Skip to main content
Tag

IOC enrichment

30 articles on IOC enrichment.

← All blog posts
RDAP: Read Domain Data During an Investigation
Threat Intel1 d ago

RDAP: Read Domain Data During an Investigation

Use RDAP events, statuses, and contacts to document a suspicious domain without misattributing an identity or claiming an unproven compromise.

5 min read
Smart Lookup: Check Any Threat Indicator from One Search
Threat Intel2026-09-02

Smart Lookup: Check Any Threat Indicator from One Search

Paste an IP, domain, URL, email, phone number, wallet, file hash, or a complete suspicious message. Smart Lookup routes each indicator to the right threat report.

5 min read
isMalicious API: Make Your First Reliable IOC Lookup
API2026-09-02

isMalicious API: Make Your First Reliable IOC Lookup

Call the current isMalicious IOC endpoint safely, handle failures, log useful evidence, and move from a terminal test to production.

7 min read
Threat Report History: Recheck, Monitor, and Reuse Evidence
Threat Intel2026-09-02

Threat Report History: Recheck, Monitor, and Reuse Evidence

Use isMalicious report history to find earlier lookups, run fresh checks, add indicators to monitoring, create cases, and export a reusable lookup index.

5 min read
Threat Intelligence Sources: Evaluate Evidence Before You Act
Threat Intel2026-09-02

Threat Intelligence Sources: Evaluate Evidence Before You Act

Use isMalicious Sources and Threat Patterns to examine freshness, contribution, agreement, coverage, and corpus-wide patterns before turning a detection into action.

5 min read
isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers
Threat Intel2026-08-25

isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers

Spamhaus DROP and SBL are the standard for mail and network DNSBL blocking. isMalicious adds REST enrichment, URL scoring, CVE context, and STIX feeds. Most mature stacks use both at different layers.

6 min read
isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs
Threat Intel2026-08-24

isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs

Censys maps what exists on the internet — hosts, certificates, open ports. isMalicious assesses what is malicious. Most teams comparing the two need the second question answered, not the first.

5 min read
isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program
Threat Intel2026-08-22

isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program

Recorded Future delivers finished intelligence and analyst support at enterprise scale. isMalicious delivers self-serve enrichment and feeds without a sales cycle. The right choice depends on whether you need strategic reports or automated verdicts.

6 min read
CVE-2026-9198 Gives Unauthenticated RCE in IBM Langflow OSS Agent Control Planes
Vulnerabilities2026-08-17

CVE-2026-9198 Gives Unauthenticated RCE in IBM Langflow OSS Agent Control Planes

A SUPERUSER token minted through /api/v1/auto_login chains with Python exec() in /api/v1/validate/code. Langflow 1.10.1 fixes the flaw — but internet-exposed instances need hunting now, not after the next sprint.

7 min read
INC Ransomware Chains Two SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410)
Ransomware2026-08-16

INC Ransomware Chains Two SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410)

INC affiliates are weaponizing an SSRF and a post-authentication code injection in SonicWall SMA 1000 to reach internal networks. Exploitation started weeks before the July 14 patch — here is how to hunt and triage.

7 min read
isMalicious vs SecurityTrails: Discovery Data and Reputation Verdicts Are Not the Same Product
Threat Intel2026-08-15

isMalicious vs SecurityTrails: Discovery Data and Reputation Verdicts Are Not the Same Product

SecurityTrails tells you what exists — every subdomain, every historical DNS record. isMalicious tells you what is dangerous. Most teams searching for a SecurityTrails alternative want the second half.

6 min read
isMalicious vs IPQualityScore: Fraud Scoring and Threat Intelligence Are Different Jobs
Threat Intel2026-08-14

isMalicious vs IPQualityScore: Fraud Scoring and Threat Intelligence Are Different Jobs

IPQS scores whether a signup is fraudulent. isMalicious scores whether infrastructure is malicious. The two get compared constantly because both return a number about an IP address — and they answer different questions.

6 min read
isMalicious vs MISP: Why This Is the Wrong Comparison (and What to Compare Instead)
Threat Intel2026-08-13

isMalicious vs MISP: Why This Is the Wrong Comparison (and What to Compare Instead)

MISP is where you store and share indicators. isMalicious is where indicators come from. Teams searching for a MISP alternative are usually looking for a feed, not a replacement platform.

6 min read
isMalicious vs Cisco Talos: Reputation Lookups Outside the Cisco Stack
Threat Intel2026-08-12

isMalicious vs Cisco Talos: Reputation Lookups Outside the Cisco Stack

Talos reputation is excellent and it lives inside Cisco products. If your stack is not Cisco, or you need an API rather than a web form, that is where the comparison starts.

6 min read
Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume
Threat Intel2026-08-11

Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume

One incident produces hundreds of indicators, and per-indicator lookups are where triage stalls. Here is how to build a batch enrichment pipeline that respects quotas, deduplicates properly, and fails gracefully.

7 min read
Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting
SOC2026-08-10

Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting

A reverse IP lookup turns one indicator into a cluster — or into a thousand innocent neighbours. Here is how to tell the difference, and how to pivot on hosting infrastructure without generating false positives.

7 min read
WHOIS Lookup for Security Investigations: Reading a Record After Redaction
Phishing2026-08-09

WHOIS Lookup for Security Investigations: Reading a Record After Redaction

Privacy services stripped the registrant name out of most WHOIS records, but the fields that matter for triage survived. Here is what a WHOIS record still tells an analyst, and how to read it.

7 min read
The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There
Phishing2026-08-08

The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There

German and US law enforcement dismantled Kratos, the AiTM phishing service behind roughly 15,000 Microsoft 365 campaigns a month. The infrastructure is offline, but the kit is not. Here is what to hunt for now.

7 min read
Cl0p Is Exploiting PTC Windchill (CVE-2026-12569) to Steal Engineering Data
Ransomware2026-08-06

Cl0p Is Exploiting PTC Windchill (CVE-2026-12569) to Steal Engineering Data

A Cl0p affiliate is chaining a FlexPLM information disclosure with an unauthenticated RCE in PTC Windchill to plant JSP web shells and run double-extortion data theft. Here are the detection signals and the triage workflow.

7 min read
Infostealer Log Marketplaces: How Stolen Corporate Credentials End Up for Sale
Malware2026-08-04

Infostealer Log Marketplaces: How Stolen Corporate Credentials End Up for Sale

Stealer-log marketplaces are booming in 2026, trading stolen corporate cookies, passwords, and SaaS sessions that fuel ransomware access and bypass MFA.

6 min read
Subdomain Enumeration for Security Teams: Attack Surface Discovery and DNS Reconnaissance
DNS2026-08-02

Subdomain Enumeration for Security Teams: Attack Surface Discovery and DNS Reconnaissance

Subdomain enumeration surfaces forgotten dev servers, dangling DNS, and shadow IT before attackers do. Passive and active recon techniques compared.

6 min read
isMalicious vs GreyNoise: IP Noise Scoring and Threat Intelligence API Compared
Threat Intel2026-07-27

isMalicious vs GreyNoise: IP Noise Scoring and Threat Intelligence API Compared

GreyNoise tags internet background noise; isMalicious adds verdicts, WHOIS, DNS history, and ransomware context. A SOC-focused comparison for triage teams.

6 min read
Agentic AI Threat Mapping: MITRE ATT&CK Needs Evidence-Rich Workflows
AI & ML2026-07-08

Agentic AI Threat Mapping: MITRE ATT&CK Needs Evidence-Rich Workflows

Anthropic mapped AI-enabled cyber activity to MITRE ATT&CK and found gaps around autonomous orchestration. SOC teams need AI summaries tied to evidence, not unsupported verdicts.

4 min read
AMOS macOS Infostealer: ClickFix Shows Why Hash Reputation Must Cover Developer Macs
Malware2026-07-05

AMOS macOS Infostealer: ClickFix Shows Why Hash Reputation Must Cover Developer Macs

AMOS and related macOS infostealers are turning social engineering into credential theft. File hash reputation, URL scanning, and domain intelligence help teams respond before stolen tokens spread.

3 min read