Threat Intel Feed (Configuration)
Path: /admin/threat-intel · Sidebar: Administration → Threat Intel Feed
The admin counterpart to the Threat Intel page: configure the live intelligence sources that enrich your vulnerabilities.
Sources
- CISA KEV - Known Exploited Vulnerabilities.
- EPSS - exploitation-probability scores.
- NVD / GHSA / OSV - CVE advisory data.
What you configure
- Enable/disable each source and set its refresh cadence.
- Review last-sync status and any sync errors.
- Control egress - in air-gapped deployments, disable outbound feeds and rely on the bundled data (see also the SCA OSV feed).
Why it matters
Fresh feeds are what make KEV/EPSS-driven prioritisation and KEV-match notifications accurate. Stale feeds mean you might miss that a CVE you have was just added to KEV.
Match cadence to risk tolerance
A daily KEV/EPSS refresh is a sensible default. Increase frequency if you operate high-risk, internet-facing systems where hours matter.