Resources
Published intelligence, the editorial policies behind it, and the ways to reach us. Every link on this page goes somewhere real.
ThreatBharat is early and the published body of reporting is still small. Several views below will be sparse or empty, and they say so plainly rather than filling the space. We would rather you found an honest empty page than a padded one.
Published intelligence
Open to anyone, no account required.
- Threat feed
Every published report, newest first, filterable by category, sector and severity.
- Breach reporting
Claimed and confirmed data-breach reporting, with the two states kept clearly apart.
- Ransomware reporting
Victim-listing and group-activity reporting. A listing is a claim by an actor, not a confirmed breach.
- Threat actor directory
Profiles built from observed activity only, each carrying explicit attribution caveats.
- Vulnerability intelligence
Reporting on vulnerabilities exploited against India-relevant targets, plus advisories. Not a CVE database.
- Incidents
Published incident reporting with timelines and related-report links.
India views
The same published reporting, organised for a national and sectoral reader.
- India hub
The national view of published reporting, including a state-level breakdown.
- Sector views
Published reporting grouped by sector, for peer context on whether a campaign is broader than one organisation.
Methodology and policies
How we decide what to publish, how we label it, and what happens when we are wrong. Worth reading before citing a verification label.
- Methodology
How sources are assessed, how claims are separated from confirmation, and what each verification and confidence label means.
- Responsible publication
What we will and will not publish, and why publication is never confirmation.
- Source handling
How evidence is captured, redacted and stored — and why original captures are never published.
- Corrections policy
How mistakes are corrected in public, and how to ask for a correction to a report about you.
- Acceptable use
What this platform may and may not be used for.
- Privacy
What we store about site visitors and about people who contact us, and for how long.
Research, feeds and contact
Longer-form work, machine-readable output, and the routes to reach a person.
- Research
Longer-form analysis published by our team.
- RSS feed
Published reporting as an RSS feed, for readers who would rather not visit.
- Platform status
Current availability of the public site and API.
- Request a correction
Tell us a published report is wrong. Corrections are published, not quiet edits.
- Affected organisation contact
For an organisation named in a report that needs to reach us directly.
Not available yet
In developmentListed so the roadmap is not a surprise. These are deliberately not links — there is nothing behind them yet, and a button that leads nowhere wastes your time.
- Downloadable threat reports
In preparation. We would rather publish nothing than put a download button on a file that does not exist.
- Public API documentation
In preparation. The public read API is live and used by this site; the written documentation for it is not finished.
- Sector threat briefings
Planned. Available through limited access first, once there is enough published reporting to make a briefing worth reading.
Request access
Organisational monitoring — matching published reporting against your own assets and watchlists — is reached through a reviewed access request.
Submitting a request does not create an account or guarantee access. Every request is reviewed by a person.
Request access