Skip to main content
The Threat Intelligence tab in Case Management has two jobs: it lets you look up any indicator of compromise on demand, and it manages the feeders that bring your own indicators into Myrmex. Both feed the same picture of what’s dangerous in your environment.

Look Up an Indicator

Paste an indicator to get a verdict and the context behind it. The lookup accepts the common IOC types:
  • IP addresses
  • Domains
  • File hashes
  • URLs
Each lookup is kept in a history so you can revisit earlier checks without running them again. Results are backed by Orion, Myrmex’s threat-intelligence specialist, drawing on sources such as Google Threat Intelligence and VirusTotal.
For a deeper, multi-step investigation — attribution, infrastructure mapping, breach exposure — ask Orion directly in chat rather than a one-off lookup.

Bring Your Own Indicators: Threat Feeders

Threat Feeders pull indicators you already trust into Myrmex on a schedule. You can create a feeder from three source types:

CSV

Load indicators from a structured CSV source.

Text

Ingest a plain-text list of indicators.

MISP

Connect a MISP threat-sharing instance.
Once a feeder exists, you manage it from this tab:
1

Create

Add a feeder and point it at your CSV, text, or MISP source.
2

Activate

Turn the feeder on so Myrmex starts collecting from it.
3

Run & schedule

Run a feeder on demand, or set it to refresh on a schedule so new indicators arrive automatically.
The indicators a feeder collects surface here in Threat Intelligence, where they enrich your lookups and the SOC investigations you launch from Alerts.

Orion

The threat-intelligence specialist behind lookups and enrichment.

Alerts

Where feeder indicators and lookups meet your live detections.