Examples disclosed herein relate to providing enhanced threat intelligence on a security information sharing platform. Some examples may enable correlating a first set of items of threat information from the security information sharing platform. Some examples may enable, responsive to determining that the correlated first set of items of threat information indicate a first malicious action type, creating a new security indicator comprising information from the correlated first set of items of threat information and associating the new security indicator with the first malicious action type. Some examples may enable determining whether a first threat pattern exists based on the new security indicator.
展开▼