What is Aethelgate?
Aethelgate is a live, open-source threat intelligence dashboard. It pulls data from trusted public feeds and shows what is happening in the threat landscape right now — no account, no setup.
How it works
- Collect — open feeds are fetched on a schedule (CISA KEV, RansomLook, ThreatFox, URLhaus, XposedOrNot, RSS security news).
- Normalize — events are deduplicated and merged into a single threat feed with common fields: type, severity, date, source.
- Visualize — the dashboard shows KPIs, charts and tables so you can spot spikes and priorities at a glance.
- Investigate — click any KPI, chart segment or row to see details. Use the global search for CVE, CWE, vendor, product or tool.
Data sources
- CISA KEV ↗ — vulnerabilities confirmed as actively exploited, with the action CISA recommends.
- RansomLook ↗ — ransomware groups and their victim disclosures.
- ThreatFox ↗ — indicators of compromise (IOCs) shared by the community.
- URLhaus ↗ — malicious URLs used for malware distribution.
- XposedOrNot ↗ — data breach intelligence and exposed credentials.
- CIRCL ↗ — CVE/CWE references from the Luxembourg incident response center.
- RSS feeds — curated security news and threat intelligence headlines.
Quick FAQ
Is this tool for me?
Anyone who wants a quick, no-cost view of the threat landscape: SOC analysts, incident responders, students, or curious defenders.
Does it store my data?
No. Aethelgate is read-only: it fetches public feeds and renders them in your browser. Nothing is submitted to us.
Is it real-time?
Feeds are refreshed on a regular schedule (minutes to hours, depending on the source). It is not a SIEM; treat it as an awareness and triage layer.