ThreatConnect’s CAL™
Collective Analytics Layer
Enhance Intelligence through Global Context

Enhance Intelligence through Global Context
The ThreatConnect® Platform already helps you identify threats with your own data. Now, with our CAL™ (Collective Analytics Layer), ThreatConnect provides an anonymous way to learn how many times potential threats were identified across all participating platform instances.
By distilling billions of data points, this innovative feature offers immediate insight into how widespread and relevant the threat is, providing global context that has never before been available.
Not only can CAL give you answers about intelligence you care about, CAL Feeds can tell you what’s worth asking about. The initial four feeds (with plans to add more) help you to develop more actionable insights. With CAL Feeds, the immense dataset and analytics already found within CAL are paired with the tradecraft of our Research Team to identify pockets of intelligence that are fertile hunting grounds for teams of all sizes and maturity levels.
CAL provides anonymized, crowdsourced intel about your threats and indicators. It leverages the collective insight of the thousands of analysts who use ThreatConnect around the globe to provide you with even more context regarding your indicators and threats. The more you know about a threat and the sooner you know it, the better equipped you are to fight it.
CAL intelligence can be found on the Details page and Browse Screen flyout for Indicators in the ThreatConnect Platform.
Right now! CAL is currently active in the ThreatConnect Platform.
Absolutely not. CAL does not attribute indicator data to a particular ThreatConnect customer instance or user. All resulting data is reported in the form of global counts and has been de-identified so that the ThreatConnect customer or user source remains anonymous. No matter what deployment you choose, your data is completely secure.
Yes, unless someone has opted out of CAL. However, you will not know where the data comes from due to the anonymity of the data.
You could, but we’re not sure you want to. If you opt out, you will not be able to see CAL’s valuable data. But, dedicated cloud or on-premises users have the option to opt-out of allowing their data to be used in CAL if they would like. Cloud users are automatically part of CAL.
ThreatAssess and CAL are both made possible by ThreatConnect’s powerful analytics in the platform. ThreatAssess is a score derived just from your data where CAL is the result of global data across the ThreatConnect community of users and partners.