Skip to main content
Tag

Incident response

39 articles on incident response.

← All blog posts
SMTP 550 5.7.1: Find the Cause of an Email Rejection
Email Security3 d ago

SMTP 550 5.7.1: Find the Cause of an Email Rejection

A 550 5.7.1 rejection can involve recipient policy, authentication, or reputation. Use the full diagnostic and delivery traces to find the cause.

5 min read
How to Analyze Suspicious Email Headers
Phishing4 d ago

How to Analyze Suspicious Email Headers

Identify trusted servers, interpret Authentication-Results, and investigate a suspicious email without confusing authentication with safe content.

5 min read
Investigate an IOC Alert: Link IP, DNS and Process Logs
Threat Intel2026-09-09

Investigate an IOC Alert: Link IP, DNS and Process Logs

An IOC match is an investigation lead. Correlate DNS, network connections and process records to establish what happened on the endpoint.

6 min read
Smart Lookup: Check Any Threat Indicator from One Search
Threat Intel2026-09-02

Smart Lookup: Check Any Threat Indicator from One Search

Paste an IP, domain, URL, email, phone number, wallet, file hash, or a complete suspicious message. Smart Lookup routes each indicator to the right threat report.

5 min read
Composite Threat Reports: Triage Multiple IOCs Together
Threat Intel2026-09-02

Composite Threat Reports: Triage Multiple IOCs Together

A phishing message or security alert rarely contains one indicator. Use a composite threat report to scope several IOCs without losing the evidence behind each result.

5 min read
Threats Dashboard: Turn Current Intelligence into Priorities
Threat Intel2026-09-02

Threats Dashboard: Turn Current Intelligence into Priorities

Use the isMalicious Threats dashboard to move from a broad threat picture to the sectors, ransomware groups, malware, victims, and evidence that matter to your team.

5 min read
Threat Alerts and Action Center: Build a Response Workflow
Incident Response2026-09-02

Threat Alerts and Action Center: Build a Response Workflow

Move from monitored indicators and incoming alerts to a ranked queue, analyst validation, and owned response work with isMalicious Alerts and Action Center.

5 min read
isMalicious API: Make Your First Reliable IOC Lookup
API2026-09-02

isMalicious API: Make Your First Reliable IOC Lookup

Call the current isMalicious IOC endpoint safely, handle failures, log useful evidence, and move from a terminal test to production.

7 min read
Threat Report History: Recheck, Monitor, and Reuse Evidence
Threat Intel2026-09-02

Threat Report History: Recheck, Monitor, and Reuse Evidence

Use isMalicious report history to find earlier lookups, run fresh checks, add indicators to monitoring, create cases, and export a reusable lookup index.

5 min read
Kubernetes Audit Logs: Threat Detection Guide
Cloud2026-08-24

Kubernetes Audit Logs: Threat Detection Guide

Turn Kubernetes audit logs into detections for privilege abuse, secret access, persistence, risky exec, and control-plane compromise.

4 min read
MFA Fatigue: Stop Push-Bombing Attacks
Identity2026-08-24

MFA Fatigue: Stop Push-Bombing Attacks

Detect and prevent MFA fatigue with number matching, rate limits, risk signals, phishing-resistant authentication, and an identity incident playbook.

3 min read
HTML Smuggling: Detection and Incident Response
Malware2026-08-24

HTML Smuggling: Detection and Incident Response

Detect HTML smuggling by correlating browser file creation, JavaScript Blob behavior, download telemetry, endpoint execution, and threat intelligence.

3 min read
Domain Shadowing: Detect Compromised DNS at Scale
DNS2026-08-24

Domain Shadowing: Detect Compromised DNS at Scale

Detect domain shadowing by monitoring DNS changes, certificate issuance, subdomain behavior, account security, and infrastructure relationships.

4 min read
IPv6 Threat Intelligence: Reputation Beyond IPv4
Threat Intel2026-08-24

IPv6 Threat Intelligence: Reputation Beyond IPv4

Build IPv6 threat intelligence with correct normalization, prefix context, dual-stack logging, enrichment, and reputation decisions that avoid overblocking.

4 min read
isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)
Threat Intel2026-08-23

isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)

OpenCTI is a threat intelligence platform and knowledge graph. isMalicious is a data provider that feeds it. Teams searching for an OpenCTI alternative usually need a feed, not a replacement TIP.

6 min read
isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program
Threat Intel2026-08-22

isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program

Recorded Future delivers finished intelligence and analyst support at enterprise scale. isMalicious delivers self-serve enrichment and feeds without a sales cycle. The right choice depends on whether you need strategic reports or automated verdicts.

6 min read
CVE-2026-63077 Puts Unauthenticated RCE on Every TeamCity On-Premises Server
Vulnerabilities2026-08-18

CVE-2026-63077 Puts Unauthenticated RCE on Every TeamCity On-Premises Server

A deserialization flaw in the agent polling protocol gives attackers TeamCity server privileges without credentials. JetBrains patched in 2025.11.7 and 2026.1.3 — CISA KEV and a 3-day federal deadline mean hunt now, not after the next release train.

7 min read
CVE-2026-9198 Gives Unauthenticated RCE in IBM Langflow OSS Agent Control Planes
Vulnerabilities2026-08-17

CVE-2026-9198 Gives Unauthenticated RCE in IBM Langflow OSS Agent Control Planes

A SUPERUSER token minted through /api/v1/auto_login chains with Python exec() in /api/v1/validate/code. Langflow 1.10.1 fixes the flaw — but internet-exposed instances need hunting now, not after the next sprint.

7 min read
INC Ransomware Chains Two SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410)
Ransomware2026-08-16

INC Ransomware Chains Two SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410)

INC affiliates are weaponizing an SSRF and a post-authentication code injection in SonicWall SMA 1000 to reach internal networks. Exploitation started weeks before the July 14 patch — here is how to hunt and triage.

7 min read
isMalicious vs MISP: Why This Is the Wrong Comparison (and What to Compare Instead)
Threat Intel2026-08-13

isMalicious vs MISP: Why This Is the Wrong Comparison (and What to Compare Instead)

MISP is where you store and share indicators. isMalicious is where indicators come from. Teams searching for a MISP alternative are usually looking for a feed, not a replacement platform.

6 min read
Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume
Threat Intel2026-08-11

Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume

One incident produces hundreds of indicators, and per-indicator lookups are where triage stalls. Here is how to build a batch enrichment pipeline that respects quotas, deduplicates properly, and fails gracefully.

7 min read
Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting
SOC2026-08-10

Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting

A reverse IP lookup turns one indicator into a cluster — or into a thousand innocent neighbours. Here is how to tell the difference, and how to pivot on hosting infrastructure without generating false positives.

7 min read
WHOIS Lookup for Security Investigations: Reading a Record After Redaction
Phishing2026-08-09

WHOIS Lookup for Security Investigations: Reading a Record After Redaction

Privacy services stripped the registrant name out of most WHOIS records, but the fields that matter for triage survived. Here is what a WHOIS record still tells an analyst, and how to read it.

7 min read
The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There
Phishing2026-08-08

The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There

German and US law enforcement dismantled Kratos, the AiTM phishing service behind roughly 15,000 Microsoft 365 campaigns a month. The infrastructure is offline, but the kit is not. Here is what to hunt for now.

7 min read