Threat Intelligence Blog
Research, insights, and updates from the isMalicious team.

X-Forwarded-For: Identify a Trusted Client IP
Choose the right IP to enrich behind proxies by defining trusted relays, then test forged headers, malformed values and direct origin access.

DNSSEC and SERVFAIL: Find the Cause of Resolution Failure
Diagnose SERVFAIL using detailed DNS errors, the DS/DNSKEY chain and signatures, then verify the repair with DNSSEC validation enabled.

DNS TTL: Investigate a Change of IP Address
Reconstruct DNS address changes using dated responses, caches and network views, without confusing TTL with the lifetime of a threat.

NXDOMAIN: Diagnose a DNS Security Anomaly
Separate nonexistent names, negative caching, filtering and suspicious activity before treating NXDOMAIN errors as a security incident.

CNAME Cloaking: Investigate a Third-Party Subdomain
Trace CNAME records, identify the provider, and inspect transmitted cookies before deciding whether a subdomain should remain authorized.

Parked Domains: Assess the Risk Before Blocking
Distinguish domain parking, expiration, and malicious behavior. Examine actual use and choose a restriction supported by the evidence.

RDAP: Read Domain Data During an Investigation
Use RDAP events, statuses, and contacts to document a suspicious domain without misattributing an identity or claiming an unproven compromise.

DMARC XML Reports: Interpret Authentication Failures
Read aggregate DMARC reports, distinguish alignment from authentication, and prioritize anomalies by sending service and business impact.

SPF Permerror: Fix the DNS Lookup Limit
Trace SPF dependencies, distinguish permerror from fail, and reduce DNS lookups while testing every sending service.

SMTP 550 5.7.1: Find the Cause of an Email Rejection
A 550 5.7.1 rejection can involve recipient policy, authentication, or reputation. Use the full diagnostic and delivery traces to find the cause.

How to Analyze Suspicious Email Headers
Identify trusted servers, interpret Authentication-Results, and investigate a suspicious email without confusing authentication with safe content.

Government Threat Intelligence Procurement: A Practical Guide
Specify a public-sector threat intelligence service with clear evidence, data-handling rules, acceptance tests and an exit plan for UK and European teams.

Local Government Network Security: A 90-Day Council Plan
Build a council network security plan around public services, clear ownership, tested segmentation and useful logs, with practical actions across 90 days.

Protective DNS for the Public Sector: A Deployment Guide
Deploy protective DNS across public-sector sites and remote staff. Test coverage, handle exceptions and keep essential services available during failures.

Public Sector Supplier Remote Access: Control Every Session
Control supplier remote access with named identities, agreed work windows, bounded paths and verified revocation, using a practical public sector example.

School Network Security: Test Segmentation That Works
Plan school network segmentation around teaching needs, test permitted and blocked paths, protect administration, and manage changes without losing access.

CTI Analyst OPSEC: Scan URLs Without Exposing Secrets
Protect CTI investigations before scanning URLs or files: assess public visibility, signed links, hash lookups, and the right environment for sensitive evidence.

CTI Analyst Portfolio: Build a Safe, Reproducible Lab
Build a CTI analyst portfolio with offline datasets, evidence-led assessments, reproducible results, and a review rubric that shows how you make decisions.

Cyber Attribution: Confidence and Competing Hypotheses
Assess cyber attribution with evidence, competing hypotheses, and explicit confidence. Use a practical judgment record without treating an IOC as an identity.

Threat Intelligence PIRs: A Workbook and Collection Plan
Turn threat intelligence requests into useful PIRs with a decision worksheet, collection plan, evidence requirements, ownership, and practical stopping rules.

Diamond Model: A Practical CTI Investigation Walkthrough
Use the Diamond Model to connect evidence, test competing explanations, build activity threads, and turn a phishing investigation into defensible decisions.

IOC Retrohunting: Investigating Historical Logs Reliably
Run reliable IOC retrohunts by separating event time, intelligence availability, and validity, then document historical evidence and the limits of negative results.

Threat Intelligence Feed Poisoning: Protect Your Evidence
Protect CTI decisions from misleading data with source provenance, mirror detection, contradiction handling, safe ingestion, human review, and tested rollback.

Threat Intelligence Feed ROI: Build a Reliable Benchmark
Evaluate threat intelligence feeds with an independent sample, complete operating costs, and a measure of incremental value before buying or renewing a contract.
Expert Threat Intelligence Analysis
Our blog features in-depth analysis from our threat research team. Each article is backed by real data from our analysis of millions of malicious domains, IPs, and URLs across the global threat landscape. Topics include ransomware campaigns, phishing techniques, malware distribution networks, and emerging threat trends. We publish specific intelligence that security teams can immediately use to improve their defenses.
Practical Security Guidance
Beyond threat analysis, we share practical guidance for security practitioners. Our tutorials cover API integration, SIEM configuration, threat hunting techniques, and building effective threat intelligence programs. Whether you're a SOC analyst, security engineer, or CISO, you'll find content tailored to your role and experience level.
Stay Ahead of Emerging Threats
The threat landscape evolves constantly. Our blog keeps you informed about the latest attack techniques, newly discovered vulnerabilities, and emerging threat actors. Subscribe to our newsletter for weekly digests of the most important developments in cybersecurity.
Subscribe to Our Newsletter
Weekly threat intelligence insights delivered to your inbox.
