ThreatStreamThe Olympus engine · Discover & test

Know if a threat is
live right now.

A live feed of threat indicators, built into the platform. Look at any IP, domain, hash, or other field and ThreatStream tells you what threats it's associated with — and which co-occurring indicators, if you also see them, mean those threats are live in your environment right now.

185.220.101.44Malicious · TI matchlive now
This IP is associated with Cobalt Strike C2. ThreatStream flags the co-occurring indicators seen in your lake that confirm it's active:
Beacon interval to known C2 domain
JA3 hash matches the toolkit
2 internal hosts talking to it
What it does

From indicator to confirmed threat.

🛰

Feed

A live threat stream — IPs, domains, hashes, URLs, and more.

🔍

Look up

See the threats any field is associated with, instantly.

Confirm

Co-occurring indicators prove a threat is live in your lake.

Live threat feed

An indicator is only half the story.

ThreatStream runs continuously against the full NKW. The moment a malicious indicator and its co-occurring signals appear together in your environment, you know the threat is live — not theoretical.

  • Live threat feed — IPs, domains, hashes, URLs, & more
  • Instantly see the threats any field is associated with
  • Correlates co-occurring indicators to confirm a live threat
  • Runs against the full NKW — alarms the moment a match appears
Indicator match
LIVE
threat feedYour lake
Indicator + live signals = confirmed threat
MATCHES · LIVEhits
live
Confirmed
real-time
Alarm
✓ active threat
How it works

Match, correlate, confirm.

Ingest

Threat-indicator feeds load into the platform.

Match

Every field is checked against the live threat feed.

Correlate

Co-occurring indicators are linked together.

Alarm

A confirmed live threat fires the moment it appears.

Works with the engine

Works across the engine.

Know the Unknown

See live threats the moment they appear.

See how ThreatStream confirms active threats against your own data — in real time.