Platform · Context that lands on your own surface

Threat intelligence

Campaign and indicator context is matched against your inventory, so intelligence arrives as "this affects these four assets" rather than a feed nobody reads.

5

campaigns currently matching the demo tenant's surface

Capabilities

What threat intelligence actually does

01

Surface matching

Indicators are resolved against your own assets before they are shown. Unmatched intelligence stays in the library.

02

Campaign profiles

Actor type, targeting pattern, observed techniques and how those techniques interact with your live paths.

03

Look-alike watch

Certificate transparency and registration monitoring for names that imitate your own.

04

Activity timeline

A single chronological record of intelligence, discovery and posture changes.

In the console

See it working on demo data

  • Indicators are matched against your own inventory before they are shown to anyone.
  • Campaign profiles state actor type, targeting pattern and which of your live paths the techniques touch.
  • Look-alike watch monitors certificate transparency and registrations for names imitating your own.
LodemarkDemo tenantNorthfleet Group · 4 cloud accounts · 11 regions · 3 subsidiariesHead of Security OperationsSigned in as Asha Rehman
Threat intelligence5 campaigns matched against this tenant’s own surface
Campaigns
CMP-311

Quiet Ledger

Invoice fraud crew that harvests supplier document portals, then re-issues payment instructions from look-alike domains.

Actor type
Financially motivated
Targets
Freight and customs brokerage
First observed
2026-06-11
Surface matches
3
Portal enumerationLook-alike domainBusiness email compromise
Indicators resolved against the tenant inventory before they are shown.
IndicatorTypeCampaignConfidenceMatched asset
northfleet-invoices[.]codomainQuiet Ledgerhighsupplier-docs.northfleet.io
nfg-supplier-portal[.]netdomainQuiet Ledgerhighsupplier-docs.northfleet.io
CN=fleet-ops-eu, O=UnverifiedcertificateQuiet Ledgermediumlegacy-edi.northfleet.io

Activity timeline

Intelligence, discovery and posture changes in one record.

08:41 UTCLook-alike domain registered

northfleet-invoices[.]co resolved for the first time. Certificate transparency match on the supplier portal name.

07:58 UTCNew edge asset discovered

supplier-docs.northfleet.io began answering on a second origin pool in eu-west-2.

06:12 UTCPath AP-01 re-scored

Blast radius widened after the analytics role gained read on a fourth prefix.

YesterdayChoke point applied on AP-05

Enforcement point deployed between the campus range and the depot gateway.

YesterdayFND-8749 verified remediated

Deploy identity subject claim narrowed to 13 active repositories.

Questions

About threat intelligence

Everything else is in the documentation.

Yes. STIX/TAXII feeds and custom indicator lists are supported, and they go through the same surface-matching step as our own intelligence.

Next step

Put threat intelligence against your own estate

A four-week proof of value connects one cloud account, your DNS and your identity provider, and ends with a written readout. Lodemark stays read-only throughout.

Book a walkthroughOpen the console demo

Illustrative product data. Nothing on this site performs a live scan.