> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Threat Feed 3.0 Changelog
- URL: https://darkwebinformer.com/threat-feed-3-0-changelog/
- Published: 2026-06-12T16:30:48.000Z
- Updated: 2026-07-12T22:52:57.000Z
- Author: Dark Web Informer

<!doctype html> 

dwi@threat-feed:\~/release 

$ **diff** \--semantic feed@2.0 feed@3.0 --out changelog

# Threat Feed 3.0

A large, additive release. The front-end roughly tripled with no removed user-facing features, and the realtime backend never moved.

v2.0→v3.0· public release notes 

§01 Investigation

## Interactive Investigation Toolbox new

2.0 only had **automatic inline enrichment** that decorated threat cards. 3.0 keeps that and adds a set of **on-demand investigation tools** \- none of the underlying tool renderers existed in 2.0\. Confirmed tools and their stated purpose:

- **Domain Lookup** \- RDAP / WHOIS + live threat reputation
- **DNS Lookup** \- A / AAAA / MX / NS / TXT records via DNS-over-HTTPS
- **IP Lookup** \- RDAP allocation + live threat reputation
- **Reverse IP Lookup** \- other hosts on the same address
- **ASN Lookup** \- network / BGP allocation
- **Subdomain enumeration** \- discover hostnames under a target domain
- **Certificate Transparency** \- issued-certificate history from CT logs
- **CVE Lookup** \- full CVE detail with CWE references; includes a CVE gauge / ring visual
- **Hash Lookup** \- file-hash reputation against malware-sample and sandbox sources
- **IOC Lookup** \- generic indicator triage
- **Email Auth** \- SPF / DKIM / DMARC / MX checks
- **Reputation Check** \- threat-exchange pulses + IP abuse reputation + malware / phishing scan
- **Breach Intel** \- public breach-notification datasets
- **Credential Leak Search** \- email / username against public leak datasets
- **Infostealer Check** \- stealer-log & combolist captures by email, username, or domain
- **Brand Protect Lookup** \- lookalike-domain / typosquat detection
- **Security News**, **Threat Intelligence Report**, **Backup**, and **Quick Filters & Views**

Supporting infrastructure: tabbed tool panels, inline IOC rows with copy actions, gauges / rings / sparklines, and result caching.

§02 Enrichment

## Expanded enrichment & new data sources

Enrichment that already shipped in 2.0 (registration / WHOIS, malicious-URL scanning, IOC feeds, stealer-log lookups, screenshots, and TTP tactics) was **significantly expanded**, and several **new categories of external source** were wired in. The additions break down by capability:

- **Certificate transparency** \- issued-certificate history for a host or domain.
- **Network & routing** \- ASN / BGP allocation and reverse-IP neighbours.
- **Internet exposure** \- open-port and service-exposure search.
- **Malware intelligence** \- file-hash reputation across sample repositories and a sandbox source.
- **Reputation & abuse** \- threat-exchange pulses and IP abuse scoring.
- **Breach & leak** \- account breach notification and credential-leak datasets.
- **Vulnerability data** \- CVE / CWE detail from public vulnerability databases.

Existing sources also saw heavy use growth, and a handful of capabilities are **new from zero**: malicious-URL feeds, internet-exposure search, breach / leak lookups, IP and domain reputation, and subdomain discovery.

§03 Workflow

## Triage & verdict workflow new

A full per-threat triage system, persisted in dwi\_triage\_v1 and absent in 2.0:

- Mark threats as **Investigating**, **Dismissed**, or **Accepted** with verdict pills (good / bad / neutral).
- Live counters for investigating and dismissed items, with toggles to show or hide them.
- **Mute categories**, with a persistent muted bar and one-click clear.
- Verdict and evidence indicators (high / medium / low confidence).

§04 Organisation

## Tagging, saved views & pivots new

- **Tagging** \- apply custom tags to threats, stored in dwi\_threat\_tags\_v1.
- **Saved views** \- save and restore filter / search configurations (dwi-saved-views-v1).
- **Feed pivots & panel filters** \- pivot the feed by actor, category, or country and apply multi-facet panel filters.

§05 Export

## Export overhaul

- New **export filter panel** with facet combo-boxes for building precise export queries.
- **Live export count + quota** shown before exporting, with reset-time formatting.
- **HTML threat report** generation produces a standalone, shareable report, alongside the existing JSON / CSV / XML exports.
- **State backup & restore** \- export and re-import local bookmarks, tags, triage, and views.

§06 Cards

## Source branding & card redesign

- Per-source **logos** with monogram fallbacks and a brand-icon cache.
- New inline card actions: **bookmark**, **copy-URL**, **dismiss**, and **mute** on each card.
- Entry animations for newly arriving alerts.

§07 Correlation

## Related threats, reposts & actor claims new

- **Related-threats** and **threat-summary** sections inside the detail modal.
- **Repost detection** flags near-duplicate / cross-posted alerts.
- **Actor-claim** UI surfaces which actor is claiming an incident.
- **Watch terms** matching for tracked keywords.

§08 Monitoring

## Forum & source monitoring upgrades

- **Status-board monitoring** new \- polls an external uptime board, detects up / down state, pushes notification subscriptions, and drives a badge.
- **Forum-status redesign** \- a ring / donut status visualization, a new **Evaluating** status alongside up / onboarding / maintenance / degraded / down / paused / unmonitored, and a collapsible forum-status section (dwi:fs-collapsed).

§09 Charts

## New & enhanced charts

- **Category Trend** chart.
- **Month-over-month delta** card.
- **CVE gauge / ring** and **abuse gauge** visuals.
- **Trend signals** with sparklines.
- TTP / tactic display refreshed with new legend and bar styling; the underlying tactic data existed in 2.0.

§10 Interface

## UI / UX additions

- **Custom timezone picker** \- a searchable dropdown replacing the native select, with a full bundled timezone list.
- **"New since last visit" banner** with snooze (dwi\_last\_visit\_v1, dwi\_new\_since\_snooze\_until).
- **Sidebar / rail** \- a collapsible left rail is injected; the bookmarks button moves into the rail and quick-stats merge into the header. Collapse state persists (dwi\_sb\_collapsed, dwi-sb-pinned).
- **Bookmarks** now persist under dwi\_bookmarks\_v1; **notification history** under dwi\_notification\_history\_v1 with prefs bumped to v2.
- **Defang / refang** \- IOCs are defanged when copied or exported (e.g. hxxp://, \[.\]) for safer sharing, with a copy-defanged action.
- **Screenshot capture + OCR findings** expanded.

§11 Privacy

## Privacy & consent new

A **consent banner** with Accept / Decline, persisted in dwi\_consent\_v1 and posted to a consent API. It gates external behavior - confirm exactly which third-party lookups are blocked until consent is given. This matters for the public launch.

// end of changelog - feed@3.0 Dark Web Informer · Live Threat Intelligence