Threat Feeds
Normalized phishing, malware, C2, and network reputation indicators with source, timestamps, context, and expiry.
- Phishing URLs and domains
- Malware and C2 infrastructure
- Tor and network-role context
DEFENSIVE THREAT INTELLIGENCE
Know what matched, why it matters, and what to do next. Castle SecTel is built to turn network threat signals into clear, evidence-backed decisions.
ABOUT CASTLE SECTEL
Founded by William Frederick Koester, Castle SecTel delivers threat feeds and defensive intelligence.
It grows from feeds-dl, a Python prototype that collects selected public feeds, normalizes and de-duplicates records, and supports local lookups. The product direction adds the context defenders need to work with those signals: source provenance, clear reasons, freshness, confidence, alerts, and evidence-backed threat relationships.
Product concept in development. Alerting, hosted feeds, and threat mapping are planned capabilities.
OUR MISSION
We want every signal to answer four questions: What matched? Why is it here? What is it connected to? What is the sensible next step?
PRODUCTS & CAPABILITIES
Start with useful indicators. Add the reason, the relationship, and the alert that helps a team respond.
Normalized phishing, malware, C2, and network reputation indicators with source, timestamps, context, and expiry.
See what changed or matched, the source behind it, and the evidence that triggered the alert.
Follow supported relationships between indicators, infrastructure, malware, campaigns, and behavior.
Understand feed freshness, indicator volume, changes, matches, and trends across your environment.
Designed for network workflows. Planned delivery includes downloadable JSON feeds, API access, and interoperable formats such as STIX/TAXII and MISP-compatible exports.
ROADMAPTor nodes and dual-use tools such as Cobalt Strike are treated as context, not automatic proof of malicious activity. Blocking remains customer-controlled.
THE CASTLE SECTEL APPROACH
Good threat intelligence explains uncertainty as well as risk. A single source listing is not the same as a confirmed threat. Castle SecTel is designed to keep that distinction visible.
CONTACT US
We’re looking for security teams and service providers who want clearer feed matches, reasons, and threat relationships.