Open Threat Exchange

Open Threat Exchange (OTX) is an open platform for sharing information about cyber threats. It is operated by the security company AlienVault (now part of AT&T Cybersecurity) and is used to quickly and collaboratively share insights about attacks, vulnerabilities, malware and attackers.

 

What exactly is OTX?

OTX is a threat intelligence network where security experts, companies and research institutions compile data on current threats. This information is published in so-called pulses – structured posts that contain IP addresses, domains, hash values or attacker tactics, for example.

OTX is based on the principle of collective defence: when one company detects a new threat, others can benefit by taking protective measures at an early stage.

 

Why do you need OTX?

  • To detect and assess new threats
  • For early warnings about ongoing or imminent attacks
  • To enrich security solutions (e.g. firewalls, SIEMs, endpoint protection) with up-to-date indicators
  • For exchange with the security community