Skip to main content
Tag

Threat intelligence

80 articles on threat intelligence. Page 2 of 4.

← All blog posts
Residential Proxy Abuse: Detect Fraud Without Blocking Users
Bot Detection2026-08-24

Residential Proxy Abuse: Detect Fraud Without Blocking Users

Detect residential proxy abuse by combining IP reputation, identity, velocity, device, and behavioral signals without penalizing legitimate users.

4 min read
DGA Detection: Find Algorithmically Generated Domains
DNS2026-08-24

DGA Detection: Find Algorithmically Generated Domains

Detect domain generation algorithms with lexical, DNS, endpoint, and reputation signals while controlling false positives in production.

4 min read
Fast-Flux DNS: Detect Rotating Attack Infrastructure
DNS2026-08-24

Fast-Flux DNS: Detect Rotating Attack Infrastructure

Learn how to detect fast-flux DNS using TTL, passive DNS, ASN diversity, reputation signals, and a repeatable SOC investigation workflow.

4 min read
isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs
Threat Intel2026-08-24

isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs

Censys maps what exists on the internet — hosts, certificates, open ports. isMalicious assesses what is malicious. Most teams comparing the two need the second question answered, not the first.

5 min read
isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)
Threat Intel2026-08-23

isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)

OpenCTI is a threat intelligence platform and knowledge graph. isMalicious is a data provider that feeds it. Teams searching for an OpenCTI alternative usually need a feed, not a replacement TIP.

6 min read
isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program
Threat Intel2026-08-22

isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program

Recorded Future delivers finished intelligence and analyst support at enterprise scale. isMalicious delivers self-serve enrichment and feeds without a sales cycle. The right choice depends on whether you need strategic reports or automated verdicts.

6 min read
Firewall Blocklist Automation: Pulling IP and Domain Feeds Without Outages
Threat Intel2026-08-21

Firewall Blocklist Automation: Pulling IP and Domain Feeds Without Outages

External dynamic lists can block malware and phishing at the edge — or break payroll, CDN traffic, and vendor portals. This guide covers staged rollout, allowlists, fail-open vs fail-closed, and measuring hit rates for IP and domain blocklists.

8 min read
STIX/TAXII Threat Feeds: Operational Guide for OpenCTI, MISP, and SIEM Pipelines
Threat Intel2026-08-20

STIX/TAXII Threat Feeds: Operational Guide for OpenCTI, MISP, and SIEM Pipelines

How to wire STIX 2.1 and TAXII 2.1 collections into OpenCTI, MISP, or your SIEM — what to poll, how to handle confidence and aging indicators, and where enrichment APIs fit alongside feed ingestion.

9 min read
How to Use an NRD Feed to Catch Phishing Before It Lands in the Inbox
Phishing2026-08-19

How to Use an NRD Feed to Catch Phishing Before It Lands in the Inbox

Newly registered domains are where most phishing campaigns start. This guide walks through NRD feed workflows for brand monitoring, mail gateway hygiene, and SOC triage — without treating domain age as a blunt block rule.

8 min read
isMalicious vs SecurityTrails: Discovery Data and Reputation Verdicts Are Not the Same Product
Threat Intel2026-08-15

isMalicious vs SecurityTrails: Discovery Data and Reputation Verdicts Are Not the Same Product

SecurityTrails tells you what exists — every subdomain, every historical DNS record. isMalicious tells you what is dangerous. Most teams searching for a SecurityTrails alternative want the second half.

6 min read
isMalicious vs IPQualityScore: Fraud Scoring and Threat Intelligence Are Different Jobs
Threat Intel2026-08-14

isMalicious vs IPQualityScore: Fraud Scoring and Threat Intelligence Are Different Jobs

IPQS scores whether a signup is fraudulent. isMalicious scores whether infrastructure is malicious. The two get compared constantly because both return a number about an IP address — and they answer different questions.

6 min read
isMalicious vs MISP: Why This Is the Wrong Comparison (and What to Compare Instead)
Threat Intel2026-08-13

isMalicious vs MISP: Why This Is the Wrong Comparison (and What to Compare Instead)

MISP is where you store and share indicators. isMalicious is where indicators come from. Teams searching for a MISP alternative are usually looking for a feed, not a replacement platform.

6 min read
isMalicious vs Cisco Talos: Reputation Lookups Outside the Cisco Stack
Threat Intel2026-08-12

isMalicious vs Cisco Talos: Reputation Lookups Outside the Cisco Stack

Talos reputation is excellent and it lives inside Cisco products. If your stack is not Cisco, or you need an API rather than a web form, that is where the comparison starts.

6 min read
Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume
Threat Intel2026-08-11

Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume

One incident produces hundreds of indicators, and per-indicator lookups are where triage stalls. Here is how to build a batch enrichment pipeline that respects quotas, deduplicates properly, and fails gracefully.

7 min read
Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting
SOC2026-08-10

Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting

A reverse IP lookup turns one indicator into a cluster — or into a thousand innocent neighbours. Here is how to tell the difference, and how to pivot on hosting infrastructure without generating false positives.

7 min read
WHOIS Lookup for Security Investigations: Reading a Record After Redaction
Phishing2026-08-09

WHOIS Lookup for Security Investigations: Reading a Record After Redaction

Privacy services stripped the registrant name out of most WHOIS records, but the fields that matter for triage survived. Here is what a WHOIS record still tells an analyst, and how to read it.

7 min read
The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There
Phishing2026-08-08

The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There

German and US law enforcement dismantled Kratos, the AiTM phishing service behind roughly 15,000 Microsoft 365 campaigns a month. The infrastructure is offline, but the kit is not. Here is what to hunt for now.

7 min read
Subdomain Enumeration for Security Teams: Attack Surface Discovery and DNS Reconnaissance
DNS2026-08-02

Subdomain Enumeration for Security Teams: Attack Surface Discovery and DNS Reconnaissance

Subdomain enumeration surfaces forgotten dev servers, dangling DNS, and shadow IT before attackers do. Passive and active recon techniques compared.

6 min read
China Edge Device Campaigns: Passive DNS And Certificates For Early Warning
Threat Intel2026-07-11

China Edge Device Campaigns: Passive DNS And Certificates For Early Warning

Dutch intelligence warnings about Chinese cyber capability reinforce a practical defense priority: monitor edge devices, VPNs, routers, DNS history, and certificate reuse.

3 min read
Agentic AI Threat Mapping: MITRE ATT&CK Needs Evidence-Rich Workflows
AI & ML2026-07-08

Agentic AI Threat Mapping: MITRE ATT&CK Needs Evidence-Rich Workflows

Anthropic mapped AI-enabled cyber activity to MITRE ATT&CK and found gaps around autonomous orchestration. SOC teams need AI summaries tied to evidence, not unsupported verdicts.

4 min read
SOC Alert Fatigue In July 2026: Confidence Scoring Beats More Noise
SOC2026-07-07

SOC Alert Fatigue In July 2026: Confidence Scoring Beats More Noise

Vectra AI research shows alert overload remains a resilience problem. SOC teams need source quality, confidence scoring, enrichment, and SIEM workflows that suppress noise without hiding risk.

4 min read
AI-Enabled Cyberattacks and MITRE ATT&CK: Turning New Threat Maps Into SOC Action
AI & ML2026-06-04

AI-Enabled Cyberattacks and MITRE ATT&CK: Turning New Threat Maps Into SOC Action

AI-enabled threats are being mapped into ATT&CK language, but mapping is only useful when it drives enrichment, detection, triage, and response workflows.

8 min read
Cyber Extortion Now Includes Physical Threats: What Incident Response Teams Must Change
Ransomware2026-06-04

Cyber Extortion Now Includes Physical Threats: What Incident Response Teams Must Change

Cyber incidents are no longer always contained to systems and data. As extortion crews add physical threats, responders need ransomware intelligence, safety escalation, IOC enrichment, and executive-ready evidence.

8 min read
SOC Alert Fatigue: How Threat Intelligence Reduces False Positives Without Hiding Real Attacks
SOC2026-06-04

SOC Alert Fatigue: How Threat Intelligence Reduces False Positives Without Hiding Real Attacks

Alert fatigue is not a staffing problem alone. SOC teams need better evidence, source quality, confidence bands, and enrichment workflows that turn noisy alerts into defensible decisions.

8 min read