OFFICIAL PARTNER · CYBER BOOST

KELA

Cyber Threat Intelligence

KELA automates cyber threat intelligence. It monitors the dark web and closed sources, finds leaked credentials, and tracks threat actors and threats to your organization. It shows the real risks first.

Threat IntelligenceDark WebCredential LeaksAttack Surface
KEY FACTS
2009
year founded (Israel)
Dark/Deep
coverage of cybercrime sources
Automated
intelligence gathering
Actionable
prioritization of real risks
Threat intelligence from the cybercrime underground
KELA logo
Cyber Threat Intelligence
CTIDark Web
CATEGORY
SecOps · Threat Intel
CTI · Dark Web
DELIVERY MODEL
SaaS
Cloud platform
PARTNERSHIP
CYBER BOOST
Official partner in Uzbekistan
PRODUCTS AND MODULES

What the platform includes.

KELA automatically collects, analyzes and prioritizes threat intelligence from closed sources.

Monitor
Threat Monitoring
Constantly monitors the dark web, forums and Telegram channels for mentions of your organization.
Identity
Compromised Credentials
Finds leaked employee and customer credentials in dumps and botnet logs.
Actors
Threat Actor Intelligence
Profiles attackers and ransomware groups and tracks their activity.
Attack Surface
External Attack Surface
Finds your external assets and their weak points, as an attacker sees them.
TPR
Third-Party Risk
Assesses the cyber risks of suppliers and partners using data from the cybercrime underground.
Brand
Brand & Fraud Protection
Finds phishing, fake domains and threats to your brand on closed platforms.
Investigate
Threat Investigations
Investigation tools: search by indicators, relationships and historical data.
Feeds
Intelligence Feeds
Machine-readable indicator feeds for integration into SIEM/SOAR and enrichment.
Alerts
Targeted Alerts
Alerts only about threats relevant to your organization.
CAPABILITIES

Key capabilities.

Coverage of the underground

Access to closed forums, marketplaces and Telegram channels used by cybercriminals.

Credential leaks

Early detection of compromised logins from botnet logs and dumps.

Threat Actor Intel

Profiles of attackers and ransomware groups, their TTPs and activity.

Risk prioritization

Only threats relevant to your organization, without the noise.

External Attack Surface

A map of external assets and weak points from a potential attacker’s point of view.

Automation

Automated collection and analysis replace manual monitoring of thousands of sources.

Integrations and feeds

Indicators sent to SIEM/SOAR through an API and machine-readable feeds.

Targeted alerts

Real-time alerts about new threats, with the context you need to respond.

USE CASES

Who uses KELA and how.

Leak protection

Early detection of compromised accounts before they are used.

Banks and finance

Tracking threats, phishing and the sale of access to financial systems.

Public sector

Monitoring threats to critical infrastructure and data leaks from government systems.

SOC enrichment

Feeding external threat intelligence into SIEM/SOAR to prioritize alerts.

Supplier risk

Assessing the cyber risks of partners and contractors using data from the underground.

Brand protection

Detecting fake domains, phishing and the sale of fakes on closed platforms.

2009
year founded (Israel)
Dark/Deep
coverage of cybercrime sources
Automated
intelligence gathering
Actionable
prioritization of real risks
INTEGRATIONS

What KELA works with.

SIEM AND SOAR
SplunkMicrosoft SentinelIBM QRadarCortex XSOAR
EXCHANGE FORMATS
STIX / TAXIIMISPREST API
ITSM AND NOTIFICATIONS
ServiceNowJiraSlack
ENRICHMENT
VirusTotalWebhooks
COMPARING MODULES

Which option to choose.

CapabilityMonitorIdentityAttack Surface
Dark web monitoring✓Logs-
Credential leaksPartial✓-
External asset discovery--✓
Threat actor intelligence✓ContextContext
Feeds for SIEM/SOAR✓✓✓
Delivery modelSaaSSaaSSaaS

The module set depends on your threat intelligence needs. Ask CYBER BOOST for the exact configuration.

FAQ

Frequently asked questions

What is cyber threat intelligence?
CTI means collecting and analyzing threat data from outside sources (the dark web, forums, leaks). It warns you early about attacks being prepared against your organization, leaked data and attacker activity.
How is KELA different from a SIEM?
A SIEM analyzes internal events in your infrastructure. KELA works with external sources: the cybercrime underground, leaks and attacker activity. KELA sends indicators to the SIEM to enrich and prioritize its alerts.
Does any software need to be installed?
No. KELA is a cloud SaaS platform. It monitors and analyzes external threats without installing agents on your systems.
Who deploys KELA in Uzbekistan?
CYBER BOOST, the official partner, supplies KELA, sets up the monitoring profile, connects it to your SOC and gives technical support in Russian and Uzbek.
REQUEST

Request a KELA demo

We reply within one business day.