Skip to main content

Threat Intelligence Feeds

Threat-intelligence feeds keep SafeSquid policy decisions current. Static rules decay quickly against phishing kits, malware delivery domains, remote-access tooling, and newly abused cloud services. The application ecosystem places feed delivery beside the proxy, DNS, reporting, and Self-Service Portal paths. That placement matters: a feed outage can weaken classification and detection even when the proxy service itself is healthy.

Feed categories

SafeSquid ecosystem documentation identifies these intelligence categories:

Operational checks

Verify feed health during deployment and incident response:
  1. Confirm the deployment can reach approved SafeSquid cloud dependencies.
  2. Confirm feed update status in the appropriate operating view or logs.
  3. Test a known category, malware-test, or policy-safe indicator.
  4. Confirm the Reporting Service or SIEM receives the resulting event.

Failure symptoms

Next steps