Public-safe threat intelligence
Investigate published threat activity without exposing customer tests.
Public CTI is the open intelligence surface for approved IP indicators, observation trends, classifications, and source context. It is deliberately separated from private tenant operations and controlled validation.
The promise
Provide useful, explainable IP intelligence with clear observation windows and provenance-safe publication boundaries.
Designed for
Customers, analysts, operators, and community users investigating a public IP or activity pattern.
What it delivers
A focused surface with a specific job.
IP reputation lookup
Search a public IP and review its classifications, observation history, and current public status.
Activity summaries
Review public-safe trends, service targets, event density, countries, and behavior categories.
Explainable evidence
See why an indicator is represented without exposing tenant identities, protected assets, or raw private logs.
Publication controls
Apply provenance, confidence, freshness, suppression, and privacy rules before an indicator becomes public.
How the work flows
From intent to verifiable result.
- 01
Search an indicator
Look up a public IP or enter through a public trend and classification view.
- 02
Review context
Inspect behavior, targets, observation windows, confidence, and supporting public-safe evidence.
- 03
Use with judgment
Treat reputation as decision support rather than an automatic claim about every user behind an IP.
- 04
Verify freshness
Check when and how the indicator was observed before using it in a defensive decision.
Trust boundary
What this surface does not blur.
Private tenant evidence, customer identities, protected targets, and raw customer logs do not appear in Public CTI.
ProtectTheBox sources, targets, and controlled attack traffic are categorically excluded from publication.
Collector Lab can contribute only qualifying unsolicited hostile observations; synthetic and replay traffic remain excluded.
Explore the system