Indicator intake
Decide whether the workflow starts from domains, IPs, ASNs, emails, phone numbers, usernames, crypto addresses, or document metadata.
Threat intelligence
SpiderFoot connects with many threat intelligence and reputation sources. This planner keeps enrichment scoped, repeatable, and reviewable.
Decide whether the workflow starts from domains, IPs, ASNs, emails, phone numbers, usernames, crypto addresses, or document metadata.
Select blacklist, breach, reputation, passive DNS, certificate, leak, social, dark-web, and malware intelligence sources based on the target.
Separate raw collection from confirmed findings, confidence scores, false-positive handling, and escalation evidence.
Strong relevance
These terms match the product theme and landing task. They remain keyword candidates until same-request MiroFish Trends evidence is collected.
Prepare threat intelligence enrichment and indicator review workflows.
Theme relevance: SpiderFoot integrates with threat feeds and blacklist/enrichment modules.
pending_mirofish_value
Combine indicators, enrichment, blacklist checks, breach sources, and analyst review.
Theme relevance: Directly maps to the threat intelligence workflow page.
pending_mirofish_value