Click your stack. See only what matters.
50+ threat-intel feeds. Filter by vendor, severity, exploitation status, region, sector, and a selectable timeframe. Hourly updates. Free, no login.
Group Profiler
Look up APT groups, TTPs, and intel context in seconds.
How this works & data freshness
ThreatFilter pulls fresh advisories hourly from 50+ public sources (CISA KEV, NVD, vendor PSIRTs, regional CERTs, and independent security press). The freshness dot in the header shows how recently a source was fetched.
Vendor / severity / exploitation / sector tagging shown here is currently heuristic — it is derived in your browser by matching each item's title and summary against a 349-vendor alias catalog with word-boundary keyword rules. It is intentionally conservative (no loose substring hits) but it is not a substitute for the dedicated ML classifier; treat tags as a strong hint, and always open the source for ground truth.
Use the filter bar to narrow by vendor, severity, exploitation status, region, and sector. The Timeframe control (24h · 48h · 7d · 30d · 90d · All, default 7 days) sets how far back the feed reaches — picking a longer window fetches deeper history, not just the most recent items. Counts on each tile reflect the loaded window of items, not all-time.
Pick your vendors
optional · narrow the feed to your stack
?
Boolean search syntax
cisco vpn— both words must appear (implicit AND)cisco OR fortinet— either wordcisco AND vpn NOT ios— combine; NOT excludes"zero day"— exact phrase in quotes(rce OR "remote code") AND linux— parenthesised groupscve-2024— plain words still substring-match for back-compat
Case-insensitive. Operators are case-sensitive (must be uppercase).
No items match. Try widening filters or clearing region.
Couldn't reach the feed
The advisory API didn't respond. It's usually a brief hiccup — give it a moment and try again.