// tool reference · Monitoring & Detection
Threat Live Free
A live, streaming feed of current threat indicators.
What it does
A continuously refreshed feed of what is actually being exploited right now, aggregated from authoritative sources rather than social media.
When to use it
- Morning triage — deciding what deserves attention today.
What you get back
A ranked feed: KEV additions, new CVEs, advisories and vendor reporting.
Worked example
Input
(no input -- the feed refreshes on a schedule)
Output (abridged)
CISA KEV -- added today
CVE-2026-XXXX RCE, internet-facing appliance
KEV means EXPLOITED IN THE WILD, not theoretical.
The federal remediation deadline is a good proxy for
your own urgency.
NVD -- new criticals
CVE-2026-YYYY CVSS 9.8, no patch yet. Mitigation guidance only.
Read order: KEV first, always. A KEV entry at CVSS 7 outranks a
non-exploited CVSS 9.8 every time.
How it works
Cron-refreshed and cached. Sources: CISA KEV, NVD, CISA advisories, SANS ISC, and reputable vendor reporting. If every source is unreachable the page falls back to a deterministic baseline rather than breaking.
Limits
Read live from the platform configuration.
| Rate limit | 30 requests / 60s (platform default) |
Limitations — what it does not do
Aggregation, not intelligence tailored to you. It does not know your asset inventory, so it cannot say which entries you are actually exposed to. Pair it with Vulnerability Triage.
Privacy
No input. Nothing to store.
Standards
CISA KEVNVD / CVE