Home Tech One search box, eight feeds: inside Wiestell, the free threat intelligence platform
Tech

One search box, eight feeds: inside Wiestell, the free threat intelligence platform

Share
Wiestell
Share

It is two in the morning at a small security team somewhere. An alert has fired, an unfamiliar IP address is sitting in the log line, and the analyst on shift needs to answer one question quickly: is it hostile? The usual method means opening half a dozen browser tabs, pasting the address into each, and squinting at six verdicts that never quite line up.

Now picture the same analyst dropping that address into a single search box and getting one clear answer within a couple of seconds. Which feeds have seen the IP, what each of them reports, where it sits geographically, who owns the network behind it, and a short AI-written assessment of the risk. No subscription. No sales call. The page did not even ask them to register.

That platform is Wiestell, and it was built by Garyson Pereira.

The practitioner behind it

Gary(son), as he goes by, is a Lead Security Engineer at Oakbrook Finance, a UK consumer lender backed by Blenheim Chalcot. Eleven years in cybersecurity sit behind him, along with an MSc in Computer Forensics and Cyber Security from the University of Greenwich. His working days run on detection engineering and incident response inside a regulated financial environment. Wiestell, by contrast, was built in evenings and at weekends, on his own infrastructure, and released for nothing. His fuller story sits on the Wiestell About page.

Why give it away?

His reasoning is printed on the platform’s homepage, in his own words:

Threat intelligence shouldn’t be a privilege. Every defender, whether in a mature enterprise SOC or working solo, deserves access to the same quality of threat data.

That reads less like a slogan and more like a description of how the market behaves. Commercial threat intelligence tends to be priced for large enterprises, with annual licences climbing well into five and six figures. A thirty-person charity has no route to that. Nor does a journalist trace a phishing campaign, or a student teaching themselves to triage indicators after class. They get by on browser tabs and patience, even though the malware infrastructure aimed at a FTSE 100 bank frequently turns up in attacks on far smaller targets.

What a single lookup does

An indicator of compromise, in the trade, is one of a handful of artefacts: an IP address, a domain, a URL, or a file hash. Paste any of them into Wiestell and it queries eight open-source feeds at once. Four come from the Swiss non-profit abuse.ch: URLhaus, MalwareBazaar, ThreatFox and Feodo Tracker. The others are AbuseIPDB, VirusTotal, AlienVault OTX and PhishTank, each watching a slightly different corner of the threat landscape.

single lookup

On top of the raw feed data sits an enrichment layer. Geolocation, WHOIS records, the network owner behind an address, historical reputation. Then comes the step that sets Wiestell apart. A large language model, Meta’s Llama 3.3 70B running on Groq’s infrastructure for sub-second replies, reads the conflicting signals and produces a single risk verdict with reasoning you can inspect. The feed-level results are not hidden behind that verdict. They sit right next to it, so an analyst who disagrees can trace exactly what drove the score.

A practical flavour

Consider a suspicious domain. A careful investigation asks a few pointed questions. How old is it, given that phishing kits tend to run on freshly registered domains? Who registered it, and does that pattern resemble a legitimate business in the same sector? Where does it actually resolve, and what sort of network hosts it? Has the wider community already flagged it? Done by hand, that is roughly twenty minutes and seven tabs. Wiestell folds it into about a minute.

File hashes carry a quirk worth knowing. Malware databases still index samples under three algorithms: MD5, SHA-1 and SHA-256. The first two have been cryptographically broken for years, yet nobody has retired them, because in malware work a hash serves as a label rather than a security guarantee. An old research paper might quote an MD5, while a modern tool hands you a SHA-256. Wiestell accepts all three without asking which one you have pasted.

The same consolidated approach carries over to the other artefacts an analyst chases during triage, from indicators tied to active campaigns through to vulnerability references pulled from an advisory.

What it is, and what it isn’t

It helps to be honest about the boundaries. Wiestell is not a SIEM, and it will not replace a commercial subscription where one is truly warranted. It is a lookup tool, built with care, kept free, and aimed at the very large population of defenders who fall between “no tooling at all” and “a six-figure annual licence”. Measured by headcount, that group is most of the security community.

The quieter pattern

The interesting part is not the software, good as it is. It is what the project hints at. People closest to the problem of under-resourced defence have started building the tools they wish had existed when they were finding their feet, then handing them over. Gary(son) has done exactly that, with no launch campaign and on the plain conviction that access to threat data should not track the size of an organisation’s budget. Wiestell lives at wiestell.com, and it is still free.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
How to Make the Internet Safe for Your Children
Tech

How to Make the Internet Safe for Your Children

Since the internet has become an essential part of communities all over...

10 Everyday Tasks AI Will Replace by 2030
Tech

10 Everyday Tasks AI Will Replace by 2030

According to predictions, artificial intelligence will subtly change daily life by 2030,...

Top Chrome Extensions to Boost Your Efficiency
Tech

Top Chrome Extensions to Boost Your Efficiency

The Chrome Store is a vast collection of extensions that can do...

How-AI-Assistants-Are-Replacing-Virtual-Assistants
Tech

How AI Assistants Are Replacing Virtual Assistants

The emergence of virtual assistants with artificial intelligence (AI) has significantly changed...