Skip to main content
Blog

Threat Intelligence Blog

Research, insights, and updates from the isMalicious team. Page 2 of 10.

isMalicious API: Make Your First Reliable IOC Lookup
API2026-09-02

isMalicious API: Make Your First Reliable IOC Lookup

Call the current isMalicious IOC endpoint safely, handle failures, log useful evidence, and move from a terminal test to production.

7 min readRead
TAXII Threat Feeds: Build a Continuous SIEM Integration
Research2026-09-02

TAXII Threat Feeds: Build a Continuous SIEM Integration

Connect an isMalicious TAXII collection to your SIEM with safe pagination, durable checkpoints, validation, monitoring, and recovery.

6 min readRead
Blocklists for Operational Threat Prevention: Test and Roll Back
Research2026-09-02

Blocklists for Operational Threat Prevention: Test and Roll Back

Use /app/blocklists to select, test, deploy, measure, and safely reverse IP or domain prevention controls.

7 min readRead
Threat Report History: Recheck, Monitor, and Reuse Evidence
Research2026-09-02

Threat Report History: Recheck, Monitor, and Reuse Evidence

Use isMalicious report history to find earlier lookups, run fresh checks, add indicators to monitoring, create cases, and export a reusable lookup index.

5 min readRead
Threat Intelligence Sources: Evaluate Evidence Before You Act
Research2026-09-02

Threat Intelligence Sources: Evaluate Evidence Before You Act

Use isMalicious Sources and Threat Patterns to examine freshness, contribution, agreement, coverage, and corpus-wide patterns before turning a detection into action.

5 min readRead
CVE Watch Perimeters: Prioritize Findings by Real Exposure
Research2026-09-02

CVE Watch Perimeters: Prioritize Findings by Real Exposure

Map products to CVE Watch perimeters, then combine active exploitation, CISA KEV, EPSS, CVSS, product context, and remediation status to focus vulnerability work.

5 min readRead
isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers
DNS2026-08-25

isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers

Spamhaus DROP and SBL are the standard for mail and network DNSBL blocking. isMalicious adds REST enrichment, URL scoring, CVE context, and STIX feeds. Most mature stacks use both at different layers.

6 min readRead
GitHub Actions OIDC: Secure Cloud Deployments
Cloud2026-08-24

GitHub Actions OIDC: Secure Cloud Deployments

Replace long-lived cloud secrets with GitHub Actions OIDC while constraining claims, permissions, environments, reusable workflows, and incident response.

4 min readRead
Kubernetes Audit Logs: Threat Detection Guide
Research2026-08-24

Kubernetes Audit Logs: Threat Detection Guide

Turn Kubernetes audit logs into detections for privilege abuse, secret access, persistence, risky exec, and control-plane compromise.

4 min readRead
eBPF Runtime Security for Kubernetes
Research2026-08-24

eBPF Runtime Security for Kubernetes

Use eBPF runtime security to observe processes, files, privileges, and network activity in Kubernetes while controlling noise and enforcement risk.

4 min readRead
Sigstore and Cosign: Verify Container Images
AI & ML2026-08-24

Sigstore and Cosign: Verify Container Images

Sign and verify container images with Cosign, keyless identities, transparency evidence, digest pinning, and admission policies that check the signer.

4 min readRead
SLSA Provenance: Verify the Software Supply Chain
Supply Chain2026-08-24

SLSA Provenance: Verify the Software Supply Chain

Use SLSA provenance to trace artifacts to source and build systems, verify expectations, improve CI controls, and respond to tampering.

4 min readRead
Malicious PyPI Packages: Detect Supply-Chain Attacks
Supply Chain2026-08-24

Malicious PyPI Packages: Detect Supply-Chain Attacks

Detect malicious PyPI packages through provenance, dependency controls, install behavior, network telemetry, hashes, and a Python incident playbook.

3 min readRead
YARA vs Sigma: Which Detection Rule Should You Use?
Research2026-08-24

YARA vs Sigma: Which Detection Rule Should You Use?

Compare YARA and Sigma by data source, purpose, portability, performance, false positives, testing, and threat-intelligence workflow.

4 min readRead
MFA Fatigue: Stop Push-Bombing Attacks
Research2026-08-24

MFA Fatigue: Stop Push-Bombing Attacks

Detect and prevent MFA fatigue with number matching, rate limits, risk signals, phishing-resistant authentication, and an identity incident playbook.

3 min readRead
HTML Smuggling: Detection and Incident Response
Incident Response2026-08-24

HTML Smuggling: Detection and Incident Response

Detect HTML smuggling by correlating browser file creation, JavaScript Blob behavior, download telemetry, endpoint execution, and threat intelligence.

3 min readRead
Browser-in-the-Browser Phishing: Detection Guide
Phishing2026-08-24

Browser-in-the-Browser Phishing: Detection Guide

Understand browser-in-the-browser phishing, spot fake SSO windows, detect campaign infrastructure, and reduce risk with phishing-resistant authentication.

4 min readRead
Subdomain Takeover: Find Dangling DNS First
DNS2026-08-24

Subdomain Takeover: Find Dangling DNS First

Prevent subdomain takeover by finding dangling DNS records, linking names to cloud owners, monitoring certificates, and fixing decommissioning order.

4 min readRead
Bulletproof Hosting: Map Criminal Infrastructure
Research2026-08-24

Bulletproof Hosting: Map Criminal Infrastructure

Identify bulletproof hosting through ASN, prefix, domain, abuse, migration, and campaign signals without treating an entire network as malicious.

4 min readRead
Domain Shadowing: Detect Compromised DNS at Scale
DNS2026-08-24

Domain Shadowing: Detect Compromised DNS at Scale

Detect domain shadowing by monitoring DNS changes, certificate issuance, subdomain behavior, account security, and infrastructure relationships.

4 min readRead
JA4 TLS Fingerprinting for Threat Hunting
Research2026-08-24

JA4 TLS Fingerprinting for Threat Hunting

Use JA4 TLS fingerprints for threat hunting, malware clustering, allowlisting, and anomaly detection without treating a fingerprint as identity.

4 min readRead
DNS over HTTPS Security: Detect DoH Abuse
DNS2026-08-24

DNS over HTTPS Security: Detect DoH Abuse

Secure DNS over HTTPS without losing visibility: govern resolvers, detect bypass attempts, correlate endpoint telemetry, and preserve user privacy.

4 min readRead
Certificate Transparency for Phishing Detection
Security2026-08-24

Certificate Transparency for Phishing Detection

Use Certificate Transparency logs to find rogue certificates, phishing subdomains, brand impersonation, and exposed assets before they become incidents.

4 min readRead
IPv6 Threat Intelligence: Reputation Beyond IPv4
Research2026-08-24

IPv6 Threat Intelligence: Reputation Beyond IPv4

Build IPv6 threat intelligence with correct normalization, prefix context, dual-stack logging, enrichment, and reputation decisions that avoid overblocking.

4 min readRead

Subscribe to Our Newsletter

Weekly threat intelligence insights delivered to your inbox.