The **Threat Intelligence Framework** automatically downloads, parses, and consumes threat feeds (IPs, domains, hashes) from external providers (e.g., STIX/TAXII, malicious domains lists).
These indicators are stored in Splunk lookups and KV stores. ES automatically cross-references every network, web, and endpoint event against these lists.