pkg.soopen package index

brew / rank 9457

Install threatdeck with Homebrew

TUI threat intelligence monitoring and alerting platform. Version 0.6.0 via Homebrew; verified 2026-06-14.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install threatdeck

local Homebrew formula metadata

overview

Package summary

TUI threat intelligence monitoring and alerting platform

Commands and aliases

  • ThreatDeck

history

Project history and usage

ThreatDeck is a terminal-based threat-intelligence monitoring and alerting platform for SOCs, security researchers, and threat-intelligence analysts. Its README presents it as a TUI for feeds, alerts, cached articles, indicators, enrichment queues, keywords, tags, logs, and settings.

Project history

The project is a Rust application built around a local SQLite database and a terminal UI. The README describes feed ingestion from APIs, RSS and Atom feeds, websites, and onion services, with alert generation, deduplication, IOC extraction, local enrichment, notification channels, and dashboard views.

Adoption history

ThreatDeck appears to be a newer and smaller package than the long-running security CLIs in this batch: the official GitHub page shows a modest star/fork count and a short repository history. Its packaging path is still meaningful because the README documents Cargo installation, source builds, a Homebrew package in the assigned facts, and first-run creation of config and data directories.

How it is used

Users launch `ThreatDeck`, add feeds, define keyword or regex alerts with criticality levels, browse and triage alerts in the terminal, and optionally configure enrichment providers. The default config file is `~/.config/ThreatDeck/config.toml`; the README documents the data database path and a `--config-paths` command for exact paths.

Why package nerds care

For package nerds, ThreatDeck is interesting as a packaged security TUI: it combines Rust, bundled SQLite, terminal UI dependencies, scheduled feed polling, JSONPath templates, optional Tor/onion access, and local enrichment into a single installable binary.

Timeline

  • Current README: documents Cargo install, source build, first-run config/data paths, feed management, alerts, IOC enrichment, notifications, and SQLite storage.
  • Current repository page: shows a small public repository with README, docs, dist artifacts, and Rust source.

Related projects

  • Related tools include RSS/API feed monitors, SOC alert triage dashboards, threat-intelligence platforms, IOC enrichment tools, terminal UI applications, and local SQLite-backed monitoring utilities.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for threatdeck. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/.config/ThreatDeck/config.toml

executables

Installed executables

CommandKindExposureNote
ThreatDeckexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version0.6.0
manager updated2026-06-14
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:threatdeck
Version0.6.0
Package managerHomebrew
Homepagehttps://threatdeck.io/
Repositoryhttps://github.com/gripebomb/ThreatDeck
Last updated2026-06-14T11:02:48Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • pkg.so package database
  • pkgdb category and tag curation