BUILT FOR SECURITY SERVICE PROVIDERS

Threat intelligence, turned into protection.

Bring your intelligence together. Build feeds for every customer. Put the right protection in the right place.

One workspace. Every customer. Intelligence in action.

One intelligence source. Customer-specific protection.
Customer-specific feeds STIX 2.1 & TAXII 2.1 Clear customer reporting

FROM INTELLIGENCE TO ENFORCEMENT

A shared source of intelligence.
A tailored feed for every customer.

CloudHawk connects the intelligence you trust to the environments you protect. Bring curation, customer segmentation, feed delivery, and reporting into one operational workflow.

  • IP addresses
  • Domains
  • File hashes
  • Threat categories

THE PLATFORM

Less feed management.
More intelligence at work.

Everything your team needs to turn disconnected threat lists into a repeatable security service.

Curate in one place

Search, organize, and bulk-upload IPs, domains, hashes, and categories. Activate the intelligence you want to distribute.

Make every feed customer-specific

Combine shared intelligence, customer mappings, and named custom lists to fit each customer’s environment.

Bring your sources together

Ingest plain-text feeds, STIX 2.1 bundles, and TAXII 2.1 collections, with source credentials where needed.

Publish protection-ready lists

Generate consumable text lists and feed URLs for downstream security controls. Track feed retrieval activity.

Make coverage visible

Explore threat categories and geographies. Create customer PDF reports with indicator summaries and analyst notes.

Keep operations accountable

Manage access with separate roles, MFA, and optional Microsoft Entra ID sign-on. Follow changes through audit history.

HOW IT WORKS

From scattered indicators
to a service you can scale.

A clear path from the sources your analysts trust to the feeds your customers need.

  1. Intelligence sources

    • Curated indicatorsIPs, domains & file hashes
    • External threat feedsPlain text & STIX 2.1
    • TAXII collectionsTAXII 2.1 sources

    Bring intelligence in

    Add analyst-curated indicators and connect external threat sources in a shared workspace.

  2. Curate & tailor

    CloudHawk

    One shared workspace

    • Curate intelligence
    • Map to customers
    • Build tailored lists
    Ready to publish

    Shape it for each customer

    Map customer-specific indicators and assemble custom lists from selected sources.

  3. Customer feeds

    • Customer AIP & domain feed
    • Customer BThreat category feed
    • Customer CCustom source list

    Publish. Track. Report.

    Deliver feed URLs, review retrieval activity, and communicate coverage through customer reports.

Illustrative workflow · Feed contents are tailored to each customer.
CloudHawkINTELLIGENCE BRIEF / 01

CUSTOMER INTELLIGENCE REPORT

A clearer picture.
A stronger service.

4,280Indicators in scope
24Protected devices

01 Intelligence by category

Malware1,860
Command & control1,320
Phishing820
Other280

02 Analyst perspective

Shared intelligence and customer-specific indicators, brought together in one coverage summary.

PREPARED FOR NORTHSTARCloudHawk / 1
Illustrative customer report · Sample data

VISIBILITY WITHOUT THE GUESSWORK

See the intelligence.
Show the value.

Give analysts the detail they need and customers a clearer view of the service you deliver. Filter by customer and date range, explore coverage, and build a report that tells the story.

  • Global and customer-specific indicator summaries
  • Threat categories and geographic context
  • Device coverage and customer PDF reports
Request a Demo

BUILT AROUND YOUR OPERATIONS

One platform.
A stronger security service.

FOR MSSPs

Scale the service, not the busywork.

Curate shared intelligence once, then tailor delivery across your customer base with client mappings and custom feeds.

FOR MSPs

Put intelligence within reach.

Bring feed sources, customers, and device inventory together in a practical workflow for your service team.

FOR SECURITY TEAMS

Close the loop on your intelligence.

Move curated indicators into usable feeds, retain an activity trail, and give leadership a clear account of coverage.

LET’S TALK ABOUT YOUR ENVIRONMENT

Your customers. Your workflow.
A walkthrough built around you.

Explore how CloudHawk fits your sources, customer structure, and delivery requirements. We’ll walk through the platform and discuss the right setup for your team.

A closer look at CloudHawk

  • Walk through the platform
  • Explore your feed workflow
  • Discuss your requirements
Request a Demo

Have a specific use case? Bring it to the conversation.

GOOD QUESTIONS. CLEAR ANSWERS.

A little more intelligence.

What does CloudHawk do?

CloudHawk manages and delivers threat intelligence. It brings together curated and external indicators, segments them by customer, publishes consumable feeds, and makes coverage visible through dashboards and reports.

Which indicator types and source formats are supported?

CloudHawk manages IP addresses and CIDR blocks, domains, file hashes, and threat categories. External intake supports plain-text sources, STIX 2.1 bundles, and TAXII 2.1 collections. Sources can use basic authentication or API keys where required.

Can each customer receive a different feed?

Yes. You can combine global intelligence with customer-specific IPs, domains, and categories, and create named customer lists from selected external sources. Available list types depend on the source and feed configuration.

How do feeds reach our security tools?

CloudHawk publishes consumable text lists and feed URLs for compatible downstream controls to retrieve. It also provides JWT-protected API operations for core indicator workflows. Compatibility with your particular security tools can be discussed during a demo.

Is CloudHawk a threat detection or incident response tool?

CloudHawk is the operational layer between threat intelligence and enforcement. Its focus is curation, segmentation, delivery, and reporting. It does not replace your detection, monitoring, or incident response tools.

Can we produce reports for individual customers?

Yes. Generate customer PDF reports for the prior month, all time, or a selected date range. Reports can summarize indicators, protected devices, threat geographies, categories, and analyst notes.

How do we get started, and what does it cost?

Request a demo to discuss your customer base, intelligence sources, and operational requirements. Pricing is not published on this site; the conversation will help establish the setup and commercial details for your team.

PUT YOUR INTELLIGENCE TO WORK

Curate once.
Protect every customer.

See what a connected threat-feed workflow could look like for your team.

Request a Demo