All Posts
ThreatStream
1
min read

New in ThreatStream: Certego Threat Intelligence Feeds

Published on
March 13, 2025
Table of Contents

Certego’s threat intelligence modules are the latest addition to ThreatStream’s massive repository of relevant IoCs and IoAs. ThreatStream offers four distinct feeds from Certego: malware, phishing, sinkhole, and hash detection.

Founded in 2013 and headquartered in Modena, Italy, Certego’s team has extensive experience in security intelligence, incident response, and malware analysis. In addition to Certego’s threat intelligence offerings, the company provides Managed Detection and Response (MDR) services and a Unified Security Operations platform, PanOptikon®.

Activating Certego Intelligence in ThreatStream

As a premium feed, activating Certego’s data feeds in ThreatStream requires a subscription to Certego’s threat intelligence modules. Setting up these feeds in ThreatStream is quick and easy: users simply activate the Certego Data Feeds tile within the ThreatStream APP store and provide their Certego Token.

Four feeds from Certego with actionable, tactical intelligence are now available in ThreatStream:

  1. Malware: Provides domain records and IP addresses associated with malware
  2. Phishing: Provides domain records and IP addresses associated with phishing attacks
  3. Sinkhole: Tracks malicious sites used in DNS sinkhole redirection
  4. Hash: Allows security analysts to quickly identify malicious files by comparing MD5 hash values
A screenshot of Certego data feeds in the ThreatStream APP Store
A screenshot of Certego data feeds in the ThreatStream APP Store

Get Started with Certego and ThreatStream

Visit the Certego website to learn more about its threat intelligence modules, or schedule a demo with Anomali to see how ThreatStream provides access to the industry's largest curated global repository of threat intelligence, including new premium intelligence feeds from Certego.

FEATURED RESOURCES

July 10, 2026
CISOs

CTEM Is Not Another Security Program—It's How Modern CISOs Turn Exposure Into Action

Read More
July 24, 2026
Anomali Cyber Watch

Iranian Cyber Retaliation Is No Longer Theoretical — It's Happening Now

Read More
December 24, 2025
Anomali Cyber Watch

Anomali Cyber Watch: Sample

LockBit 5.0 Ransomware Targets Windows, Linux, and VMware ESXi in Active Campaigns. Google Patches Actively Exploited Chrome Zero-Day CVE-2026-2441. Infostealer Targets OpenClaw Configuration Files to Capture Credentials and User Context. And more...
Read More
Explore All