abuse.ch launches unified Hunting Platform
abuse.ch introduced a new Hunting Platform that unifies search across its threat intel feeds and adds new hunting features to URLhaus, YARAify and ThreatFox.
abuse.ch, a long-running community-driven threat intelligence provider, announced a new Hunting Platform that consolidates data from its seven existing platforms into a single searchable interface. The release allows analysts to query previously non-public datasets and introduces a consolidated False Positive List, accessible via web and API, to improve data transparency.
Alongside the new platform, abuse.ch rolled out several feature updates: URLhaus now supports payload overviews, on-demand URL rescans, and hunting alerts; YARAify gained auto-delete options for submitted files, rescan capability, and API-based YARA rule deployment; and ThreatFox added ASN enrichment for network-based IOCs. MalwareBazaar also introduced automatic parsing of malicious Bash scripts to extract payload delivery URLs.
This is a platform and tooling announcement rather than a threat report - it describes infrastructure improvements intended to help the security community aggregate and hunt for indicators more efficiently, with no specific new threat, vulnerability, or campaign disclosed.
Mentioned in this report
Source reporting: https://abuse.ch/blog/introducing-abuse-ch-hunting-platform
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free