ZeroFox Threat Intelligence
This ZeroFox integration with ThreatConnect allows ThreatConnect users to import threat intelligence data along with all of their context from the ZeroFox platform into ThreatConnect.
The ZeroFox ThreatIntel integration is a Threat Intelligence Feed that can be enabled as a standalone job or using ThreatConnect’s Feed Deployer, which adds the feed to your current list of Intelligence sources.
The ZeroFox ThreatIntel app can leverage multiple threat intelligence endpoints to ingest data into the ThreatConnect platform, depending on the user’s access and scope within the ZeroFox ThreatIntel API.
Available endpoints include:
- Botnet
- Disruption
- Exploits
- Vulnerabilities
- C2 Domains
- Phishing
- Malware
- Ransomware
- Compromised Credentials

