Arctic Hub
Answers about the Arctic Hub platform — who it's for, what it handles, deployment, and operator troubleshooting.
No matches — try a different word, or clear the filter.
General
What is Arctic Hub?
Arctic Hub is a cyber threat intelligence and early warning platform that automates the gathering, harmonization, and distribution of threat data. It helps organizations process massive amounts of threat intelligence and automatically map relevant security alerts directly to their stakeholders or customers.
Related: Arctic Hub product page
Who is Arctic Hub designed for?
It is built for organizations and authorities in charge of cybersecurity, such as national CERT/CSIRT teams, Managed Security Service Providers (MSSPs), Internet Service Providers (ISPs), and large enterprises managing critical infrastructure. It allows these entities to act as a central intelligence "hub" to protect their constituents.
Does Arctic Hub actively scan constituent networks?
No, Arctic Hub does not actively probe or scan constituent networks. Instead, it operates as a central aggregator, harmonizer, and matching engine. It continuously ingests threat intelligence from external feeds, scan results (via integrations), and custom data sources, matching those observations against your constituents' public-facing assets without generating network traffic or alarms.
How Arctic Hub compares to other solutions
How does Arctic Hub compare to traditional Threat Intelligence Platforms (TIPs) or Risk-Scoring Tools?
Traditional TIPs aggregate data for internal analyst review, and risk-scoring platforms provide abstract posture ratings. Arctic Hub serves a different purpose: it automates the end-to-end pipeline from feed ingestion to targeted constituent notification. Instead of giving you a broad threat landscape to triage manually or an arbitrary score, Hub automatically filters high-volume intelligence down to confirmed, actionable issues mapped to specific assets, sending exact findings directly to the affected stakeholders.
Business & compliance value
Will Arctic Hub create more work for our security team?
No, Arctic Hub is designed to drastically reduce manual labor. By automating the ingestion, harmonization, and distribution of threat intelligence, it eliminates the need for analysts to manually triage spreadsheets and emails, freeing up your team to focus on critical incident response.
Can Arctic Hub help with regulatory compliance?
Yes. For organizations serving as national CERTs, critical infrastructure providers, or large MSSPs, an active Arctic Hub deployment helps satisfy key requirements for frameworks such as NIS2 by establishing a structured, automated, and documented process for vulnerability and threat notification sharing.
Related: What is early warning?
Features & capabilities
What external threat feeds and data sources are supported out of the box?
Arctic Hub features native, plug-and-play connectors for a vast array of commercial, open-source, and specialized external feeders, including:
- Commercial & Specialized Feeds: CrowdStrike, Mandiant, GreyNoise, Spamhaus Private, Team Cymru (and Team Cymru Private), Akamai, Fitsec (and Fitsec API), Bambenek Consulting, Abusix, Telia.
- Vulnerability & Threat Intelligence: ShadowServer (and ShadowServer API), Shodan (custom), SANS ISC, DataPlane.org, Daniel Gerzo, ddos-tracker.org.
- Phishing & Ransomware Feeds: Abuse.ch, OpenPhish & OpenPhish Premium, PhishTank, Ransomware.live, VxVault, ZONE-H, Microsoft Digital Crimes Unit.
What external integrations and Input APIs are supported?
To enrich asset discovery and ingest custom or internal data, Arctic Hub supports direct integrations and Input APIs, including:
- Vulnerability & Breach Integrations: Nessus, Nessus Customer Scans, and HIBP (Have I Been Pwned) integration.
- Reconnaissance & DNS Integrations: SecurityTrails, DomainTools, CTL Domain Enumeration, and native DNS Resolver.
- Custom Input APIs: Allows you to feed internally generated vulnerability scan results, national sensor logs, or proprietary threat feeds directly into the Hub via a JSON payload.
How does Arctic Hub map threats to customers?
Arctic Hub uses automated attack surface discovery and a built-in customer database. It matches incoming, harmonized threat data to specific customers based on their internet presence and assets, ensuring stakeholders only receive alerts relevant to their own infrastructure.
How is information shared with stakeholders?
You can share tailored threat intelligence packages with your stakeholders through automated, directly actionable email reports or via direct API access.
Related: EWS Flex
Can I encrypt automated report emails sent to customers?
No, but Arctic Hub does support PGP signing for outgoing plaintext emails. You can import your public / private key pair into the Hub's secure keyring and enable PGP signing within the system configuration. For the step-by-step PGP configuration guide, please contact our team.
How long is historical event data kept in the Hub?
By default, historical event data is never automatically removed. If you need to manage disk space, or delete old event data, a custom data retention period can be configured in your system settings to automatically purge older events.
Summarized data of the collected events is kept in separate data aggregate indexes, so data visualizations can extend further into history, even though the event has been dropped from the database.
For guidance on calculating storage requirements or setting up data retention policies, please reach out to support.
Setup & infrastructure
What is considered an "asset" in Arctic Hub?
An asset is an IP address, IP range, or domain name associated with your constituents' IT infrastructure. If a constituent possesses an Autonomous System Number (ASN), that is considered an asset if managed directly by them.
How are cloud-hosted or shared resources handled?
If an IP address appears to belong to a dedicated cloud resource for a constituent, it is treated as a direct asset. If an IP hosts multiple tenants (such as shared web hosting), Arctic Hub automatically excludes the shared IP to prevent multi-tenant alert noise, while continuing to match threats specific to the constituent's domain name.
What are the minimum memory (RAM) requirements for Arctic Hub?
The absolute minimum recommended memory for a stable deployment is 32 GB of RAM. The Hub relies heavily on in-memory databases and caching to process threat data quickly. Allocating less than 32 GB can result in the operating system forcefully terminating Hub processes (OOM kills) during normal data spikes.
If you are sizing a new environment, please contact our team for hardware recommendations. As Arctic Hub is intended for national scale deployments, we know from experience that the hardware recommendations for production use can be significantly higher than the minimum recommendations quoted here.
Where is data stored, and is Arctic Hub GDPR-compliant?
Yes, Arctic Hub is fully GDPR-compliant. Depending on your deployment model (SaaS or dedicated on-premise/cloud instance), data can be hosted locally or within EU-based data centers (AWS Ireland) to ensure full compliance with European data sovereignty regulations.
Didn't find your answer?
Write to product-support@arcticsecurity.com — we reply the next business day.