Threat Feeds Tab View

Prev Next

A domain such as example.com triggers a callback or phishing alert to your SIEM. Is it a fleeting hit, or is it chronically listed across feeds, signaling ongoing threats? Manual feed checks across sources fragment your hunt.

The Threat Feeds tab in Total View displays a clear timeline of when a domain or IP appeared in Silent Push threat intelligence feeds — either historically or currently. It highlights IOFA (Indicators of Future Attack) exposures via flags such as “Part of IOFA Feed,” which aggregates sources to identify risk patterns including phishing and malware.

Available for Domains and IPv4, this view pulls from Silent Push’s feed integrations and complements WHOIS (for ownership ties) and PADNS (for resolution context).

What’s New in the Refreshed Threat Feeds Tab

The Threat Feeds experience has been fully refreshed to improve readability and usability:

  • Improved historical timeline with better colors, adaptive scaling, and clearer legends

  • Enhanced overall layout and smarter default ordering

  • Direct PDF export so you can quickly share insights with stakeholders

Why It Matters

Threat feeds expose malicious timelines, but disjointed views often obscure persistence. The Threat Feeds tab tracks first-seen and last-seen dates along with listing spans, revealing behaviors such as brief IOFA listings for emerging campaigns. The IOFA Feed flag surfaces proactive risks and prompts deeper investigation.

Teams can assess activity duration (for example, 10 days on FIN7-related feeds) and correlate it with Infrastructure Variance for infrastructure shifts, or use the historical view for actor attribution — essential for SOC triage and defender monitoring.

How It Works

Silent Push’s aggregation engine compiles feed data in-house, creating gap-free timelines from third-party sources. Core fields (First Seen, Last Seen, and Listed Span) populate with “ago” calculations. The graph visualizes trends, and hovering reveals feed-specific details (for example, “TrafficAI Generated Websites Domains”).

The Feeds Historical View provides a detailed log of entries, including IOFA ties. It links seamlessly to other Total View tabs — a recent listing here might align with PADNS anomalies or signal potential takeovers.

Generating Results

  1. Enter a domain (for example, grandssofa.site) in the search bar and open Total View.

  2. Click the Threat Feeds tab.

  3. The timeline and summary fields load automatically.

  4. Expand the Historical View for detailed entries.

  5. Filter by date or feed name as needed.

  6. Toggle Domain Wide View when you want to include subdomains.

Example

Querying grandssofa.site in Threat Feeds might show:

  • First Seen: 2025-09-29 (9 days ago)

  • Last Seen: 2025-10-08 (0 days ago)

  • Listed Span: 10 days

  • “Part of IOFA Feed” flag highlighting exposure

The Historical View lists entries such as “Threat Actor – FIN7 Domains” (first seen 2025-09-29, last seen 2025-10-07), with a trend graph. Hovering a line reveals feed details, including descriptions of the actor’s typical targeting.

Key Fields

Field

Description

First Seen

The initial date the observable was detected on a threat feed (e.g., 2025-08-03).

First Seen Ago

Time elapsed since the first detection (e.g., 30 days ago).

Last Seen

The most recent date the observable was detected on a feed (e.g., 2025-09-01).

Last Seen Ago

Time elapsed since the last detection (e.g., 1 day ago).

Listed Span

The total duration the observable has been listed across feeds.

Feeds Historical View

The Historical View provides a detailed log of specific feed entries and listing dates. For benign domains such as example.com, this section may appear empty.

It includes:

  • Feed names (e.g., TrafficAI Generated Websites Domains)

  • First-seen and last-seen dates for each entry

  • IOFA indicators

Hover over lines on the timeline graph to see expanded information: feed source, description, and update timestamps.

Working with Results

From the Threat Feeds tab, you can:

  • Copy individual fields

  • Customize visible columns (for example, add descriptions)

  • Download results as CSV for reporting

  • Export directly to PDF for easy sharing with stakeholders

  • Save the observable to a Feed or Draft Feed to monitor future listings and IOFA spikes

Tips

  • Start with a known suspicious domain to populate First Seen, Last Seen, and Listed Span fields.

  • Use the Feeds Historical View to examine feed-specific activity over time.

  • Always correlate findings with PADNS and Infrastructure Variance for a more complete picture.

  • Take advantage of the new PDF export when preparing reports or briefings.

The refreshed Threat Feeds tab turns fragmented intelligence into a clear, actionable timeline — helping you move from alert to understanding faster.