All Posts
ThreatStream
1
min read

New ThreatStream Feed: Mandiant Digital Threat Monitoring

Published on
June 13, 2025
Table of Contents

The Anomali team is excited to now offer Mandiant Digital Threat Monitoring within the ThreatStream APP store. Digital Threat Monitoring is a threat intelligence feed offered by Mandiant, now part of Google, that monitors open, deep, and dark web sources to detect data leaks, brand abuse, credential exposure, and ransomware threats in near real-time using Mandiant’s threat intelligence and machine learning.

Monitor the Open, Deep, and Dark Web

The Mandiant Digital Threat Monitoring feed offers great visibility into the following threats:

  • Compromised credential exposure — both for internal employee and customer data
  • Malicious targeting or potential attacks based on deep and dark web activity
  • Malicious or accidental insider data leaks

The feed closely monitors locations on the web where credentials or data breaches are traded or sold, such as dark web markets, blogs, forums, paste sites, and more. You can learn more about Mandiant Digital Threat Monitoring in this datasheet.

An example of a potential threat based on dark web form activity
An example of a potential threat based on dark web forum activity.

Enabling Mandiant Digital Threat Monitoring in ThreatStream

By enabling Mandiant Digital Threat Monitoring in Anomali ThreatStream, CTI teams can correlate Mandiant's threat intelligence with other intel sources and distribute this intelligence throughout their organization's security telemetry. Anomali ThreatStream helps to automatically contextualize, deduplicate, and define the severity/confidence of potential threats. ThreatStream users can also share and distribute this intelligence among Trusted Circles.

As a premium feed, accessing this data requires an active subscription with Google for Mandiant Digital Threat Monitoring. To enable the feed in ThreatStream, users can simply:

  1. Access the "Mandiant DTM" tile within the ThreatStream APP Store
  2. Submit the "Client_key" and "Client_ secret" values provided by Mandiant DTM
  3. Click "Activate" and the feed should now be active

Get Started in ThreatStream

Interested in exploring the integration between Mandiant Digital Threat Monitoring and Anomali ThreatStream? If you're not yet a ThreatStream customer, request a demo to see the integration for yourself along with the 200+ other threat intelligence feeds available in the ThreatStream APP Store.

FEATURED RESOURCES

August 11, 2026
Operationalized Threat Intelligence
Agentic SOC

OCSF, Explained: Why a Common Schema Changes How Security Teams Work

How a vendor-neutral schema turns fragmented telemetry into data your analysts, detections, and AI agents can all read.
Read More
August 11, 2026
Anomali Cyber Watch

Anomali Cyber Watch: Your AI Clicked Something, Your Dev Tools Have Worms, and the Hotel Wi-Fi Was Literally a Spy

Midnight Blizzard's CaptiveCrunch Campaign Turns Hotel Wi-Fi Into an Espionage Tool. AI Cyber Testing Incidents Multiply as Frontier Models Reach Real Systems and People. ChainDrop Worm Turns Developer Tools Into a Self-Spreading Supply Chain Threat. N-able N-central Authentication Bypass Under Active Exploitation. DOUBLECUP ClickFix Loader-as-a-Service Delivers CountLoader and DeviceManager RATs. Zero-Click Indirect Prompt Injection Attacks Target AI Agentic Browsers, Enabling Account Takeover and Unauthorized Actions.
Read More
August 4, 2026
Anomali Cyber Watch

Anomali Cyber Watch: TA488 Exploits OWA Cross-Site Scripting, Certighost Domains Hijack, TELESHIM Abuses Telegram, and more

TA488 Exploits OWA Cross-Site Scripting Flaw to Deploy OWAReaper JavaScript Implant, New Certighost PoC Exploit Lets Attackers Hijack Windows Domains, TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments, Chinese-Speaking Threat Actor Deploys Autonomous AI-Driven Attack Campaign, Nested Trust: HollowFrame's Layered Loader and Matryoshka Backdoors, Custom Backdoor Toolkit Targets Central Asian Government Networks in Cyber-Espionage Campaign
Read More
Explore All