Curate in one place
Search, organize, and bulk-upload IPs, domains, hashes, and categories. Activate the intelligence you want to distribute.
BUILT FOR SECURITY SERVICE PROVIDERS
Bring your intelligence together. Build feeds for every customer. Put the right protection in the right place.
One workspace. Every customer. Intelligence in action.
FROM INTELLIGENCE TO ENFORCEMENT
CloudHawk connects the intelligence you trust to the environments you protect. Bring curation, customer segmentation, feed delivery, and reporting into one operational workflow.
THE PLATFORM
Everything your team needs to turn disconnected threat lists into a repeatable security service.
Search, organize, and bulk-upload IPs, domains, hashes, and categories. Activate the intelligence you want to distribute.
Combine shared intelligence, customer mappings, and named custom lists to fit each customer’s environment.
Ingest plain-text feeds, STIX 2.1 bundles, and TAXII 2.1 collections, with source credentials where needed.
Generate consumable text lists and feed URLs for downstream security controls. Track feed retrieval activity.
Explore threat categories and geographies. Create customer PDF reports with indicator summaries and analyst notes.
Manage access with separate roles, MFA, and optional Microsoft Entra ID sign-on. Follow changes through audit history.
HOW IT WORKS
A clear path from the sources your analysts trust to the feeds your customers need.
Bring intelligence in
Add analyst-curated indicators and connect external threat sources in a shared workspace.
CloudHawkOne shared workspace
Shape it for each customer
Map customer-specific indicators and assemble custom lists from selected sources.
Publish. Track. Report.
Deliver feed URLs, review retrieval activity, and communicate coverage through customer reports.
CUSTOMER INTELLIGENCE REPORT
Shared intelligence and customer-specific indicators, brought together in one coverage summary.
VISIBILITY WITHOUT THE GUESSWORK
Give analysts the detail they need and customers a clearer view of the service you deliver. Filter by customer and date range, explore coverage, and build a report that tells the story.
BUILT AROUND YOUR OPERATIONS
FOR MSSPs
Curate shared intelligence once, then tailor delivery across your customer base with client mappings and custom feeds.
FOR MSPs
Bring feed sources, customers, and device inventory together in a practical workflow for your service team.
FOR SECURITY TEAMS
Move curated indicators into usable feeds, retain an activity trail, and give leadership a clear account of coverage.
LET’S TALK ABOUT YOUR ENVIRONMENT
Explore how CloudHawk fits your sources, customer structure, and delivery requirements. We’ll walk through the platform and discuss the right setup for your team.
Have a specific use case? Bring it to the conversation.
GOOD QUESTIONS. CLEAR ANSWERS.
CloudHawk manages and delivers threat intelligence. It brings together curated and external indicators, segments them by customer, publishes consumable feeds, and makes coverage visible through dashboards and reports.
CloudHawk manages IP addresses and CIDR blocks, domains, file hashes, and threat categories. External intake supports plain-text sources, STIX 2.1 bundles, and TAXII 2.1 collections. Sources can use basic authentication or API keys where required.
Yes. You can combine global intelligence with customer-specific IPs, domains, and categories, and create named customer lists from selected external sources. Available list types depend on the source and feed configuration.
CloudHawk publishes consumable text lists and feed URLs for compatible downstream controls to retrieve. It also provides JWT-protected API operations for core indicator workflows. Compatibility with your particular security tools can be discussed during a demo.
CloudHawk is the operational layer between threat intelligence and enforcement. Its focus is curation, segmentation, delivery, and reporting. It does not replace your detection, monitoring, or incident response tools.
Yes. Generate customer PDF reports for the prior month, all time, or a selected date range. Reports can summarize indicators, protected devices, threat geographies, categories, and analyst notes.
Request a demo to discuss your customer base, intelligence sources, and operational requirements. Pricing is not published on this site; the conversation will help establish the setup and commercial details for your team.
PUT YOUR INTELLIGENCE TO WORK
See what a connected threat-feed workflow could look like for your team.