Automic VaultAutomic Vault

brew

Install threatdeck with Homebrew

TUI threat intelligence monitoring and alerting platform. Version 0.6.0 via Homebrew; verified 2026-06-14.

install

Additional install commands

macOS

Homebrewverified ยท 100%
brew install threatdeck

local Homebrew formula metadata

overview

Package summary

TUI threat intelligence monitoring and alerting platform

Commands and aliases

  • ThreatDeck

history

Project history and usage

ThreatDeck is a terminal-based threat-intelligence monitoring and alerting platform for SOCs, security researchers, and threat-intelligence analysts. Its README presents it as a TUI for feeds, alerts, cached articles, indicators, enrichment queues, keywords, tags, logs, and settings.

Project history

The project is a Rust application built around a local SQLite database and a terminal UI. The README describes feed ingestion from APIs, RSS and Atom feeds, websites, and onion services, with alert generation, deduplication, IOC extraction, local enrichment, notification channels, and dashboard views.

Adoption history

ThreatDeck appears to be a newer and smaller package than the long-running security CLIs in this batch: the official GitHub page shows a modest star/fork count and a short repository history. Its packaging path is still meaningful because the README documents Cargo installation, source builds, a Homebrew package in the assigned facts, and first-run creation of config and data directories.

How it is used

Users launch `ThreatDeck`, add feeds, define keyword or regex alerts with criticality levels, browse and triage alerts in the terminal, and optionally configure enrichment providers. The default config file is `~/.config/ThreatDeck/config.toml`; the README documents the data database path and a `--config-paths` command for exact paths.

Why package nerds care

For package nerds, ThreatDeck is interesting as a packaged security TUI: it combines Rust, bundled SQLite, terminal UI dependencies, scheduled feed polling, JSONPath templates, optional Tor/onion access, and local enrichment into a single installable binary.

Timeline

  • Current README: documents Cargo install, source build, first-run config/data paths, feed management, alerts, IOC enrichment, notifications, and SQLite storage.
  • Current repository page: shows a small public repository with README, docs, dist artifacts, and Rust source.

Related projects

  • Related tools include RSS/API feed monitors, SOC alert triage dashboards, threat-intelligence platforms, IOC enrichment tools, terminal UI applications, and local SQLite-backed monitoring utilities.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for threatdeck. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Installs with 1 runtime dependencies.
  • Build metadata lists 2 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/.config/ThreatDeck/config.toml

executables

Installed executables

CommandKindExposureNote
ThreatDeckcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-07-25
manager version0.6.0
manager updated2026-06-14
local dataok
upstreamcurrent
latest detectedv0.6.0

https://github.com/gripebomb/ThreatDeck

  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:threatdeck
Version0.6.0
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/threatdeck
Homepagehttps://threatdeck.io/
Repositoryhttps://github.com/gripebomb/ThreatDeck
Upstream docshttps://github.com/gripebomb/ThreatDeck#readme
LicenseMIT
Source archivehttps://github.com/gripebomb/ThreatDeck/archive/refs/tags/v0.6.0.tar.gz
Last updated2026-06-14T11:02:48Z
Pulseupdated
Dependenciesopenssl@4
Build dependenciespkgconf, rust
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namethreatdeck
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment