KELA
Cyber Threat Intelligence
KELA automates cyber threat intelligence. It monitors the dark web and closed sources, finds leaked credentials, and tracks threat actors and threats to your organization. It shows the real risks first.
What the platform includes.
KELA automatically collects, analyzes and prioritizes threat intelligence from closed sources.
Key capabilities.
Coverage of the underground
Access to closed forums, marketplaces and Telegram channels used by cybercriminals.
Credential leaks
Early detection of compromised logins from botnet logs and dumps.
Threat Actor Intel
Profiles of attackers and ransomware groups, their TTPs and activity.
Risk prioritization
Only threats relevant to your organization, without the noise.
External Attack Surface
A map of external assets and weak points from a potential attacker’s point of view.
Automation
Automated collection and analysis replace manual monitoring of thousands of sources.
Integrations and feeds
Indicators sent to SIEM/SOAR through an API and machine-readable feeds.
Targeted alerts
Real-time alerts about new threats, with the context you need to respond.
Who uses KELA and how.
Leak protection
Early detection of compromised accounts before they are used.
Banks and finance
Tracking threats, phishing and the sale of access to financial systems.
Public sector
Monitoring threats to critical infrastructure and data leaks from government systems.
SOC enrichment
Feeding external threat intelligence into SIEM/SOAR to prioritize alerts.
Supplier risk
Assessing the cyber risks of partners and contractors using data from the underground.
Brand protection
Detecting fake domains, phishing and the sale of fakes on closed platforms.
What KELA works with.
Which option to choose.
| Capability | Monitor | Identity | Attack Surface |
|---|---|---|---|
| Dark web monitoring | ✓ | Logs | - |
| Credential leaks | Partial | ✓ | - |
| External asset discovery | - | - | ✓ |
| Threat actor intelligence | ✓ | Context | Context |
| Feeds for SIEM/SOAR | ✓ | ✓ | ✓ |
| Delivery model | SaaS | SaaS | SaaS |
The module set depends on your threat intelligence needs. Ask CYBER BOOST for the exact configuration.
Frequently asked questions
What is cyber threat intelligence?
How is KELA different from a SIEM?
Does any software need to be installed?
Who deploys KELA in Uzbekistan?
Vendors in SecOps · SIEM · SOAR.
Request a KELA demo
We reply within one business day.

