VORANT. Threat Intelligence Sign in Get the full feed

abuse.ch launches unified Hunting Platform

low threat technology

abuse.ch introduced a new Hunting Platform that unifies search across its threat intel feeds and adds new hunting features to URLhaus, YARAify and ThreatFox.

abuse.ch, a long-running community-driven threat intelligence provider, announced a new Hunting Platform that consolidates data from its seven existing platforms into a single searchable interface. The release allows analysts to query previously non-public datasets and introduces a consolidated False Positive List, accessible via web and API, to improve data transparency.

Alongside the new platform, abuse.ch rolled out several feature updates: URLhaus now supports payload overviews, on-demand URL rescans, and hunting alerts; YARAify gained auto-delete options for submitted files, rescan capability, and API-based YARA rule deployment; and ThreatFox added ASN enrichment for network-based IOCs. MalwareBazaar also introduced automatic parsing of malicious Bash scripts to extract payload delivery URLs.

This is a platform and tooling announcement rather than a threat report - it describes infrastructure improvements intended to help the security community aggregate and hunt for indicators more efficiently, with no specific new threat, vulnerability, or campaign disclosed.

Mentioned in this report

Malware Mirai

Source reporting: https://abuse.ch/blog/introducing-abuse-ch-hunting-platform

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free