Edgewatch CTI — Trends Tag

Trends highlights activity around threat-intel tags (actors, tools, CVEs) detected by Edgewatch, using a signature-based approach to surface what’s moving now across our collections. Use it to spot spikes, anomalies, and newly active items before they hit your incidents queue.

Public preview of trends: https://search.edgewatch.net/trends

  • Classification filters: ALL · MALICIOUS · SUSPICIOUS · BENIGN · UNKNOWN — quickly narrow trends to the risk level you care about.
  • Trend lenses: TRENDING · ANOMALIES · MOST ACTIVE · MOST RECENT — switch between momentum, outliers, raw volume leaders, or the latest arrivals.
  • Each trend item represents a tag (e.g., an actor/tool/CVE) derived via signature-based detection in Edgewatch threat-intel data.

How to use it (SOC/EASM)

  • Morning triage: open TRENDING + MALICIOUS to prioritize hunts and temporary blocks for high-momentum tags. 
  • Risk review: check ANOMALIES to catch low-frequency but fast-rising tags that may signal emerging campaigns.
  • Change tracking: pivot from MOST RECENT items into your internal alerts to confirm exposure paths and add detections.

If the page shows “No trends available,” there may be no current activity in your selected view; try changing the lens or classification filter and revisit later.

Was this article helpful?

Related Articles

Need Support?

Can't find the answer you're looking for?
Contact Support