Skip to content
AppClap
RST Cloud is unclaimed —
R

RST Cloud

Agent-ready CTI — Threat intelligence your agents can trust.·rstcloud.net

Visit

RST Cloud provides threat intelligence delivered as structured, source-backed, machine-readable data for SIEM, SOAR, TIP and AI agents. Its product family includes scored threat feeds, a source-referenced report knowledge base, a threat actor library, noise/false-positive filtering, IoC lookup, breach credential alerts, bot/proxy detection, and an AI-driven CTI assistant accessible over API, MCP or an OpenAI-compatible endpoint. Every indicator carries a published, auditable score built from statistical decay, active verification, and multi-source confidence modelling. It integrates out-of-the-box with common security tools such as firewalls, SIEMs and SOAR platforms.

What it's for

Filtering out noise before it reaches detection systemsScoring indicators with an auditable, multi-dimensional confidence scoreFeeding SIEM/SOAR/firewall/EDR/XDR/WAF systems with actionable indicatorsAnswering plain-language questions about CVE exploitation from parsed threat reportingChecking for leaked/compromised credentials and verifying if passwords still workDetecting residential proxy and browser automation abuseTracking emerging threats by sector, region or actor from parsed reportingResolving threat actor aliases and profiles across vendorsEnriching indicators with Whois, SSL certificate, favicon, HTML fetch and screenshot lookupsProviding source-referenced answers to SOC analysts and AI agents

Features 16

  • Adversary-aware active verification of indicators
  • AI CTI Assistant answering questions with cited sources over MCP or an OpenAI-compatible endpoint
  • Data delivered in STIX, JSON, ndJSON, CSV, TSV, XML and MISP formats
  • Detection of residential proxy and browser automation abuse (Bot Radar)
  • Enrichment APIs: Whois, SSL certificate, favicon, HTML fetch, screenshot lookups
  • Known-good/noise filtering across every indicator type (Noise Control)
  • Leaked credential detection with password-validity verification (Breach Alert)
  • Multi-source confidence scoring with per-source trust weighting
  • Multilingual source collection and translation (English, German, Spanish, French, Russian, Chinese, Japanese, Arabic, Ukrainian and others)
  • Native SIEM/SOAR/firewall integrations for automated blocking or detection
  • Out-of-the-box connectors and cloud-to-cloud integration pipelines
  • Scored threat indicators (Threat Feed) with a three-dimension auditable score: source confidence, context score, time relevance
  • Single-call IP/domain/URL/hash contextualisation (IoC Lookup)
  • Statistical decay modelling per indicator type
  • STIX 2.1 machine-readable parsing of threat reports (Report Hub)
  • Threat actor profiles with vendor aliases resolved (Threat Library)

At a glance

free trialAPI
TypeWeb app
DeploymentCloud
PlatformsWeb
Formid-market security teams, MSSPs, national CERTs, SOC analysts, CTI analysts, threat hunters, detection engineers, CISOs, incident responders
CompanyRST Cloud

Integrations

FortiGatePalo Alto NGFWOpenCTIPalo Alto Cortex XSOARSplunk EnterpriseMicrosoft SentinelElastic SIEMMISPSearchlight CyberIBM QRadarCisco FirepowerSAF SystemsCheck Point NGFWGoogle Threat IntelligenceRecorded FutureCrowdStrikeMicrosoft Defender TI

Resources

Pricing

No plan prices are published. RST Threat Feed offers a self-serve one-month free trial delivered by email. Other products (Report Hub, Threat Library, Noise Control, CTI Assistant, Breach Alert, Bot Radar, Enrichment APIs) require requesting a demo. The vendor states pricing is set for the use case rather than the brand, aimed at mid-market teams, MSSPs and national CERTs.

Last checked 2 days ago·