Skip to main content
Blog

Threat Intelligence Blog

Research, insights, and updates from the isMalicious team.

X-Forwarded-For: Identify a Trusted Client IP
Research1 d ago

X-Forwarded-For: Identify a Trusted Client IP

Choose the right IP to enrich behind proxies by defining trusted relays, then test forged headers, malformed values and direct origin access.

5 min readRead
DNSSEC and SERVFAIL: Find the Cause of Resolution Failure
DNS2 d ago

DNSSEC and SERVFAIL: Find the Cause of Resolution Failure

Diagnose SERVFAIL using detailed DNS errors, the DS/DNSKEY chain and signatures, then verify the repair with DNSSEC validation enabled.

5 min readRead
DNS TTL: Investigate a Change of IP Address
DNS3 d ago

DNS TTL: Investigate a Change of IP Address

Reconstruct DNS address changes using dated responses, caches and network views, without confusing TTL with the lifetime of a threat.

5 min readRead
NXDOMAIN: Diagnose a DNS Security Anomaly
DNS4 d ago

NXDOMAIN: Diagnose a DNS Security Anomaly

Separate nonexistent names, negative caching, filtering and suspicious activity before treating NXDOMAIN errors as a security incident.

5 min readRead
CNAME Cloaking: Investigate a Third-Party Subdomain
DNS5 d ago

CNAME Cloaking: Investigate a Third-Party Subdomain

Trace CNAME records, identify the provider, and inspect transmitted cookies before deciding whether a subdomain should remain authorized.

5 min readRead
Parked Domains: Assess the Risk Before Blocking
Phishing6 d ago

Parked Domains: Assess the Risk Before Blocking

Distinguish domain parking, expiration, and malicious behavior. Examine actual use and choose a restriction supported by the evidence.

5 min readRead
RDAP: Read Domain Data During an Investigation
Threat Intel2026-10-04

RDAP: Read Domain Data During an Investigation

Use RDAP events, statuses, and contacts to document a suspicious domain without misattributing an identity or claiming an unproven compromise.

5 min readRead
DMARC XML Reports: Interpret Authentication Failures
Email Security2026-10-03

DMARC XML Reports: Interpret Authentication Failures

Read aggregate DMARC reports, distinguish alignment from authentication, and prioritize anomalies by sending service and business impact.

5 min readRead
SPF Permerror: Fix the DNS Lookup Limit
Email Security2026-10-02

SPF Permerror: Fix the DNS Lookup Limit

Trace SPF dependencies, distinguish permerror from fail, and reduce DNS lookups while testing every sending service.

5 min readRead
SMTP 550 5.7.1: Find the Cause of an Email Rejection
Email Security2026-10-01

SMTP 550 5.7.1: Find the Cause of an Email Rejection

A 550 5.7.1 rejection can involve recipient policy, authentication, or reputation. Use the full diagnostic and delivery traces to find the cause.

5 min readRead
How to Analyze Suspicious Email Headers
Phishing2026-09-30

How to Analyze Suspicious Email Headers

Identify trusted servers, interpret Authentication-Results, and investigate a suspicious email without confusing authentication with safe content.

5 min readRead
Government Threat Intelligence Procurement: A Practical Guide
Threat Intel2026-09-18

Government Threat Intelligence Procurement: A Practical Guide

Specify a public-sector threat intelligence service with clear evidence, data-handling rules, acceptance tests and an exit plan for UK and European teams.

10 min readRead
Local Government Network Security: A 90-Day Council Plan
Research2026-09-18

Local Government Network Security: A 90-Day Council Plan

Build a council network security plan around public services, clear ownership, tested segmentation and useful logs, with practical actions across 90 days.

11 min readRead
Protective DNS for the Public Sector: A Deployment Guide
DNS2026-09-18

Protective DNS for the Public Sector: A Deployment Guide

Deploy protective DNS across public-sector sites and remote staff. Test coverage, handle exceptions and keep essential services available during failures.

10 min readRead
Public Sector Supplier Remote Access: Control Every Session
Research2026-09-18

Public Sector Supplier Remote Access: Control Every Session

Control supplier remote access with named identities, agreed work windows, bounded paths and verified revocation, using a practical public sector example.

11 min readRead
School Network Security: Test Segmentation That Works
Research2026-09-18

School Network Security: Test Segmentation That Works

Plan school network segmentation around teaching needs, test permitted and blocked paths, protect administration, and manage changes without losing access.

10 min readRead
CTI Analyst OPSEC: Scan URLs Without Exposing Secrets
Threat Intel2026-09-17

CTI Analyst OPSEC: Scan URLs Without Exposing Secrets

Protect CTI investigations before scanning URLs or files: assess public visibility, signed links, hash lookups, and the right environment for sensitive evidence.

11 min readRead
CTI Analyst Portfolio: Build a Safe, Reproducible Lab
Threat Intel2026-09-17

CTI Analyst Portfolio: Build a Safe, Reproducible Lab

Build a CTI analyst portfolio with offline datasets, evidence-led assessments, reproducible results, and a review rubric that shows how you make decisions.

11 min readRead
Cyber Attribution: Confidence and Competing Hypotheses
Threat Intel2026-09-17

Cyber Attribution: Confidence and Competing Hypotheses

Assess cyber attribution with evidence, competing hypotheses, and explicit confidence. Use a practical judgment record without treating an IOC as an identity.

11 min readRead
Threat Intelligence PIRs: A Workbook and Collection Plan
Threat Intel2026-09-17

Threat Intelligence PIRs: A Workbook and Collection Plan

Turn threat intelligence requests into useful PIRs with a decision worksheet, collection plan, evidence requirements, ownership, and practical stopping rules.

10 min readRead
Diamond Model: A Practical CTI Investigation Walkthrough
Threat Intel2026-09-17

Diamond Model: A Practical CTI Investigation Walkthrough

Use the Diamond Model to connect evidence, test competing explanations, build activity threads, and turn a phishing investigation into defensible decisions.

11 min readRead
IOC Retrohunting: Investigating Historical Logs Reliably
Threat Intel2026-09-17

IOC Retrohunting: Investigating Historical Logs Reliably

Run reliable IOC retrohunts by separating event time, intelligence availability, and validity, then document historical evidence and the limits of negative results.

11 min readRead
Threat Intelligence Feed Poisoning: Protect Your Evidence
Threat Intel2026-09-17

Threat Intelligence Feed Poisoning: Protect Your Evidence

Protect CTI decisions from misleading data with source provenance, mirror detection, contradiction handling, safe ingestion, human review, and tested rollback.

10 min readRead
Threat Intelligence Feed ROI: Build a Reliable Benchmark
Threat Intel2026-09-17

Threat Intelligence Feed ROI: Build a Reliable Benchmark

Evaluate threat intelligence feeds with an independent sample, complete operating costs, and a measure of incremental value before buying or renewing a contract.

10 min readRead

Expert Threat Intelligence Analysis

Our blog features in-depth analysis from our threat research team. Each article is backed by real data from our analysis of millions of malicious domains, IPs, and URLs across the global threat landscape. Topics include ransomware campaigns, phishing techniques, malware distribution networks, and emerging threat trends. We publish specific intelligence that security teams can immediately use to improve their defenses.

Practical Security Guidance

Beyond threat analysis, we share practical guidance for security practitioners. Our tutorials cover API integration, SIEM configuration, threat hunting techniques, and building effective threat intelligence programs. Whether you're a SOC analyst, security engineer, or CISO, you'll find content tailored to your role and experience level.

Stay Ahead of Emerging Threats

The threat landscape evolves constantly. Our blog keeps you informed about the latest attack techniques, newly discovered vulnerabilities, and emerging threat actors. Subscribe to our newsletter for weekly digests of the most important developments in cybersecurity.

Subscribe to Our Newsletter

Weekly threat intelligence insights delivered to your inbox.