Threat Intel module
2026 threat intelligence for agent and supply-chain attacks
Shield maintains a curated threat feed sourced from public incident reporting on skills marketplace trojans, MCP abuse, Entra and Intune wipe campaigns, and PyPI supply-chain packages. Each story links IOCs you can hunt against logs and agent artifacts.
GET /v1/threat-feedreturns active stories with severity, tags, and linked IOC identifiers.POST /v1/ioc-huntmatches pasted logs, shell history, or configs against the IOC database.- Agent Guard and IOC hunt share the same IOC corpus for consistent verdicts.
- Updated as major 2026 campaigns are disclosed; no signup required.
Context before the scan
Security teams use the feed to brief engineering on why agent guardrails matter this quarter, then run IOC hunts on CI logs and developer laptops when a story matches their stack. The feed is complementary to your SIEM: it is focused on the attack patterns Shield can detect deterministically today.