Threat Intel module

2026 threat intelligence for agent and supply-chain attacks

Shield maintains a curated threat feed sourced from public incident reporting on skills marketplace trojans, MCP abuse, Entra and Intune wipe campaigns, and PyPI supply-chain packages. Each story links IOCs you can hunt against logs and agent artifacts.

Browse threat feed IOC hunter

Context before the scan

Security teams use the feed to brief engineering on why agent guardrails matter this quarter, then run IOC hunts on CI logs and developer laptops when a story matches their stack. The feed is complementary to your SIEM: it is focused on the attack patterns Shield can detect deterministically today.