
School Network Security: Test Segmentation That Works
Plan school network segmentation around teaching needs, test permitted and blocked paths, protect administration, and manage changes without losing access.

CTI Analyst Portfolio: Build a Safe, Reproducible Lab
Build a CTI analyst portfolio with offline datasets, evidence-led assessments, reproducible results, and a review rubric that shows how you make decisions.

Cyber Attribution: Confidence and Competing Hypotheses
Assess cyber attribution with evidence, competing hypotheses, and explicit confidence. Use a practical judgment record without treating an IOC as an identity.

Threat Intelligence PIRs: A Workbook and Collection Plan
Turn threat intelligence requests into useful PIRs with a decision worksheet, collection plan, evidence requirements, ownership, and practical stopping rules.

Diamond Model: A Practical CTI Investigation Walkthrough
Use the Diamond Model to connect evidence, test competing explanations, build activity threads, and turn a phishing investigation into defensible decisions.

Threat Intelligence Feed Poisoning: Protect Your Evidence
Protect CTI decisions from misleading data with source provenance, mirror detection, contradiction handling, safe ingestion, human review, and tested rollback.

TLP 2.0: Share Threat Intelligence Without Leaking Data
Apply TLP 2.0 to CTI reports, indicators, and supplier exchanges with practical sharing boundaries, permission checks, data minimization, and export controls.
IOC Expiration: When to Remove an IP From a Blocklist
Manage IOC expiration with separate DNS, evidence and STIX validity clocks. Review stale IP blocks, process withdrawals and preserve the audit trail.
Domain Reputation Monitoring: Which Changes Need Action?
Track domain reputation over time: distinguish a new phishing report from expected DNS changes, then decide what to verify before restricting access.

Smart Lookup: Check Any Threat Indicator from One Search
Paste an IP, domain, URL, email, phone number, wallet, file hash, or a complete suspicious message. Smart Lookup routes each indicator to the right threat report.

Composite Threat Reports: Triage Multiple IOCs Together
A phishing message or security alert rarely contains one indicator. Use a composite threat report to scope several IOCs without losing the evidence behind each result.

Threats Dashboard: Turn Current Intelligence into Priorities
Use the isMalicious Threats dashboard to move from a broad threat picture to the sectors, ransomware groups, malware, victims, and evidence that matter to your team.

TAXII Threat Feeds: Build a Continuous SIEM Integration
Connect an isMalicious TAXII collection to your SIEM with safe pagination, durable checkpoints, validation, monitoring, and recovery.

Blocklists for Operational Threat Prevention: Test and Roll Back
Use /app/blocklists to select, test, deploy, measure, and safely reverse IP or domain prevention controls.

Threat Intelligence Sources: Evaluate Evidence Before You Act
Use isMalicious Sources and Threat Patterns to examine freshness, contribution, agreement, coverage, and corpus-wide patterns before turning a detection into action.
isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers
Spamhaus DROP and SBL are the standard for mail and network DNSBL blocking. isMalicious adds REST enrichment, URL scoring, CVE context, and STIX feeds. Most mature stacks use both at different layers.

Malicious PyPI Packages: Detect Supply-Chain Attacks
Detect malicious PyPI packages through provenance, dependency controls, install behavior, network telemetry, hashes, and a Python incident playbook.

Bulletproof Hosting: Map Criminal Infrastructure
Identify bulletproof hosting through ASN, prefix, domain, abuse, migration, and campaign signals without treating an entire network as malicious.

Domain Shadowing: Detect Compromised DNS at Scale
Detect domain shadowing by monitoring DNS changes, certificate issuance, subdomain behavior, account security, and infrastructure relationships.

JA4 TLS Fingerprinting for Threat Hunting
Use JA4 TLS fingerprints for threat hunting, malware clustering, allowlisting, and anomaly detection without treating a fingerprint as identity.

Certificate Transparency for Phishing Detection
Use Certificate Transparency logs to find rogue certificates, phishing subdomains, brand impersonation, and exposed assets before they become incidents.

IPv6 Threat Intelligence: Reputation Beyond IPv4
Build IPv6 threat intelligence with correct normalization, prefix context, dual-stack logging, enrichment, and reputation decisions that avoid overblocking.

Residential Proxy Abuse: Detect Fraud Without Blocking Users
Detect residential proxy abuse by combining IP reputation, identity, velocity, device, and behavioral signals without penalizing legitimate users.

DGA Detection: Find Algorithmically Generated Domains
Detect domain generation algorithms with lexical, DNS, endpoint, and reputation signals while controlling false positives in production.