Skip to main content
Tag

IOC

7 articles on IOC.

← All blog posts
IOC Expiration: When to Remove an IP From a Blocklist
Threat Intel2026-09-09

IOC Expiration: When to Remove an IP From a Blocklist

Manage IOC expiration with separate DNS, evidence and STIX validity clocks. Review stale IP blocks, process withdrawals and preserve the audit trail.

6 min read
Investigate an IOC Alert: Link IP, DNS and Process Logs
Threat Intel2026-09-09

Investigate an IOC Alert: Link IP, DNS and Process Logs

An IOC match is an investigation lead. Correlate DNS, network connections and process records to establish what happened on the endpoint.

6 min read
Threat Intelligence Platforms: Architecture, Data Quality, and High-Signal Feeds
Threat Intel2026-04-26

Threat Intelligence Platforms: Architecture, Data Quality, and High-Signal Feeds

Design TIPs and intel pipelines that scale: normalization, confidence scoring, deduplication, API-first delivery, and how to pair platform investments with analyst workflows.

8 min read
Building IOC Pipelines: From Raw Indicators to Operational Threat Intelligence in 2026
Threat Intel2026-04-26

Building IOC Pipelines: From Raw Indicators to Operational Threat Intelligence in 2026

A practical engineering guide to building indicator of compromise (IOC) pipelines—ingestion, normalization, deduplication, enrichment, scoring, distribution, and feedback—to turn raw threat feeds into operational defense.

10 min read
Operational Threat Intelligence: Turning IOCs into Prioritized Security Actions
Threat Intel2026-04-19

Operational Threat Intelligence: Turning IOCs into Prioritized Security Actions

Define operational CTI that SOC teams can use daily: IOC lifecycle, confidence scoring, feed hygiene, and how to align indicators with detection engineering and incident response.

8 min read
File Hash Check: Is This SHA-256 Malware?
Malware2026-04-18

File Hash Check: Is This SHA-256 Malware?

How to check MD5, SHA-1, and SHA-256 hashes against threat intelligence, and how SOC teams use hash reputation to cut false positives.

8 min read
File Hash Analysis: MD5, SHA-1, and SHA-256 for Malware Detection and Threat Hunting
Malware2026-04-18

File Hash Analysis: MD5, SHA-1, and SHA-256 for Malware Detection and Threat Hunting

A practical guide to file hashes in cybersecurity—how MD5, SHA-1, and SHA-256 work, why they matter for malware detection, incident response, and threat hunting, and how to use hash lookups to enrich indicators of compromise.

9 min read