Infoblox Threat Intelligence Data Exchange (TIDE) for ActiveTrust® uses highly accurate machine-readable threat intelligence data via a flexible Threat Intelligence Data Exchange (TIDE) to aggregate, curate and enable distribution of data across a broad range of infrastructure. ActiveTrust TIDE provides an API access to active indicators of compromise (IOC) such as domain names, hostnames and IP-addresses. The indicators can have an expiration date and time. This implementation aims at integrating the Threat Intelligence Data with the Splunk Enterprise Security providing the ability to block access to malicious domains and IP addresses as well as provide a mechanism to enrich investigations through dynamic checks.