NORSESTAR
Product · RuneFeed Intelligence

Curated threat intel,
machine-ready.

RuneFeed is the NorseStar threat-intelligence database — every indicator our sensor grid attributes, scored and enriched, delivered as STIX/TAXII, a REST API, or native connectors for your SIEM and SOAR. The same data that trains Valkyrie AI, in your stack.

61M+indicators under management
190Knew IOCs / day
STIX/TAXII+ REST & webhooks
< 90ssensor-to-feed latency
The database

One scored record per indicator

Every indicator RuneFeed publishes carries the same enrichment: the actor and malware family it belongs to, a confidence score, a severity, and a first-seen timestamp. Analysts query it directly; machines pull it through the API; Valkyrie AI trains on it nightly.

Scored IOCs

Confidence 0–100 with first-seen and last-seen on every record.

Attributed

Adversary-infrastructure and malware-family tagging on every indicator.

Six types

IPv4, domain, URL, SHA-256, MD5, and email indicators.

Delivered

Push to Splunk, Sentinel, Elastic, and webhook sinks.

Sample feed · live export

What a RuneFeed record looks like

TypeIndicatorActorMalware familyConf.Severity
ipv4203.0.113.47FROST-KRAKENRagnarok85high
domaincdn-updates.frosthollow.exampleFROST-KRAKENRagnarok78high
ipv4198.51.100.22NIGHT-RAVENDraugr72medium
sha256a3f1c9e4b7d20516…FROST-KRAKENRagnarok90critical
emailpayments@odin-invoices.exampleFJORD-SPIDER—70high
md51a2b3c4d5e6f7a8b…—Fenrir60medium

Representative records — all indicators shown are fictional.

Tracked adversaries

Named actors, mapped infrastructure

RuneFeed clusters indicators into the adversaries behind them. Three of the campaigns our intelligence team tracks most closely:

FROST-KRAKEN

Ragnarok malware · high severity

A payload-staging and C2 operator behind the Ragnarok family. Tracked across staging domains, C2 panels, and first-stage droppers; our highest-confidence cluster.

NIGHT-RAVEN

Draugr malware · medium severity

A reconnaissance and credential-phishing actor distributing the Draugr loader. Noted for valhalla-themed SSO phishing landings and scanning infrastructure.

FJORD-SPIDER

BEC & exfiltration · high severity

A financially-motivated actor running business-email-compromise and data-exfiltration campaigns. Tracked by sender infrastructure and exfil endpoints rather than a named family.

Delivery

However your stack consumes intel

Community

Public sample feed

$0Rate-limited, 24h delayed
  • Daily high-confidence IOC export
  • STIX 2.1 bundle download
  • Attribution tags included

Enterprise

Private intelligence

CustomOrg-wide
  • Sector-scoped and private collections
  • Yggdrasil graph exports bundled
  • Dedicated intelligence liaison
Inside the platform

RuneFeed trains Valkyrie

RuneFeed is not just an export. It is the ground-truth label store the rest of DarkWatch learns from — every analyst-confirmed indicator becomes a training example.

Each night, confirmed RuneFeed indicators are promoted into the labeled corpus that retrains Valkyrie AI's classifiers from the NorseStar model registry. A new indicator an analyst confirms today shapes how Valkyrie scores tomorrow's traffic.

Release notes

RuneFeed changelog

Currently shipping RuneFeed 5.2. Highlights from recent releases.

5.2September 2026

AI-attack signatures

  • New indicator class for LLM- and agent-generated attack infrastructure
  • Confidence model recalibrated against Valkyrie v4 verdicts
  • TAXII 2.1 collections split by sector
5.1April 2026

Native SOAR connectors

  • Webhook push with retry and dead-letter handling
  • Splunk ES and Microsoft Sentinel native connectors
  • First-seen and last-seen on every record
5.0November 2025

Attribution tagging

  • Actor and malware-family tags on every indicator
  • STIX 2.1 migration
  • Confidence scoring (0–100) replaces the old three-tier model
The DarkWatch suite

RuneFeed is one layer

The feed is the data. These products collect it, read it, and connect it.

DarkWatch Live

The global attack map

Renders every attack the sensor grid sees, in real time, with AI-attack fingerprinting — the screen on the SOC wall.

Explore DarkWatch Live ▸

Bifrost Sensor Network

Global collection grid

Passive sensors, honeypots, and dark-IP listeners that capture the raw attack traffic RuneFeed enriches.

Explore Bifrost ▸

Valkyrie AI

Analyst copilot & triage

Reads the firehose for you — clustering campaigns and flagging machine-generated attacks, trained on RuneFeed labels.

Explore Valkyrie AI ▸

Yggdrasil Graph

Attribution & infrastructure graph

Connects every RuneFeed indicator — domains, certs, ASNs, wallets, operators — into the whole adversary tree.

Explore Yggdrasil ▸
Put RuneFeed in your pipeline

Request API access

A sandbox key, the STIX/TAXII docs, and a sample sector-scoped collection — enough to wire RuneFeed into your SIEM this afternoon.

Request API access ▸