Threat Intelligence modules are used to collect and analyze information from multiple sources. Certego&apos:s proprietary Threat Intelligence platform, Quokka, generates actionable tactical intelligence to counter next-generation threats.

Threat Intelligence IOC Feeds

It ensures a continuous flow of Indicators of Compromise (IOCs) generated by the proprietary Threat Intelligence platform. These indicators (verified malicious IPs and domains) are integrated in real-time into the client's defense systems, automatically updating firewall blocklists to enhance preventive protection.

Dark Web Scanner

It allows users to stay up-to-date on new information emerging from the Dark Web, enabling the monitoring of any sensitive data exposed to potential threats. It works through keywords: clients select a set of keywords to monitor, and whenever data related to these keywords is detected in the Dark Web, Certego analyzes it and immediately notifies the client.

Early Warning

It keeps clients constantly informed about newly disclosed vulnerabilities. Certego continuously monitors public alerts (such as those from NIST) related to the technologies used by clients, providing all necessary information to implement timely countermeasures before vulnerabilities can be exploited by attackers.

Targeted CyberThreat Intelligence

It adopts an exclusive and customized approach to information gathering, accessing Dark Web sources such as closed forums, underground networks, and private social groups. This allows for the transformation of collected data into actionable intelligence, providing clients with relevant, accurate, and immediately usable information, shared through our PanOptikon® platform.

Partnership

Certego's intelligence feeds are internationally recognized for their quality, as demonstrated by the partnership where Certego serves as a Threat Intelligence contributor for major global distribution sources.

Certego is Threat Intelligence contributor to VirusTotal since 2019, the world’s most comprehensive and widely used threat intelligence platform.

Certego shares its IOCs with CrowdSec, the open-source project that uses crowdsourced data to identify and block malicious IPs in real-time on a global scale.

Certego shares its DNS with SIE Europe, whose mission is to make the European digital economy safer through the collection and sharing of relevant data to combat cybercrime.

Certego is a member of The Honeynet Project, the international non-profit organization focused on sharing cybersecurity threat knowledge and creating open-source projects. Certego participates annually in workshops as a trainer and in the Google Summer of Code as a mentor.

Certego actively participates in FIRST (Global Forum of Incident Response and Security Teams) activities. In 2024, we presented as speakers at the Fukuoka conference, showcasing the IntelOwl project, and also participated in the OCSC 2024 in Tenerife.