All Posts
ThreatStream
1
min read

New ThreatStream Feed: Mandiant Digital Threat Monitoring

Published on
June 13, 2025
Table of Contents

The Anomali team is excited to now offer Mandiant Digital Threat Monitoring within the ThreatStream APP store. Digital Threat Monitoring is a threat intelligence feed offered by Mandiant, now part of Google, that monitors open, deep, and dark web sources to detect data leaks, brand abuse, credential exposure, and ransomware threats in near real-time using Mandiant’s threat intelligence and machine learning.

Monitor the Open, Deep, and Dark Web

The Mandiant Digital Threat Monitoring feed offers great visibility into the following threats:

  • Compromised credential exposure — both for internal employee and customer data
  • Malicious targeting or potential attacks based on deep and dark web activity
  • Malicious or accidental insider data leaks

The feed closely monitors locations on the web where credentials or data breaches are traded or sold, such as dark web markets, blogs, forums, paste sites, and more. You can learn more about Mandiant Digital Threat Monitoring in this datasheet.

An example of a potential threat based on dark web form activity
An example of a potential threat based on dark web forum activity.

Enabling Mandiant Digital Threat Monitoring in ThreatStream

By enabling Mandiant Digital Threat Monitoring in Anomali ThreatStream, CTI teams can correlate Mandiant's threat intelligence with other intel sources and distribute this intelligence throughout their organization's security telemetry. Anomali ThreatStream helps to automatically contextualize, deduplicate, and define the severity/confidence of potential threats. ThreatStream users can also share and distribute this intelligence among Trusted Circles.

As a premium feed, accessing this data requires an active subscription with Google for Mandiant Digital Threat Monitoring. To enable the feed in ThreatStream, users can simply:

  1. Access the "Mandiant DTM" tile within the ThreatStream APP Store
  2. Submit the "Client_key" and "Client_ secret" values provided by Mandiant DTM
  3. Click "Activate" and the feed should now be active

Get Started in ThreatStream

Interested in exploring the integration between Mandiant Digital Threat Monitoring and Anomali ThreatStream? If you're not yet a ThreatStream customer, request a demo to see the integration for yourself along with the 200+ other threat intelligence feeds available in the ThreatStream APP Store.

FEATURED RESOURCES

September 9, 2026
No items found.

Shadow AI in the Enterprise: Why Unapproved AI Tool Adoption Is Becoming a Systemic Data Governance Crisis

Most employees already paste company data into AI tools they were never approved to use. See what shadow AI exposes and where DLP and policy fall short.
Read More
September 8, 2026
Anomali Cyber Watch

Privilege Escalation in CrowdStrike. TerminalFix, ClickFix Lure, Steganography, Reverse Tunnel. REVSTEALER Disable Windows Update and Defender.Langflow and Ruby on Rails Vulnerabilities. Microsoft Teams, Spring Ring Intrusion. Chrome Zero-Day.... and more

Researcher Releases FalconFlank Proof-of-Concept Demonstrating Privilege Escalation in CrowdStrike Falcon. TerminalFix Campaign Combines ClickFix Lure, Steganography, and Reverse Tunnel for Network Access. Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner. Critical Langflow and Ruby on Rails Vulnerabilities Under Active Exploitation. Fake Help Desk Calls on Microsoft Teams Fuel the Spring Ring Intrusion Campaign. Chrome Zero-Day Traced to Flawed Array-Sort Optimization in V8.
Read More
September 7, 2026
Agentic SOC

Pourquoi un SOC agentique commence par des données à haute fidélité

Pourquoi un SOC agentique commence par des données à haute fidélité. Les défis liés aux données. Les options pour les résoudre.
Read More
Explore All