> ## Documentation Index
> Fetch the complete documentation index at: https://docs.safesquid.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Threat Intelligence Feeds

> Real-time cloud-integrated threat intelligence for web categorization, application identification, SSL security, and malware scanning in SafeSquid SWG.

# Cloud threat intelligence keeps enforcement current

Static blocklists and outdated signatures create blind spots that attackers exploit within hours of a new campaign. SafeSquid's cloud-integrated threat intelligence delivers real-time updates to web categorization, application signatures, SSL security, image analysis, malware scanning, and geo-location databases. Feed refresh timestamps and category versions appear in the SafeSquid interface and logs; audit reports confirm current threat posture.

## Outdated threat data creates exploitable gaps

Threat actors register and rotate domains, change hosting infrastructure, and modify payloads faster than manual updates can track. Enterprises relying on static blocklists or weekly feed refreshes face a window of exposure measured in hours. Compliance frameworks (NIST SP 800-53 SI-5, ISO 27001 A.12.2.1) require timely threat intelligence to maintain control effectiveness.

SafeSquid addresses this with automatic, cloud-backed feed updates that keep enforcement aligned with the latest threat landscape.

## Feeds cover categorization, signatures, and reputation

SafeSquid cloud services deliver real-time updates across eight named intelligence feeds:

| Feed                           | Purpose                                                                      | Used by                                                                              |
| ------------------------------ | ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------ |
| **Threat Intelligence**        | Known malicious servers and exploit-serving destinations                     | [Access Restriction](/Access_Restriction), [DNS\_Security](/DNS_Security)            |
| **URL Classification**         | URL and domain classification into categories                                | [Web Categorization](/Web_Categorization), [Access Restriction](/Access_Restriction) |
| **Application Identification** | Application and SaaS recognition by traffic characteristics                  | [Architecture](/safesquid_swg/architecture/safesquid_swg)                            |
| **Image Analysis AI**          | Visual-content and image-based risk classification                           | [Image\_Analyser\_AI](/Image_Analyser_AI)                                            |
| **Content Fingerprints**       | MiMe and content-nature detection for data classification                    | [True-Mime\_Fingerprints](/True-Mime_Fingerprints)                                   |
| **Malware Signatures**         | Malware signature and heuristic updates                                      | [Malware\_Scanners](/Malware_Scanners)                                               |
| **Geo-Location**               | Geographic location of web-server hosts                                      | [GeoIP](/GeoIP)                                                                      |
| **SSL Updates**                | Trusted Root CA, algorithm, and fingerprint updates for SSL trust evaluation | [SSL\_Inspection](/SSL_Inspection)                                                   |

Feed delivery and refresh schedules are managed by the SafeSquid cloud service. SafeSquid instances pull updates automatically when connected to the cloud. Custom categorization overrides (managed via the [Self-Service Portal](/Self-Service_Portal)) merge with cloud feeds on each refresh.

Internal product knowledge describes the feed-consumption mechanism as **Zero Threat Window**, where updated intelligence is injected directly into the processing pipeline so policy decisions use current data without waiting for a slower manual refresh cycle.

## Prerequisites

* **SafeSquid activation**: A valid product activation key from [key.safesquid.com](https://key.safesquid.com). The activation key links the instance to the cloud feed service.
* **Internet connectivity**: SafeSquid must reach the SafeSquid cloud endpoints for feed updates. Restricted environments should explicitly allowlist the required update and categorisation endpoints.
* **Subscription**: Some feed categories (e.g. DLP signatures, advanced application signatures) require a premium subscription. Check the [Self-Service Portal](/Self-Service_Portal) for active subscriptions.

## Verification and evidence

* **Interface Checks**: In the [Configuration Portal](/Configuration_Portal), check the Support page for feed version numbers and last-update timestamps. Web Categorization, Application Signatures, and malware databases each show their current version.
* **Log Analysis**: SafeSquid logs feed update events including success, failure, and version changes. Search logs for feed-related entries to confirm refresh frequency.
* **Custom Categorization**: Verify custom categories created in the Self-Service Portal appear in SafeSquid's categorization engine after the next feed sync. Test by browsing a custom-categorized URL and checking the access log for the expected category.

## Troubleshooting

**Symptom:** Categorization or application detection becomes stale.\
**Likely cause:** Feed update path is blocked or the instance is not correctly linked to the cloud service.\
**Isolation:** Check update timestamps, feed-related logs, and activation status.\
**Remediation:** Restore connectivity to the required endpoints and confirm licensing state.\
**Retest:** Wait for refresh and verify the version updates.

**Symptom:** Custom categorization never appears on the proxy.\
**Likely cause:** The portal-side change is not linked to the active deployment context or sync path.\
**Isolation:** Compare the activation key and portal configuration with the running instance.\
**Remediation:** Correct the activation and synchronization state.\
**Retest:** Reapply the custom category and confirm it appears after sync.

## Next steps

* [Web Categorization](/Web_Categorization) to configure category-based policies.
* [DNS Security](/DNS_Security) for DNSBL, GeoIP, and homograph detection.
* [Malware Scanners](/Malware_Scanners) for ClamAV, ICAP, and SqScan configuration.
* [Self-Service Portal](/Self-Service_Portal) to manage custom categorization and subscriptions.


## Related topics

- [Threat Intelligence Feeds](/safesquid_swg/application_ecosystem/threat_intelligence_feeds.md)
- [Self-Service Portal](/safesquid_swg/interface/self_service_portal.md)
- [Application Ecosystem](/safesquid_swg/application_ecosystem/main.md)
- [Licensing Requirements](/deployment/licensing_requirements.md)
- [Manage Subscription State](/deployment/manage_subscription_state.md)
