Skip to main content
Tag

SOC

49 articles on SOC.

← All blog posts
Parked Domains: Assess the Risk Before Blocking
Phishing8 h ago

Parked Domains: Assess the Risk Before Blocking

Distinguish domain parking, expiration, and malicious behavior. Examine actual use and choose a restriction supported by the evidence.

5 min read
RDAP: Read Domain Data During an Investigation
Threat Intel1 d ago

RDAP: Read Domain Data During an Investigation

Use RDAP events, statuses, and contacts to document a suspicious domain without misattributing an identity or claiming an unproven compromise.

5 min read
DMARC XML Reports: Interpret Authentication Failures
Email Security2 d ago

DMARC XML Reports: Interpret Authentication Failures

Read aggregate DMARC reports, distinguish alignment from authentication, and prioritize anomalies by sending service and business impact.

5 min read
How to Analyze Suspicious Email Headers
Phishing5 d ago

How to Analyze Suspicious Email Headers

Identify trusted servers, interpret Authentication-Results, and investigate a suspicious email without confusing authentication with safe content.

5 min read
Diamond Model: A Practical CTI Investigation Walkthrough
Threat Intel2026-09-17

Diamond Model: A Practical CTI Investigation Walkthrough

Use the Diamond Model to connect evidence, test competing explanations, build activity threads, and turn a phishing investigation into defensible decisions.

11 min read
Threat Intelligence Feed Poisoning: Protect Your Evidence
Threat Intel2026-09-17

Threat Intelligence Feed Poisoning: Protect Your Evidence

Protect CTI decisions from misleading data with source provenance, mirror detection, contradiction handling, safe ingestion, human review, and tested rollback.

10 min read
TLP 2.0: Share Threat Intelligence Without Leaking Data
Threat Intel2026-09-17

TLP 2.0: Share Threat Intelligence Without Leaking Data

Apply TLP 2.0 to CTI reports, indicators, and supplier exchanges with practical sharing boundaries, permission checks, data minimization, and export controls.

10 min read
Investigate an IOC Alert: Link IP, DNS and Process Logs
Threat Intel2026-09-09

Investigate an IOC Alert: Link IP, DNS and Process Logs

An IOC match is an investigation lead. Correlate DNS, network connections and process records to establish what happened on the endpoint.

6 min read
IP Blacklisted? Check for a False Positive Before Blocking
SOC2026-09-09

IP Blacklisted? Check for a False Positive Before Blocking

Check DNSBL scope, shared IPs, stale evidence and lookup errors to find why an IP was blacklisted and choose a proportionate response.

6 min read
Smart Lookup: Check Any Threat Indicator from One Search
Threat Intel2026-09-02

Smart Lookup: Check Any Threat Indicator from One Search

Paste an IP, domain, URL, email, phone number, wallet, file hash, or a complete suspicious message. Smart Lookup routes each indicator to the right threat report.

5 min read
Composite Threat Reports: Triage Multiple IOCs Together
Threat Intel2026-09-02

Composite Threat Reports: Triage Multiple IOCs Together

A phishing message or security alert rarely contains one indicator. Use a composite threat report to scope several IOCs without losing the evidence behind each result.

5 min read
Threats Dashboard: Turn Current Intelligence into Priorities
Threat Intel2026-09-02

Threats Dashboard: Turn Current Intelligence into Priorities

Use the isMalicious Threats dashboard to move from a broad threat picture to the sectors, ransomware groups, malware, victims, and evidence that matter to your team.

5 min read
Threat Alerts and Action Center: Build a Response Workflow
Incident Response2026-09-02

Threat Alerts and Action Center: Build a Response Workflow

Move from monitored indicators and incoming alerts to a ranked queue, analyst validation, and owned response work with isMalicious Alerts and Action Center.

5 min read
isMalicious API: Make Your First Reliable IOC Lookup
API2026-09-02

isMalicious API: Make Your First Reliable IOC Lookup

Call the current isMalicious IOC endpoint safely, handle failures, log useful evidence, and move from a terminal test to production.

7 min read
Threat Report History: Recheck, Monitor, and Reuse Evidence
Threat Intel2026-09-02

Threat Report History: Recheck, Monitor, and Reuse Evidence

Use isMalicious report history to find earlier lookups, run fresh checks, add indicators to monitoring, create cases, and export a reusable lookup index.

5 min read
Threat Intelligence Sources: Evaluate Evidence Before You Act
Threat Intel2026-09-02

Threat Intelligence Sources: Evaluate Evidence Before You Act

Use isMalicious Sources and Threat Patterns to examine freshness, contribution, agreement, coverage, and corpus-wide patterns before turning a detection into action.

5 min read
isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers
Threat Intel2026-08-25

isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers

Spamhaus DROP and SBL are the standard for mail and network DNSBL blocking. isMalicious adds REST enrichment, URL scoring, CVE context, and STIX feeds. Most mature stacks use both at different layers.

6 min read
IPv6 Threat Intelligence: Reputation Beyond IPv4
Threat Intel2026-08-24

IPv6 Threat Intelligence: Reputation Beyond IPv4

Build IPv6 threat intelligence with correct normalization, prefix context, dual-stack logging, enrichment, and reputation decisions that avoid overblocking.

4 min read
Fast-Flux DNS: Detect Rotating Attack Infrastructure
DNS2026-08-24

Fast-Flux DNS: Detect Rotating Attack Infrastructure

Learn how to detect fast-flux DNS using TTL, passive DNS, ASN diversity, reputation signals, and a repeatable SOC investigation workflow.

4 min read
isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs
Threat Intel2026-08-24

isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs

Censys maps what exists on the internet — hosts, certificates, open ports. isMalicious assesses what is malicious. Most teams comparing the two need the second question answered, not the first.

5 min read
isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)
Threat Intel2026-08-23

isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)

OpenCTI is a threat intelligence platform and knowledge graph. isMalicious is a data provider that feeds it. Teams searching for an OpenCTI alternative usually need a feed, not a replacement TIP.

6 min read
isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program
Threat Intel2026-08-22

isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program

Recorded Future delivers finished intelligence and analyst support at enterprise scale. isMalicious delivers self-serve enrichment and feeds without a sales cycle. The right choice depends on whether you need strategic reports or automated verdicts.

6 min read
Firewall Blocklist Automation: Pulling IP and Domain Feeds Without Outages
Threat Intel2026-08-21

Firewall Blocklist Automation: Pulling IP and Domain Feeds Without Outages

External dynamic lists can block malware and phishing at the edge — or break payroll, CDN traffic, and vendor portals. This guide covers staged rollout, allowlists, fail-open vs fail-closed, and measuring hit rates for IP and domain blocklists.

8 min read
How to Use an NRD Feed to Catch Phishing Before It Lands in the Inbox
Phishing2026-08-19

How to Use an NRD Feed to Catch Phishing Before It Lands in the Inbox

Newly registered domains are where most phishing campaigns start. This guide walks through NRD feed workflows for brand monitoring, mail gateway hygiene, and SOC triage — without treating domain age as a blunt block rule.

8 min read