Skip to main content
Tag

Threat intelligence

80 articles on threat intelligence.

← All blog posts
Parked Domains: Assess the Risk Before Blocking
Phishing11 h ago

Parked Domains: Assess the Risk Before Blocking

Distinguish domain parking, expiration, and malicious behavior. Examine actual use and choose a restriction supported by the evidence.

5 min read
RDAP: Read Domain Data During an Investigation
Threat Intel1 d ago

RDAP: Read Domain Data During an Investigation

Use RDAP events, statuses, and contacts to document a suspicious domain without misattributing an identity or claiming an unproven compromise.

5 min read
School Network Security: Test Segmentation That Works
Research2026-09-18

School Network Security: Test Segmentation That Works

Plan school network segmentation around teaching needs, test permitted and blocked paths, protect administration, and manage changes without losing access.

10 min read
CTI Analyst Portfolio: Build a Safe, Reproducible Lab
Threat Intel2026-09-17

CTI Analyst Portfolio: Build a Safe, Reproducible Lab

Build a CTI analyst portfolio with offline datasets, evidence-led assessments, reproducible results, and a review rubric that shows how you make decisions.

11 min read
Cyber Attribution: Confidence and Competing Hypotheses
Threat Intel2026-09-17

Cyber Attribution: Confidence and Competing Hypotheses

Assess cyber attribution with evidence, competing hypotheses, and explicit confidence. Use a practical judgment record without treating an IOC as an identity.

11 min read
Threat Intelligence PIRs: A Workbook and Collection Plan
Threat Intel2026-09-17

Threat Intelligence PIRs: A Workbook and Collection Plan

Turn threat intelligence requests into useful PIRs with a decision worksheet, collection plan, evidence requirements, ownership, and practical stopping rules.

10 min read
Diamond Model: A Practical CTI Investigation Walkthrough
Threat Intel2026-09-17

Diamond Model: A Practical CTI Investigation Walkthrough

Use the Diamond Model to connect evidence, test competing explanations, build activity threads, and turn a phishing investigation into defensible decisions.

11 min read
Threat Intelligence Feed Poisoning: Protect Your Evidence
Threat Intel2026-09-17

Threat Intelligence Feed Poisoning: Protect Your Evidence

Protect CTI decisions from misleading data with source provenance, mirror detection, contradiction handling, safe ingestion, human review, and tested rollback.

10 min read
TLP 2.0: Share Threat Intelligence Without Leaking Data
Threat Intel2026-09-17

TLP 2.0: Share Threat Intelligence Without Leaking Data

Apply TLP 2.0 to CTI reports, indicators, and supplier exchanges with practical sharing boundaries, permission checks, data minimization, and export controls.

10 min read
IOC Expiration: When to Remove an IP From a Blocklist
Threat Intel2026-09-09

IOC Expiration: When to Remove an IP From a Blocklist

Manage IOC expiration with separate DNS, evidence and STIX validity clocks. Review stale IP blocks, process withdrawals and preserve the audit trail.

6 min read
Domain Reputation Monitoring: Which Changes Need Action?
DNS2026-09-09

Domain Reputation Monitoring: Which Changes Need Action?

Track domain reputation over time: distinguish a new phishing report from expected DNS changes, then decide what to verify before restricting access.

6 min read
Smart Lookup: Check Any Threat Indicator from One Search
Threat Intel2026-09-02

Smart Lookup: Check Any Threat Indicator from One Search

Paste an IP, domain, URL, email, phone number, wallet, file hash, or a complete suspicious message. Smart Lookup routes each indicator to the right threat report.

5 min read
Composite Threat Reports: Triage Multiple IOCs Together
Threat Intel2026-09-02

Composite Threat Reports: Triage Multiple IOCs Together

A phishing message or security alert rarely contains one indicator. Use a composite threat report to scope several IOCs without losing the evidence behind each result.

5 min read
Threats Dashboard: Turn Current Intelligence into Priorities
Threat Intel2026-09-02

Threats Dashboard: Turn Current Intelligence into Priorities

Use the isMalicious Threats dashboard to move from a broad threat picture to the sectors, ransomware groups, malware, victims, and evidence that matter to your team.

5 min read
TAXII Threat Feeds: Build a Continuous SIEM Integration
Threat Intel2026-09-02

TAXII Threat Feeds: Build a Continuous SIEM Integration

Connect an isMalicious TAXII collection to your SIEM with safe pagination, durable checkpoints, validation, monitoring, and recovery.

6 min read
Blocklists for Operational Threat Prevention: Test and Roll Back
Threat Intel2026-09-02

Blocklists for Operational Threat Prevention: Test and Roll Back

Use /app/blocklists to select, test, deploy, measure, and safely reverse IP or domain prevention controls.

7 min read
Threat Intelligence Sources: Evaluate Evidence Before You Act
Threat Intel2026-09-02

Threat Intelligence Sources: Evaluate Evidence Before You Act

Use isMalicious Sources and Threat Patterns to examine freshness, contribution, agreement, coverage, and corpus-wide patterns before turning a detection into action.

5 min read
isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers
Threat Intel2026-08-25

isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers

Spamhaus DROP and SBL are the standard for mail and network DNSBL blocking. isMalicious adds REST enrichment, URL scoring, CVE context, and STIX feeds. Most mature stacks use both at different layers.

6 min read
Malicious PyPI Packages: Detect Supply-Chain Attacks
Supply Chain2026-08-24

Malicious PyPI Packages: Detect Supply-Chain Attacks

Detect malicious PyPI packages through provenance, dependency controls, install behavior, network telemetry, hashes, and a Python incident playbook.

3 min read
Bulletproof Hosting: Map Criminal Infrastructure
Threat Intel2026-08-24

Bulletproof Hosting: Map Criminal Infrastructure

Identify bulletproof hosting through ASN, prefix, domain, abuse, migration, and campaign signals without treating an entire network as malicious.

4 min read
Domain Shadowing: Detect Compromised DNS at Scale
DNS2026-08-24

Domain Shadowing: Detect Compromised DNS at Scale

Detect domain shadowing by monitoring DNS changes, certificate issuance, subdomain behavior, account security, and infrastructure relationships.

4 min read
JA4 TLS Fingerprinting for Threat Hunting
SOC2026-08-24

JA4 TLS Fingerprinting for Threat Hunting

Use JA4 TLS fingerprints for threat hunting, malware clustering, allowlisting, and anomaly detection without treating a fingerprint as identity.

4 min read
Certificate Transparency for Phishing Detection
Phishing2026-08-24

Certificate Transparency for Phishing Detection

Use Certificate Transparency logs to find rogue certificates, phishing subdomains, brand impersonation, and exposed assets before they become incidents.

4 min read
IPv6 Threat Intelligence: Reputation Beyond IPv4
Threat Intel2026-08-24

IPv6 Threat Intelligence: Reputation Beyond IPv4

Build IPv6 threat intelligence with correct normalization, prefix context, dual-stack logging, enrichment, and reputation decisions that avoid overblocking.

4 min read