Skip to main content

Loading

Threat intelligence, defined

What AI threat intelligence actually means

Threat intelligence, to most security vendors, means a live feed: malicious IP addresses, file hashes, phishing domains, refreshed by the hour. raxIT Labs does not build that. AI systems do not fail the way a network does, so the fastest-moving part of the picture is not an attacker's toolkit. It is the record of what has already gone wrong: an OWASP Top 10 for LLM Applications entry, a CVE filed against an agent framework, a vendor's own system card admitting a failure mode, an incident someone documented in public. That record, not a feed of indicators, is what we mean by AI threat intelligence.

Read more

Each entry in that record starts as a document, a paper, a disclosure, a postmortem. We turn it into a threat pattern: a plain statement of who did it, what they needed, what they did, and what it hit. A pattern links down to the incidents that prove it happened and up to the controls that stop it. That structure, not a timestamp, is what makes the intelligence usable. A file hash expires in a day. A pattern like "an agent given a broad API key uses it for something outside its stated task" stays true for years.

The checks the raxIT App runs against a customer's own agents come from this record directly. When a pattern shows agents being tricked into acting outside their scope, the check looks for the same shape in your logs: an actor field that does not match the on_behalf_of user it claims to serve, a token whose scope no one signed off on, a call your policy never granted but nothing stopped. We call this scope, sign, stop: know what an agent is allowed to do, know who signed off on it doing that, and keep something in the path that can say no. Threat intelligence is the part that tells the check what to look for. Without the record, a check is a guess about what might happen. With it, the check is looking for something that already did.

Below is the record itself, laid out as a map instead of a table. Each incident, pattern, technique and control is a node, and the edges say why it belongs there. Click a technique to see the incidents that prove it, a pattern to see the control built for it, or use the filters to narrow by severity or source. It is public, and it updates as the underlying sources do, because a threat intelligence record that stops updating is just history.