DEFENSIVE THREAT INTELLIGENCE

Threat feeds.
Reasons to act.

Know what matched, why it matters, and what to do next. Castle SecTel is built to turn network threat signals into clear, evidence-backed decisions.

01Source and reason
02Threat connections
03Actionable alerts
CASTLE SECTEL THREAT INTELLIGENCE
Explain the signalMap the activityChoose the responseKeep the context

ABOUT CASTLE SECTEL

Security data should come with its story.

Founded by William Frederick Koester, Castle SecTel delivers threat feeds and defensive intelligence.

It grows from feeds-dl, a Python prototype that collects selected public feeds, normalizes and de-duplicates records, and supports local lookups. The product direction adds the context defenders need to work with those signals: source provenance, clear reasons, freshness, confidence, alerts, and evidence-backed threat relationships.

Product concept in development. Alerting, hosted feeds, and threat mapping are planned capabilities.

Castle SecTel shield and fortress mark

OUR MISSION

Make threat intelligence useful at the moment a decision is made.

We want every signal to answer four questions: What matched? Why is it here? What is it connected to? What is the sensible next step?

Evidence firstKeep the source and reasoning visible.
Context over labelsSeparate network role from malicious intent.
Defender in controlRecommend actions; let customer policy decide.

PRODUCTS & CAPABILITIES

From raw feeds to a clearer picture.

Start with useful indicators. Add the reason, the relationship, and the alert that helps a team respond.

02◉

Alerts with Reasons

See what changed or matched, the source behind it, and the evidence that triggered the alert.

  • New and updated indicators
  • Customer network matches
  • Confidence and action guidance
PLANNED
03⌘

Threat Mapping

Follow supported relationships between indicators, infrastructure, malware, campaigns, and behavior.

  • Evidence on each relationship
  • Campaign and malware context
  • Standards-based exchange
PLANNED
04▥

Metrics & Analytics

Understand feed freshness, indicator volume, changes, matches, and trends across your environment.

  • Activity over time
  • Source and confidence views
  • Network risk reporting
PLANNED
↗

Designed for network workflows. Planned delivery includes downloadable JSON feeds, API access, and interoperable formats such as STIX/TAXII and MISP-compatible exports.

ROADMAP
↓Browse the free feed libraryReview the archived Malicious Top 100 and download TXT or JSON snapshots.Open free feeds

Tor nodes and dual-use tools such as Cobalt Strike are treated as context, not automatic proof of malicious activity. Blocking remains customer-controlled.

THE CASTLE SECTEL APPROACH

Every alert should make the next step clearer.

Good threat intelligence explains uncertainty as well as risk. A single source listing is not the same as a confirmed threat. Castle SecTel is designed to keep that distinction visible.

01
OBSERVEDIndicator or behavior
02
EXPLAINEDSource, evidence, freshness
03
CONNECTEDRelated threat activity
04
DECIDEDBlock · Monitor · Enrich · Investigate

CONTACT US

Help shape what useful threat intelligence looks like.

We’re looking for security teams and service providers who want clearer feed matches, reasons, and threat relationships.

✳Design partners · Product feedback · Integration conversations

Submitting opens your email app with this message addressed to wikoeste@castle-sectel.com. Review and send it there.