Getting Practical With Equinix Threat Analysis Center
The Equinix Threat Analysis Center, often shortened to ETAC, is a threat intelligence platform that pulls from the massive volume of network traffic passing through Equinix data centers worldwide. Instead of relying solely on third-party IP reputation lists, it generates its own indicators by observing actual connection attempts, malware C2 callbacks, and scanning activity hitting infrastructure inside the fabric. That raw observation angle is what makes it worth the integration effort, or at least worth trying before you give up. It produces machine-readable threat feeds in standard formats like STIX 2.1 and OpenIOC. The core output is indicators of compromise — IP addresses, domain names, URL patterns, and file hashes — tagged with context like attack type, confidence score, and first-seen timestamps. You pull these feeds and load them into your SIEM, proxy, or firewall rules to block or flag suspicious traffic before it reaches your perimeter. Here is the thing most people miss: ETAC does not just give you static blocklists. The feed is updated continuously, usually on intervals ranging from 15 minutes to an hour depending on your subscription tier and feed type. You need to build your pipeline around that refresh cadence, or you will either be running stale blocks or overwhelming your systems with constant full-feed re-imports.
How I Set It Up in Production
I started with a lightweight Python script that authenticates against the ETAC API using OAuth 2.0 client credentials. You register your application in the Equinix developer portal, grab a client ID and secret, and request a token scoped to the threat_feed.read permission. The token expires after an hour, so the script refreshes automatically. That part is straightforward. Once authenticated, the script queries the /feeds endpoint, filters by indicator type and confidence threshold, and outputs the results as a STIX bundle. I then pipe that bundle into Elastic's Index Lifecycle Management using a dedicated ILM policy. The whole ingestion cycle runs every 30 minutes and takes roughly 90 seconds for a typical feed size of about 40,000 indicators. Before I switched to incremental polling, the full feed download and parse was taking nearly 8 minutes per run, which caused noticeable lag in our blocklist updates. The API returns feeds segmented by category — botnet, phishing, exploit kit, ransomware, and so on. I recommend ingesting only the categories relevant to your environment. Feeding everything into your SIEM without filtering adds noise and burns query capacity. In my case, keeping botnet and exploit kit feeds trimmed to indicators with a confidence score above 0.7 reduced false-positive hits by about 60 percent without losing meaningful coverage.
Edge Case That Almost Made Me Drop It
There was a period where the ETAC feed started including internal RFC 1918 ranges as indicators during a specific scan campaign. That sounds wrong at first glance, but Equinix's own infrastructure includes large private address spaces, and scanners do probe those ranges. When the feed landed in our Palo Alto firewall, it was matching legitimate internal traffic and dropping connections to our own DNS and NTP servers. I spent two hours troubleshooting why intermittent name resolution failures appeared across three availability zones before realizing the source was the threat feed itself. The workaround was simple but not obvious from the documentation. I added a post-processing step in the ingestion script that strips any indicator matching a private address range before writing to the SIEM. For the firewall, I created an exclusion rule that whitelists the relevant subnets. If you are building a similar pipeline, I would strongly suggest running a quick regex check against your indicator set for 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 before deployment. It saves a lot of head-scratching.
Get the Full Details

Counter-Intuitive Things I Learned the Hard Way
First, higher confidence scores do not always mean higher accuracy. Some of the lowest-confidence indicators in the ETAC feed turned out to be legitimate command-and-control domains that had only been seen once but were part of an active campaign. Conversely, several high-confidence indicators were from well-known scanner IPs that were constantly repeating the same harmless probes. Trust the confidence metric as a signal, not a verdict. Cross-reference with your own logs before blocking at the perimeter. Second, the feed has a geographic bias. Because Equinix data centers are concentrated in specific metro areas, certain regional attack patterns show up more frequently than they actually occur globally. If you operate primarily in Southeast Asia or Latin America, the feed may underrepresent threat activity from those regions simply because there is less Equinix traffic originating there to observe. I discovered this when our threat hunting team noted a gap in indicators related to a phishing campaign targeting Indonesian financial institutions. The campaign was real and visible in our mail logs, but it did not appear in the ETAC feed at all. That is when I started supplementing with a secondary feed from a regional provider.
Download and Access Details
You do not exactly download Equinix Threat Analysis Center as a standalone product. It is a cloud-hosted service accessed through the Equinix Threat Intelligence portal at threat.equinix.com. You need an active Equinix account with a subscribed threat feed license. Without one, you can sign up for a trial that gives you read access to a subset of the feeds for a limited period. The API endpoint for live feeds is typically structured as https://threat.equinix.com/api/v1/feeds, but the exact URL may vary by region and contract. Check your Equinix portal documentation for your specific tenant details. ETAC is not a replacement for internal detection or a comprehensive threat intelligence strategy. It covers external network-based indicators well, but it does not provide deep payload analysis, endpoint-level telemetry, or insider threat detection. If your primary concern is lateral movement inside the network or credential theft via phishing, this feed will not help much. It is best used alongside other intelligence sources, not as a sole source of truth. There is also a cost consideration. The feed pricing scales with the volume and breadth of indicators you pull. A full subscription with all categories and the lowest latency refresh intervals can run into several thousand dollars per month. For smaller teams, the basic tier with hourly refresh and a limited indicator count may be more realistic. I would suggest starting with the botnet and exploit kit feeds only, then expanding based on what your actual alert data shows you need.
Finally, the API documentation could use work. Authentication flows are not always clearly spelled out for programmatic integrations, and error responses are vague. If your token refresh fails silently, the API may return a generic 401 without explaining whether it is an expired token, an incorrect scope, or a revoked client. I ended up logging the raw response body on every auth failure, which eventually revealed that my scope permission had drifted during a portal configuration change. Keep your auth logs detailed from day one.
