언어 선택

AhnLab TIP

State-of-the-Art
Threat Intelligence Platform

AhnLab TIP is the brain behind our security platforms, helping users make informed decisions with our actionable and high-fidelity threat intelligence.

Why AhnLab TIP

The Best Way to Achieve
Intelligence-Driven Security

Actionable TI

A generic threat information curated and analyzed in AhnLab TIP becomes the actionable cyber threat intelligence that drives an accelerated response. It allows users to effectively address unidentified and imminent cyber threats in a timely manner.

01

Fueling Strategic Planning

AhnLab TIP delivers different types of threat intelligence – including groundbreaking research, threat actor profiling, dark web leaks, and more – to predict upcoming cyber threats and prevent them from materializing. This empowers organizations to make inteldriven security decisions at the boardlevel and implement priority-driven budgeting.

02

Customer-Specific Intelligence

AhnLab TIP performs an ongoing monitoring of - media coverage, social media, open and closed sources, and more – to help customers learn about security issues related to their organizations at any given moment. The platform notifies users upon identifying relevant issues so they can respond in minutes.

03

Key Features

Spanning IOC Lookup, Sandbox Analysis,
Dark Web Monitoring and Threat Research

IT-OT Unified
Threat Intelligence

AhnLab TIP integrates with AhnLab ICM, the central manager of CPS protection, and realizes intelligence-driven CPS protection. Customers can check indicators of compromise (IoCs) across cyber-physical systems in real-time on the ICM dashboard.

Threat Lookup

Users can search for various threat information spanning - IOCs, threat types, threat actors, behavioral information, and more – to fuel a unified view of cyber threats and intel-driven security decisions. The feature effectively bridges the gap between cyber threats and actual detection & response by granting a greater situational awareness.

Cloud Sandbox Analysis

AhnLab TIP runs malware on a virtual environment for its dynamic cloud sandbox analysis. Then, it sifts through the malware by performing a memory dump and behavior analysis to understand the risk it can pose to the organization.

Threat Actor Profiling

Our researchers never stop investigating global adversaries. AhnLab TIP continuously delivers relevant data, threat intelligence feed, and content to empower users to better understand different threat actors and confidently design security strategies.

Closed Source Analytics

AhnLab TIP performs around-the-clock monitoring of closed sources such as underground forums, deep web, and dark web to aggregate real-time data and unlock threat intelligence for customers. This helps them understand what is happening underneath the surface web and how it can specifically affect their businesses.

News Clipping

By providing global security current events and links to threat actors’ blogs or websites, AhnLab TIP drives users to defend against social engineering attacks and execute a swift response to asset-born cyber threats.

Dashboard

Intuitive Threat Intelligence in Consolidated View

2407314180416679.png

AhnLab TIP's centralized dashboard outlines extensive threat intelligence spanning IOCs, threat detection trends, cloud sandbox analysis, research, and news clipping. Furthermore, it graphically visualizes the latest trend of malware attacks, industrial impact, threat vectors, and techniques for easier understanding.

Users can also learn about further details of our research reports, cloud sandbox analysis, threat indicators, and dark web monitoring on the left sidebar.

From the dashboard, you can check:

  • IOC detection status: File, URL, IP, etc.
  • Cloud sandbox analysis status: File, URL, etc.
  • Analysis reports: Security advisory, threat actor trend, etc.
  • Statistical graphs: Malware detection, industrial impact, etc.

Industry Recognition

2509027920570787.png

Recognized as CPS Security Leader
in Frost Radar™ 2025

“With systematic threat management process and deep asset visibility, AhnLab CPS PLUS delivers cutting-edge security for cyber-physical systems. Organizations can benefit from AhnLab’s proactive threat identification, highly accurate detection, and prioritized response with a platform-powered experience.”

2509027919934702.png

Together We Make CPS Environments More Secure

As a member of OT-ISAC, we work hand-in-hand with its expert analysts, sharing attack tactics, threat intelligence, and best practices to fortify defenses against evolving cyber threats. Our unified CPS protection platform, powered by abundant expertise, references, and experience, contributes to keeping a global CPS community more secure.

FAQs

Frequently Asked Questions

AhnLab TIP is a cloud-based threat intelligence platform that aggregates threat data from different sources and converts them to actionable threat intelligence by performing a multi-layered analysis. AhnLab TIP relentlessly garners information on attackers and malicious campaigns at a global scale and always ensures our users stay context-aware. The user-friendly platform also offers tailored and industry-specific threat intelligence to help users better understand the primary issue within the industry and its level of impact.
There is a clear difference among threat intelligence that receives attention from board-level, SOC managers and incident response experts. AhnLab TIP fuels the establishment of enterprise-grade security strategies with its comprehensive yet specific threat intelligence.

1) Strategic threat intelligence: The threat intelligence in line with the needs of executives responsible for predicting future threats and making security decisions
2) Admin-level threat intelligence: The threat intelligence provided to senior administrators to respond to imminent threats.
3) Technical intelligence: The threat intelligence for security staff who should understand the attack stories and take response actions.
AhnLab TIP gleans millions of threat information from different sources, encompassing - our sensors across various security domains, research by our threat intelligence unit called ASEC, partners, deep and dark webs, and more. Then, the platform matches aggregated threat data with millions of IOCs and generates actionable and up-to-date threat intelligence.
The “Threat Lookup Service” is a web service that updates threat intelligence in real-time; the service can be requested via the AhnLab TIP portal. It empowers users to drill down into digital evidence and obtain the intelligence necessary to swiftly detect and respond to threats.

Users can utilize the service via web-based interface search or RESTful API.
You can look up the following items:
• MD5, SHA1, or SHA256
• URL or domain
• IP address
• Vulnerability information
• Attacker information
• Various Tags (CVE Code, Threat Actors, Threat ID, Software names, etc.)

Searched items are categorized into “Normal”, “Malicious”, “Dangerous” and ‘Unknown” while the platform delivers appropriate situational data to accelerate intelligence-driven decisions.
AhnLab TIP offers APIs for the IOC lookup feature and usage of mass-distributed malicious IOCs. By doing so, the platform enables customers to reinforce existing security tools and workflows, deploy a new TI-powered solution, or integrate threat intelligence into the system.

The APIs are provided to users who are paid subscribers of AhnLab TIP.
• Threat Lookup API
• TI Data Feed API