TILLSHIELD · THREAT INTEL

What the rest of the world already knows.

Beta

A sign-in from a Tor exit, an address other workspaces have already seen attacking them, a CVE that is being exploited right now: each changes how fast a finding or a vulnerability needs attention. TillShield fetches public feeds whose licences allow it, adds what it sees across its own workspaces, and puts both on the findings and the inventory items they concern.

01Feeds

The feeds

TillShield fetches each feed on a schedule, downloads the Tor list and the catalog again only when the publisher says they changed, and never sends anything about your workspace to the publishers. A feed that fails keeps its last data and shows as failing; one that misses 3 updates in a row shows as stale. EPSS scores are fetched only for CVEs in a workspace’s inventory.

FeedUsed forChecked everyLicence
Tor exit relays
The Tor Project
Names Tor exits on security events, so rules and findings can tell anonymised traffic apart.12 hoursCC0 1.0
Known Exploited Vulnerabilities
CISA
Marks vulnerabilities that are being exploited in the wild.24 hoursCC0 1.0
Exploit Prediction Scoring System
FIRST
Scores how likely each CVE in your inventory is to be exploited in the next 30 days.24 hoursFree for any use; attribution requested

Tor exit list from The Tor Project. Known Exploited Vulnerabilities catalog from CISA. EPSS scores from FIRST.org.

Only feeds we may use
A feed ships only once its licence allows use in a paid product. Several well-known blocklists are free for personal or non-commercial use only, so they are not here.
02Patterns

Addresses other workspaces flagged

Every hour, TillShield counts the addresses behind TillTell findings across workspaces from the last 30 days. An address is known only once findings at 3 or more workspaces named it, and a finding counts only when:

  • its event was observed by a Till server, not reported by an app or browser;
  • it is not a drill;
  • it came from a library rule, not a workspace’s own rule, and not from a rule that reads this intel;
  • its latest verdict is not false positive or benign;
  • its workspace contributes (the default).

A finding on such an address says how many other workspaces flagged it, never which, and the ATT&CK techniques their findings mapped to. Marking a finding false positive or benign takes it out of the count at the next hourly pass.

To stop counting your workspace, turn off Contribute to shared threat intelligence under Shield → Settings, or run tilldev shield settings set --no-contribute-intel. Your events are still checked against everyone else’s patterns.

03Findings

On findings and rules

The check happens as each security event is read, before the rules run, so a rule can match on it. A finding keeps what was known at that moment:

json
"intel": {
  "feeds": ["tor-exits"],
  "workspaces": 4,
  "techniques": ["T1110.004", "T1078"]
}

The fields are intel.feeds, intel.workspaces and intel.techniques, and your own rules can use them, for example intel.workspaces|gte: 3. An event without a match has no intel block. Two rules in the library use it:

RuleLevelFires onTechnique
tell-signin-tor-exitMediumA successful sign-in from a Tor exit relayT1090.003
tell-signin-flagged-addressHighA successful sign-in from an address at least two other workspaces flaggedT1078

Both start in shadow, like every new rule, and follow the TillTell lifecycle. A defense drill can test them: the drill states the intel its event carries, and that is used only when the drill’s signature checks out.

Never a block on its own
Many people share one address behind mobile carriers, offices and VPNs. Intel raises findings and their urgency; blocking stays with your rules and playbooks.
04Inventory

Exploited vulnerabilities

An item in the vulnerability inventory whose reference or alias is a CVE shows whether that CVE is in the Known Exploited Vulnerabilities catalog, when it was listed, the date US federal agencies must fix it by, and whether it is known to be used in ransomware. It also shows the EPSS score: the chance it is exploited in the next 30 days, and how it ranks against every other scored CVE.

The inventory counts open and accepted items that are known exploited, filters to them, and sorts them first, then by EPSS score. An exploited CVE does not change the item’s level or its fix-by date; those stay yours to set.

05CLI and API

From the CLI and the API

Shield → Threat intel shows the feeds and their freshness, the findings the intel named in the last 30 days, and the exploited items in the inventory. Owners and admins only.

sh
tilldev shield intel                      # feeds, findings the intel named, exploited CVEs
tilldev shield vulns --exploited          # the inventory, known-exploited first, highest EPSS next
tilldev shield vulns show <id>            # KEV listing, ransomware use and the EPSS score
tilldev shield settings set --no-contribute-intel

The API is GET /api/v1/shield/intel; the inventory takes exploited=1 and sort=exploit, and each item carries an intel object. See the API reference.