Speculus - Threat intelligence feed outage

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Detects when no Speculus threat intelligence indicators have been received for more than 24 hours. The Speculus indexer refreshes continuously, so a silent day usually means an expired API key, a connector misconfiguration, or a feed-side outage rather than an empty feed.

Attribute Value
Type Analytic Rule
Solution Speculus Threat Intelligence
ID c4f2a8d1-6e39-4c07-b5a2-1d8e3f7c9a25
Severity Informational
Status Available
Kind Scheduled
Tactics Impact
Techniques T1565
Required Connectors SpeculusThreatIntel
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Speculus_Indicators_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Speculus Threat Intelligence