IOC lookup context + Feed explorer
Search gets more context on each lookup, plus a new ad-hoc query tool:
- Corroboration signal - IOC lookup records now show whether an indicator came from a single report or multiple accounts, with a tooltip that popularity is not a verdict.
- Also in these tweets - lookup records surface up to 5 other IOCs pulled from the same source tweets (via the new optional
relatedfield on/v1/ioc), each with a one-click pivot back into the lookup. - Feed explorer - a new card on /search/ queries
/v1/<window>with type, tag and user filters, a date range, CSV export and shareable deep-links. - Report a false positive - every lookup record now links straight to the feedback board.
- OpenAPI - the spec now documents
/v1/ioc,/v1/trendsand the TAXII discovery endpoint. - Per-type and per-user RSS - subscribe to a single IOC type (/rss/type/) or a single reporter (/rss/user/) without polling the firehose.
- External corroboration - IOC lookups now show when an indicator is also listed in URLhaus or ThreatFox (public abuse.ch feeds), refreshed every 6 hours.
- IP network context - IP lookups now show organisation/ASN and country from ipinfo.io (third-party sidecar, refreshed every 6 hours).