What the rest of the world already knows.
BetaA sign-in from a Tor exit, an address other workspaces have already seen attacking them, a CVE that is being exploited right now: each changes how fast a finding or a vulnerability needs attention. TillShield fetches public feeds whose licences allow it, adds what it sees across its own workspaces, and puts both on the findings and the inventory items they concern.
The feeds
TillShield fetches each feed on a schedule, downloads the Tor list and the catalog again only when the publisher says they changed, and never sends anything about your workspace to the publishers. A feed that fails keeps its last data and shows as failing; one that misses 3 updates in a row shows as stale. EPSS scores are fetched only for CVEs in a workspace’s inventory.
| Feed | Used for | Checked every | Licence |
|---|---|---|---|
| Tor exit relays The Tor Project | Names Tor exits on security events, so rules and findings can tell anonymised traffic apart. | 12 hours | CC0 1.0 |
| Known Exploited Vulnerabilities CISA | Marks vulnerabilities that are being exploited in the wild. | 24 hours | CC0 1.0 |
| Exploit Prediction Scoring System FIRST | Scores how likely each CVE in your inventory is to be exploited in the next 30 days. | 24 hours | Free for any use; attribution requested |
Tor exit list from The Tor Project. Known Exploited Vulnerabilities catalog from CISA. EPSS scores from FIRST.org.
Addresses other workspaces flagged
Every hour, TillShield counts the addresses behind TillTell findings across workspaces from the last 30 days. An address is known only once findings at 3 or more workspaces named it, and a finding counts only when:
- its event was observed by a Till server, not reported by an app or browser;
- it is not a drill;
- it came from a library rule, not a workspace’s own rule, and not from a rule that reads this intel;
- its latest verdict is not false positive or benign;
- its workspace contributes (the default).
A finding on such an address says how many other workspaces flagged it, never which, and the ATT&CK techniques their findings mapped to. Marking a finding false positive or benign takes it out of the count at the next hourly pass.
To stop counting your workspace, turn off Contribute to shared threat intelligence under Shield → Settings, or run tilldev shield settings set --no-contribute-intel. Your events are still checked against everyone else’s patterns.
On findings and rules
The check happens as each security event is read, before the rules run, so a rule can match on it. A finding keeps what was known at that moment:
"intel": {
"feeds": ["tor-exits"],
"workspaces": 4,
"techniques": ["T1110.004", "T1078"]
}The fields are intel.feeds, intel.workspaces and intel.techniques, and your own rules can use them, for example intel.workspaces|gte: 3. An event without a match has no intel block. Two rules in the library use it:
| Rule | Level | Fires on | Technique |
|---|---|---|---|
tell-signin-tor-exit | Medium | A successful sign-in from a Tor exit relay | T1090.003 |
tell-signin-flagged-address | High | A successful sign-in from an address at least two other workspaces flagged | T1078 |
Both start in shadow, like every new rule, and follow the TillTell lifecycle. A defense drill can test them: the drill states the intel its event carries, and that is used only when the drill’s signature checks out.
Exploited vulnerabilities
An item in the vulnerability inventory whose reference or alias is a CVE shows whether that CVE is in the Known Exploited Vulnerabilities catalog, when it was listed, the date US federal agencies must fix it by, and whether it is known to be used in ransomware. It also shows the EPSS score: the chance it is exploited in the next 30 days, and how it ranks against every other scored CVE.
The inventory counts open and accepted items that are known exploited, filters to them, and sorts them first, then by EPSS score. An exploited CVE does not change the item’s level or its fix-by date; those stay yours to set.
From the CLI and the API
Shield → Threat intel shows the feeds and their freshness, the findings the intel named in the last 30 days, and the exploited items in the inventory. Owners and admins only.
tilldev shield intel # feeds, findings the intel named, exploited CVEs
tilldev shield vulns --exploited # the inventory, known-exploited first, highest EPSS next
tilldev shield vulns show <id> # KEV listing, ransomware use and the EPSS score
tilldev shield settings set --no-contribute-intelThe API is GET /api/v1/shield/intel; the inventory takes exploited=1 and sort=exploit, and each item carries an intel object. See the API reference.