CTIAD · CDPGuard

Two products. One loop.

CDPGuard detects and protects the attached systems. CTIAD is the central threat-intelligence and abuse database: collect, correlate, score, report. They are connected, and they do different work.

Roles

Protection is not the database.

CDPGuard

Detect and protect

CDPGuard filters packets, recognises abuse while it happens and blocks it on the server. That is operational defence.

On the system
CTIAD

Collect and report

CTIAD stores security events and abuse signals, relates them, scores them and makes the result available for protection and for review.

Central database
Out

Intelligence into protection

Scored threat intelligence is there so CDPGuard and operators can act on a case, not on a single unexplained line.

CTIAD → CDPGuard
Back

Events back into the database

What CDPGuard sees — abuse and threat events — is the material CTIAD is built to correlate. Protection observes. The database keeps the record.

CDPGuard → CTIAD

Blacklist

A module inside the database.

The blacklist publishes evaluated indicators. It does not replace CTIAD. A list is one output after collection, correlation and scoring. Public catalogues such as AbuseIPDB are a comparison, not the CTPF data basis and not this design.

  • Own architectureCTIAD and CDPGuard are separate CTPF products. Each keeps its own job.
  • No copied catalogueCTIAD is not a skin on someone else’s abuse site. External lists can be read beside it. They are not the system.
  • Say what is liveThis page describes the roles. It does not claim that every feed or every integration is already in production.

ctiad.com