The empty-graph problem
You downloaded ICDB. You ran it. You logged in. The graph is empty.
That’s a feature, not a bug. Your tenant starts isolated and no data crosses the boundary you don’t explicitly let cross. But staring at an empty canvas isn’t useful. You need real intel, and you need it before you’ve finished your first coffee.
The pid4 consortium is how.
What pid4 is
The pid4 consortium is the public, cross-organization threat-intel pool that every ICDB instance can join. Think of it as the open shared layer: the place where TLP:WHITE and TLP:GREEN data flows between every participating org. Insights, BOLOs, detection rules, indicator clusters: anything a member chooses to share at those classification levels lands in your graph minutes after they publish it.
Membership is opt-in. Each consortium is approved by its owner; for the pid4 consortium specifically, that’s J3J. Shared data is encrypted in transit using each receiving tenant’s X25519 public key and Ed25519-signed by the sender for third-party-verifiable attribution. When an insight shows up in your view tagged “shared by Acme SOC,” you can prove cryptographically that Acme SOC is who actually wrote it.
Joining, start to finish
You need the operator role with org_admin on your tenant to do this. On a single-user hobbyist install, that’s you by default.
- Open Settings → Consortium. The list shows every consortium your tenant can see: the ones you’re already in plus any public ones available to request.
- Find pid4. It’s marked with the pid4 logo and a “Default” badge.
- Click “Request to join.” A dialog asks for a brief note about your org. Keep it short. A sentence about what you do is plenty.
- Submit. A J3J operator reviews and approves the request.
- Check back. The pid4 entry in your Consortium list flips from “Pending” to “Active” once the request is approved, and shared data starts populating your views.
That’s it. No keys to exchange, no DNS to configure, no S2S broker certs to negotiate. The broker handles cryptographic provenance behind the scenes.
What changes the moment you’re in
Within a few seconds of approval:
- Insights appear in the Shared filter on the Insights page, badged with the publishing org. Every insight a member org publishes shows up there. Filter, search, and pull any of them into your own work.
- BOLOs (Be On the Lookout) are standing watch queries broadcast by member orgs. They run against your graph; if one of your indicators matches, both sides get a hit.
- Indicator clusters propagate into your local view as TLP-gated reads. You don’t own the data (the originating tenant does), but you can read it, query it with ICQL, and stitch it into your own work.
- Attribution stays intact. Every shared item shows which org authored it. You always know who to credit, and who to ping if you need clarification.
Reciprocity, on your schedule
Joining gives you read access. Contributing is up to you, and you control the cadence and classification.
When you publish your own insight, you set its TLP and pick which consortiums to share it into from the share panel. Pick pid4, and your peers see it (signed by your tenant) on their next refresh. Remove the share, and it’s private to your tenant again within seconds.
If you need to go quiet during an internal incident, the move is to not share, or to remove the share on anything that’s already out. Membership stays intact. Nothing new flows outbound until you re-share.
When you’re ready for more
The pid4 consortium is the broadest, most public layer, and the right starting point. Over time you’ll want private consortiums: smaller, mission-specific groups with stricter membership controls. A financial-sector ISAC. A ransomware working group. A handful of trusted peers running a closed sharing arrangement.
Creating one is two clicks from the Consortium list. Inviting a peer org is a generated URL plus an optional passphrase, sent out-of-band. The in-app Creating & Managing Consortiums guide walks through the rest.
But that’s for next week. Today, the move is simple: join pid4, watch the graph fill in, and start working with intel you didn’t have to source yourself.