SCIAT Threat Intelligence

Indicators, adversary profiles and regional context from our own research and investigations — delivered as feeds your tools can consume and briefings your people can use.

Researcher analysing malware samples
Detection & Intelligence

Regional adversary intelligence you can act on.

Available for
FeedsPortalAPI

What SCIAT Threat Intelligence
Actually Does

Most threat intelligence sold in this region is written somewhere else about someone else’s problems. SCIAT Threat Intelligence is grounded in what we actually see: the ransomware families hitting Kenyan networks, the mobile-money fraud patterns, the phishing infrastructure targeting local banks, and the malware our forensics lab pulls apart. It arrives as machine-readable feeds for your tooling and as written analysis for the people who have to make decisions.

Everything Included
in SCIAT Threat Intelligence

Regional Focus

Intelligence drawn from incidents and research across East and Southern Africa, not translated from another market.

Machine-Readable Feeds

Indicators delivered in STIX/TAXII and common formats, ready to drop into your SIEM, firewall or EDR.

Adversary Profiles

Who is active, what they target, how they get in, and what they do once inside — with the detection opportunities at each stage.

Malware Analysis Reports

Technical breakdowns of samples we have reversed, including capability, infrastructure and detection guidance.

Analyst Portal

Search indicators, pivot across related infrastructure, and pull the context behind a detection your tools just fired.

Executive Briefings

Periodic written briefings on the regional threat picture, aimed at people who make budget and risk decisions.

The Detail
You Asked For

Delivery
STIX/TAXII feeds, REST API, analyst portal
Coverage
East and Southern Africa, with global context
Update frequency
Continuous for indicators; monthly for written analysis
Integration
SIEM, EDR/XDR, firewall and gateway platforms
Licensing
Per-organisation, by seat band

Before You
Decide

Our own incident response and forensic investigations, our malware analysis work, infrastructure we track, and partnerships with regional and global sources. Where something is sourced externally, we say so.
Yes. Feeds are delivered in standard formats, and our team handles integration into your platform as part of onboarding.