Every endpoint public. No API key, no registration. Free for the community — every defender on the planet.
LIVE INTELLIGENCE FEEDS

6 sources. Updating every 15 minutes.

Each window pulls independently from a separate source. Refreshes on load, on demand, or automatically every 60 seconds.

Connecting...
60s
AUTO-REFRESH ON
abuse.ch — Feodo TrackerLOADING
--:--:--ZFetching botnet C2 IPs...
0 entries
abuse.ch — URLhausLOADING
--:--:--ZFetching malicious URLs...
0 entries
abuse.ch — ThreatFoxLOADING
--:--:--ZFetching mixed IOCs...
0 entries
CISA — Known Exploited VulnerabilitiesLOADING
--:--:--ZFetching KEV catalogue...
0 entries
AlienVault — OTX PulsesLOADING
--:--:--ZFetching OSINT pulses...
0 entries
MISP — OSINT Community FeedLOADING
--:--:--ZFetching community intel...
0 entries
AbuseIPDB — Community BlacklistLOADING
--:--:--ZFetching reported IPs...
0 entries
Palo Alto Unit42 — Timely Threat IntelLOADING
--:--:--ZFetching Unit42 campaign IOCs...
0 entries
INTELLIGENCE SOURCES

12 feeds. One unified pipeline.

Every source is free, continuously monitored, deduplicated and cross-validated before reaching the API.

SourceIOC TypeCategoryRefreshStatus
abuse.ch — Feodo TrackerIPv4BOTNET C215 min
abuse.ch — URLhausURLMALWARE URL15 min
abuse.ch — ThreatFoxIPv4 · Domain · HashIOC MIX15 min
abuse.ch — MalwareBazaarSHA256 · MD5MALWARE HASH15 min
CISA — Known Exploited VulnsCVECVE15 min
AlienVault — OTX PulsesMixedOSINT15 min
MISP — OSINT CommunityMixedCOMMUNITY15 min
Emerging Threats IDSIPv4IDS RULES15 min
Blocklist.deIPv4BRUTE FORCE15 min
OpenPhishURLPHISHING15 min
CINS Army ScoreIPv4ACTIVE THREAT15 min
VXVaultURLMALWARE URL15 min
AbuseIPDB Community BlacklistIPv4ABUSE REPORTS15 min
Palo Alto Unit42 Threat IntelIPv4 · Domain · Hash · URLUNIT42 APTDaily
STACK-AWARE REMEDIATION

Your tools. Exact commands.

Select your security stack — VEKTORA generates exact CLI, API calls, and queries in the syntax your tools expect.

// SELECT YOUR STACK
// IOC
IOC: 185.220.101.47
Type: ipv4   Severity: CRITICAL
Campaign: LockBit 3.0   Confidence: 98%
// GENERATED PLAYBOOK
# Step 1 — Block at perimeter
set address-group VEKTORA-BLOCK
  add 185.220.101.47/32
commit

# Step 2 — EDL auto-refresh
set external-list vektora-c2
  url vektora.info/api/v1/edl/ipv4

# Step 3 — Threat prevention
set profiles virus lockbit-block
  action deny log-end yes
MITRE ATT&CK COVERAGE

Know the kill chain. Not just the IOC.

Every threat mapped to TTPs automatically. Understand what the adversary is doing — not just what to block.

RECON
T1595
T1590
T1591
T1596
T1593
RESOURCE
T1583
T1584
T1587
T1588
T1585
INIT ACCESS
T1566
T1190
T1133
T1195
T1078
EXECUTION
T1059
T1047
T1053
T1569
T1204
PERSIST
T1547
T1543
T1053
T1505
T1574
PRIV ESC
T1548
T1134
T1055
T1068
T1078
DEF EVASION
T1562
T1027
T1055
T1036
T1140
C2
T1071
T1573
T1105
T1572
T1090
EXFIL
T1041
T1567
T1048
T1052
T1537
IMPACT
T1486
T1490
T1485
T1498
T1491
OT / ICS
T0855
T0816
T0836
T0828
T0831
No activity
Low
Moderate
High
Critical — active exploitation
FREE API — NO AUTH REQUIRED

Start in 30 seconds.

Every endpoint is public. No key, no registration, no rate limits for reasonable community use.

# GET LATEST THREATS
curl https://api.vektora.info/v1/feed/latest
# REMEDIATION PLAYBOOK
curl -X POST .../v1/remediation
  -d '{"ioc":"1.2.3.4",
   "vendors":["palo_alto"]}'
# PALO ALTO EDL
set external-list vektora-c2
  url .../v1/edl/ipv4
  recurring five-minute
# FILTER BY SOURCE
curl ".../v1/threats
  ?source=cisa_kev
  &severity=critical"
FULL API DOCS (SWAGGER) →
GOVERNANCE, RISK & COMPLIANCE

Aligned with international security frameworks.

GOVERNANCE
Noise reduction at scale
97% noise reduction vs raw feeds. Strict source validation, confidence scoring, and behavioral cross-referencing before any IOC reaches the API.
95% BOT TRAFFIC FILTERED
REGULATORY
ISO 27001 & NIS2 aligned
Supports ISO 27001:2022 controls A.8.20 and A.5.7. Meets NIS2 Directive requirements for essential entities providing structured risk management.
ISO 27001:2022NIS2
PRIVACY
Outside GDPR scope
WAN-to-LAN operation only. Blocked IPs are external malicious actors — not personal data. No complex GDPR documentation required for deployment.
GDPR SAFE
RISK
Phased deployment model
Observation (logging only) → Activation (blocking). Transparent false positive process. Target: under 2 false positives per month, 48-hour resolution.
<2 FP / MONTH
PROJECT ROADMAP

What's coming next.

Q1–Q2 2025
Core platform
6 feeds, FastAPI, Supabase, Cloudflare Pages
COMPLETE
Q3 2025
Stack playbooks
Palo Alto, CrowdStrike, Splunk, Sentinel
COMPLETE
Q4 2025
12 feed sources
MalwareBazaar, ET, Blocklist.de, OpenPhish, CINS, VXVault
COMPLETE
Q2 2026
Threat map & dashboard
Global threat map, customer dashboard, webhook delivery
IN PROGRESS
Q3 2026
STIX / TAXII server
Enterprise SIEM integration via STIX 2.1 / TAXII 2.1
PLANNED
Q4 2026
OT / ICS intelligence
IEC 62443 aligned intel for energy & manufacturing
PLANNED
LEGAL

Privacy Policy

Last updated: April 2026

DATA WE COLLECT

VEKTORA collects no personal data from visitors. We do not use cookies, tracking pixels, or analytics that identify individuals. The threat intelligence data we process consists entirely of malicious IP addresses, domains, URLs, and file hashes — not personal information.

API & CONTACT FORMS

If you submit a contact form, we collect your name, email address, and message solely to respond to your enquiry. This data is not shared with third parties, not used for marketing, and deleted upon request. API usage is unauthenticated and generates no user-linked logs.

THREAT DATA SCOPE

All IOCs we process are malicious infrastructure indicators (WAN-side IPs, domains, hashes). These are external threat actors — not personal data under GDPR, the Australian Privacy Act 1988, or any comparable framework. No special-category data is processed.

YOUR RIGHTS

You may request deletion of any contact form submission at any time by emailing info@connex.au. We will respond within 48 hours. As we collect no identifying data from API users, no deletion request is possible or necessary for API usage.

REGULATORY ALIGNMENT — VEKTORA operates in compliance with the Australian Privacy Act 1988, GDPR Article 2(2) (WAN-to-LAN scope exclusion), ISO 27001:2022 controls A.5.7 and A.8.20, and the NIS2 Directive requirements for threat intelligence providers. Questions: info@connex.au
TERMS OF SERVICE

Usage Terms

By accessing VEKTORA's API or website, you agree to the following terms.

PERMITTED USE

You may use VEKTORA's data for defensive security purposes — blocking threats, enriching SIEMs, building detection rules, and protecting infrastructure. Academic research and security tool development are also permitted.

PROHIBITED USE

You may not use VEKTORA's data to attack systems, conduct offensive operations, harass individuals, scrape for commercial resale without attribution, or circumvent rate limits in a way that degrades service for others.

ATTRIBUTION

You are encouraged (not required) to attribute VEKTORA when publishing research or tools built on this data. A link to vektora.info is sufficient. Commercial products built on our data must display clear attribution.

NO WARRANTY

Threat intelligence data is provided "as-is" without warranty. False positives may occur. VEKTORA is not liable for blocking decisions made based on this data. Always validate IOCs in your environment before deploying block rules in production.

GOVERNING LAW

These terms are governed by the laws of New South Wales, Australia. Disputes shall be resolved in NSW courts. For questions: info@connex.au

CONTACT US

Get in touch.

False positive reports, integration questions, partnership enquiries, or just want to say hi — we respond within 48 hours.

CONTACT INFORMATION
RESPONSE TIME
Within 48 hours
REPORT FALSE POSITIVES
Include the IOC, your evidence it's benign, and what tool flagged it. We review and remove within 48 hours.
SECURITY DISCLOSURES
Responsible disclosure to info@connex.au with subject line [SECURITY]. We acknowledge within 24 hours.
SEND A MESSAGE