Threat intelligence EU-developed

IntelFusions

Public threat-intelligence research platform linking adversary profiles, malware, incident claims, detection-rule references and contextual briefings for analyst investigation.

By IntelFusions · Romania

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
IntelFusions
Recorded country
Romania
Product model
Free service
Deployment
Public service
Software license
Website terms; third-party datasets retain separate licenses
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

IntelFusions is a Romanian threat-intelligence research platform. Its About page identifies Antonio Radu as the founder who built it. The country was confirmed directly by the index owner on 10 October 2026.

Reported capabilities

  • Threat actor and malware profiles linked to an intelligence graph
  • Detection-rule references with ATT&CK mappings and original-source links
  • Intelligence briefings and country views for research

Scope and limits

The terms describe an informational research resource, exclude alerting or monitoring services, and promise no SLA. Incident claims require independent verification. No public open-source software license or self-hosted release was verified. Public access does not permit substantial database reuse.

Inspect the research evidence 7 source observations
  1. identity / origin / capabilities

    The rendered About page identifies IntelFusions as a cyber threat analysis platform, names Antonio Radu as founder and builder, and describes briefings, adversary tracking, AI security coverage, country views and a threat graph.

    Read source
  2. capabilities / deployment / maintenance

    The public homepage was accessible without an account and linked briefings, threat actors, malware, rules and country views. It displayed published briefings dated 5 October 2026 and actor entries added 8 October 2026, establishing observed publication activity, not an uptime or support guarantee.

    Read source
  3. capabilities / deployment

    The public Rules page provides search and severity controls and describes Sigma/Splunk rule metadata with source links and ATT&CK mappings. It distinguishes mirrored metadata from IntelFusions Original rules published in full. No claim is made here that the platform executes detections.

    Read source
  4. license / deployment

    Terms last updated 24 August 2026 describe an independently operated free informational research service, with no SLA and no available accounts. Reading, searching, citing and linking are allowed; substantial reuse and certain scraping require permission. Third-party datasets keep their own licenses.

    Read source
  5. identity

    The privacy policy names IntelFusions as data controller and supplies its contact email.

    Read source
  6. identity

    The official Contact page supplies contact channels for IntelFusions.

    Read source
  7. country

    The CSIRTS.eu project owner directly confirmed on 10 October 2026 that IntelFusions is from Romania. This country attribution comes from that confirmation, separately from the public-page review.

    Project owner confirmation

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.

A threat intelligence workflow for CSIRTs