Skip to main content
Tag

incident response

38 articles on incident response.

← All blog posts
How to Analyze Suspicious Email Headers
AI & MLSep 30, 2026

How to Analyze Suspicious Email Headers

Identify trusted servers, interpret Authentication-Results, and investigate a suspicious email without confusing authentication with safe content.

5 min read
Investigate an IOC Alert: Link IP, DNS and Process Logs
DNSSep 9, 2026

Investigate an IOC Alert: Link IP, DNS and Process Logs

An IOC match is an investigation lead. Correlate DNS, network connections and process records to establish what happened on the endpoint.

6 min read
Smart Lookup: Check Any Threat Indicator from One Search
ResearchSep 2, 2026

Smart Lookup: Check Any Threat Indicator from One Search

Paste an IP, domain, URL, email, phone number, wallet, file hash, or a complete suspicious message. Smart Lookup routes each indicator to the right threat report.

5 min read
Composite Threat Reports: Triage Multiple IOCs Together
ResearchSep 2, 2026

Composite Threat Reports: Triage Multiple IOCs Together

A phishing message or security alert rarely contains one indicator. Use a composite threat report to scope several IOCs without losing the evidence behind each result.

5 min read
Threats Dashboard: Turn Current Intelligence into Priorities
ResearchSep 2, 2026

Threats Dashboard: Turn Current Intelligence into Priorities

Use the isMalicious Threats dashboard to move from a broad threat picture to the sectors, ransomware groups, malware, victims, and evidence that matter to your team.

5 min read
Threat Alerts and Action Center: Build a Response Workflow
ResearchSep 2, 2026

Threat Alerts and Action Center: Build a Response Workflow

Move from monitored indicators and incoming alerts to a ranked queue, analyst validation, and owned response work with isMalicious Alerts and Action Center.

5 min read
isMalicious API: Make Your First Reliable IOC Lookup
APISep 2, 2026

isMalicious API: Make Your First Reliable IOC Lookup

Call the current isMalicious IOC endpoint safely, handle failures, log useful evidence, and move from a terminal test to production.

7 min read
Threat Report History: Recheck, Monitor, and Reuse Evidence
ResearchSep 2, 2026

Threat Report History: Recheck, Monitor, and Reuse Evidence

Use isMalicious report history to find earlier lookups, run fresh checks, add indicators to monitoring, create cases, and export a reusable lookup index.

5 min read
Kubernetes Audit Logs: Threat Detection Guide
ResearchAug 24, 2026

Kubernetes Audit Logs: Threat Detection Guide

Turn Kubernetes audit logs into detections for privilege abuse, secret access, persistence, risky exec, and control-plane compromise.

4 min read
MFA Fatigue: Stop Push-Bombing Attacks
ResearchAug 24, 2026

MFA Fatigue: Stop Push-Bombing Attacks

Detect and prevent MFA fatigue with number matching, rate limits, risk signals, phishing-resistant authentication, and an identity incident playbook.

3 min read
HTML Smuggling: Detection and Incident Response
Incident ResponseAug 24, 2026

HTML Smuggling: Detection and Incident Response

Detect HTML smuggling by correlating browser file creation, JavaScript Blob behavior, download telemetry, endpoint execution, and threat intelligence.

3 min read
Domain Shadowing: Detect Compromised DNS at Scale
DNSAug 24, 2026

Domain Shadowing: Detect Compromised DNS at Scale

Detect domain shadowing by monitoring DNS changes, certificate issuance, subdomain behavior, account security, and infrastructure relationships.

4 min read
IPv6 Threat Intelligence: Reputation Beyond IPv4
ResearchAug 24, 2026

IPv6 Threat Intelligence: Reputation Beyond IPv4

Build IPv6 threat intelligence with correct normalization, prefix context, dual-stack logging, enrichment, and reputation decisions that avoid overblocking.

4 min read
isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)
ResearchAug 23, 2026

isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)

OpenCTI is a threat intelligence platform and knowledge graph. isMalicious is a data provider that feeds it. Teams searching for an OpenCTI alternative usually need a feed, not a replacement TIP.

6 min read
isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program
APIAug 22, 2026

isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program

Recorded Future delivers finished intelligence and analyst support at enterprise scale. isMalicious delivers self-serve enrichment and feeds without a sales cycle. The right choice depends on whether you need strategic reports or automated verdicts.

6 min read
CVE-2026-63077 Puts Unauthenticated RCE on Every TeamCity On-Premises Server
AI & MLAug 18, 2026

CVE-2026-63077 Puts Unauthenticated RCE on Every TeamCity On-Premises Server

A deserialization flaw in the agent polling protocol gives attackers TeamCity server privileges without credentials. JetBrains patched in 2025.11.7 and 2026.1.3 — CISA KEV and a 3-day federal deadline mean hunt now, not after the next release train.

7 min read
CVE-2026-9198 Gives Unauthenticated RCE in IBM Langflow OSS Agent Control Planes
AI & MLAug 17, 2026

CVE-2026-9198 Gives Unauthenticated RCE in IBM Langflow OSS Agent Control Planes

A SUPERUSER token minted through /api/v1/auto_login chains with Python exec() in /api/v1/validate/code. Langflow 1.10.1 fixes the flaw — but internet-exposed instances need hunting now, not after the next sprint.

7 min read
INC Ransomware Chains Two SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410)
RansomwareAug 16, 2026

INC Ransomware Chains Two SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410)

INC affiliates are weaponizing an SSRF and a post-authentication code injection in SonicWall SMA 1000 to reach internal networks. Exploitation started weeks before the July 14 patch — here is how to hunt and triage.

7 min read
isMalicious vs MISP: Why This Is the Wrong Comparison (and What to Compare Instead)
ResearchAug 13, 2026

isMalicious vs MISP: Why This Is the Wrong Comparison (and What to Compare Instead)

MISP is where you store and share indicators. isMalicious is where indicators come from. Teams searching for a MISP alternative are usually looking for a feed, not a replacement platform.

6 min read
Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume
AI & MLAug 11, 2026

Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume

One incident produces hundreds of indicators, and per-indicator lookups are where triage stalls. Here is how to build a batch enrichment pipeline that respects quotas, deduplicates properly, and fails gracefully.

7 min read
Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting
ResearchAug 10, 2026

Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting

A reverse IP lookup turns one indicator into a cluster — or into a thousand innocent neighbours. Here is how to tell the difference, and how to pivot on hosting infrastructure without generating false positives.

7 min read
WHOIS Lookup for Security Investigations: Reading a Record After Redaction
AI & MLAug 9, 2026

WHOIS Lookup for Security Investigations: Reading a Record After Redaction

Privacy services stripped the registrant name out of most WHOIS records, but the fields that matter for triage survived. Here is what a WHOIS record still tells an analyst, and how to read it.

7 min read
The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There
PhishingAug 8, 2026

The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There

German and US law enforcement dismantled Kratos, the AiTM phishing service behind roughly 15,000 Microsoft 365 campaigns a month. The infrastructure is offline, but the kit is not. Here is what to hunt for now.

7 min read
CISA KEV Adds Arista VeloCloud and FortiOS Flaws: Why CVSS Is the Wrong Sort Order
CloudAug 7, 2026

CISA KEV Adds Arista VeloCloud and FortiOS Flaws: Why CVSS Is the Wrong Sort Order

On 27 July 2026 CISA added a CVSS 10.0 command injection in Arista VeloCloud Orchestrator and a medium-severity FortiOS patch bypass to KEV. The pairing shows why exposure and persistence beat severity when ordering a patch queue.

7 min read