Module catalogue
    Seceon module · Managed by KaribuKloud SOC

    OTM (Open Threat Management)

    Unified threat intelligence layer — curated and crowd-sourced IOCs continuously pushed into detection rules.

    Why OTM exists

    Legacy stacks pay for threat intel once per tool. OTM is enriched in a single fabric and pushed to SIEM, XDR, UEBA, SOAR and the cloud workload modules simultaneously — eliminating duplicate licensing and inconsistent indicator coverage.

    What feeds it

    • 65+ commercial and OSINT feeds (MISP, AlienVault OTX, Abuse.ch)
    • Curated Kenya-specific indicators (regional C2 infrastructure, mobile-money fraud patterns)
    • Tenant-shared IOCs across the KaribuKloud MSSP fabric (anonymised)