Tag

SOC

31 articles on soc.

← All blog posts
isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers
DNSAug 25, 2026

isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers

Spamhaus DROP and SBL are the standard for mail and network DNSBL blocking. isMalicious adds REST enrichment, URL scoring, CVE context, and STIX feeds. Most mature stacks use both at different layers.

6 min read
isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs
ResearchAug 24, 2026

isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs

Censys maps what exists on the internet — hosts, certificates, open ports. isMalicious assesses what is malicious. Most teams comparing the two need the second question answered, not the first.

5 min read
isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)
ResearchAug 23, 2026

isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)

OpenCTI is a threat intelligence platform and knowledge graph. isMalicious is a data provider that feeds it. Teams searching for an OpenCTI alternative usually need a feed, not a replacement TIP.

6 min read
isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program
APIAug 22, 2026

isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program

Recorded Future delivers finished intelligence and analyst support at enterprise scale. isMalicious delivers self-serve enrichment and feeds without a sales cycle. The right choice depends on whether you need strategic reports or automated verdicts.

6 min read
Firewall Blocklist Automation: Pulling IP and Domain Feeds Without Outages
AI & MLAug 21, 2026

Firewall Blocklist Automation: Pulling IP and Domain Feeds Without Outages

External dynamic lists can block malware and phishing at the edge — or break payroll, CDN traffic, and vendor portals. This guide covers staged rollout, allowlists, fail-open vs fail-closed, and measuring hit rates for IP and domain blocklists.

8 min read
How to Use an NRD Feed to Catch Phishing Before It Lands in the Inbox
PhishingAug 19, 2026

How to Use an NRD Feed to Catch Phishing Before It Lands in the Inbox

Newly registered domains are where most phishing campaigns start. This guide walks through NRD feed workflows for brand monitoring, mail gateway hygiene, and SOC triage — without treating domain age as a blunt block rule.

8 min read
CVE-2026-63077 Puts Unauthenticated RCE on Every TeamCity On-Premises Server
AI & MLAug 18, 2026

CVE-2026-63077 Puts Unauthenticated RCE on Every TeamCity On-Premises Server

A deserialization flaw in the agent polling protocol gives attackers TeamCity server privileges without credentials. JetBrains patched in 2025.11.7 and 2026.1.3 — CISA KEV and a 3-day federal deadline mean hunt now, not after the next release train.

7 min read
CVE-2026-9198 Gives Unauthenticated RCE in IBM Langflow OSS Agent Control Planes
AI & MLAug 17, 2026

CVE-2026-9198 Gives Unauthenticated RCE in IBM Langflow OSS Agent Control Planes

A SUPERUSER token minted through /api/v1/auto_login chains with Python exec() in /api/v1/validate/code. Langflow 1.10.1 fixes the flaw — but internet-exposed instances need hunting now, not after the next sprint.

7 min read
INC Ransomware Chains Two SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410)
RansomwareAug 16, 2026

INC Ransomware Chains Two SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410)

INC affiliates are weaponizing an SSRF and a post-authentication code injection in SonicWall SMA 1000 to reach internal networks. Exploitation started weeks before the July 14 patch — here is how to hunt and triage.

7 min read
isMalicious vs SecurityTrails: Discovery Data and Reputation Verdicts Are Not the Same Product
DNSAug 15, 2026

isMalicious vs SecurityTrails: Discovery Data and Reputation Verdicts Are Not the Same Product

SecurityTrails tells you what exists — every subdomain, every historical DNS record. isMalicious tells you what is dangerous. Most teams searching for a SecurityTrails alternative want the second half.

6 min read
isMalicious vs IPQualityScore: Fraud Scoring and Threat Intelligence Are Different Jobs
ResearchAug 14, 2026

isMalicious vs IPQualityScore: Fraud Scoring and Threat Intelligence Are Different Jobs

IPQS scores whether a signup is fraudulent. isMalicious scores whether infrastructure is malicious. The two get compared constantly because both return a number about an IP address — and they answer different questions.

6 min read
isMalicious vs MISP: Why This Is the Wrong Comparison (and What to Compare Instead)
ResearchAug 13, 2026

isMalicious vs MISP: Why This Is the Wrong Comparison (and What to Compare Instead)

MISP is where you store and share indicators. isMalicious is where indicators come from. Teams searching for a MISP alternative are usually looking for a feed, not a replacement platform.

6 min read
isMalicious vs Cisco Talos: Reputation Lookups Outside the Cisco Stack
AI & MLAug 12, 2026

isMalicious vs Cisco Talos: Reputation Lookups Outside the Cisco Stack

Talos reputation is excellent and it lives inside Cisco products. If your stack is not Cisco, or you need an API rather than a web form, that is where the comparison starts.

6 min read
Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume
AI & MLAug 11, 2026

Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume

One incident produces hundreds of indicators, and per-indicator lookups are where triage stalls. Here is how to build a batch enrichment pipeline that respects quotas, deduplicates properly, and fails gracefully.

7 min read
Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting
ResearchAug 10, 2026

Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting

A reverse IP lookup turns one indicator into a cluster — or into a thousand innocent neighbours. Here is how to tell the difference, and how to pivot on hosting infrastructure without generating false positives.

7 min read
WHOIS Lookup for Security Investigations: Reading a Record After Redaction
AI & MLAug 9, 2026

WHOIS Lookup for Security Investigations: Reading a Record After Redaction

Privacy services stripped the registrant name out of most WHOIS records, but the fields that matter for triage survived. Here is what a WHOIS record still tells an analyst, and how to read it.

7 min read
The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There
PhishingAug 8, 2026

The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There

German and US law enforcement dismantled Kratos, the AiTM phishing service behind roughly 15,000 Microsoft 365 campaigns a month. The infrastructure is offline, but the kit is not. Here is what to hunt for now.

7 min read
CISA KEV Adds Arista VeloCloud and FortiOS Flaws: Why CVSS Is the Wrong Sort Order
CloudAug 7, 2026

CISA KEV Adds Arista VeloCloud and FortiOS Flaws: Why CVSS Is the Wrong Sort Order

On 27 July 2026 CISA added a CVSS 10.0 command injection in Arista VeloCloud Orchestrator and a medium-severity FortiOS patch bypass to KEV. The pairing shows why exposure and persistence beat severity when ordering a patch queue.

7 min read
Cl0p Is Exploiting PTC Windchill (CVE-2026-12569) to Steal Engineering Data
AI & MLAug 6, 2026

Cl0p Is Exploiting PTC Windchill (CVE-2026-12569) to Steal Engineering Data

A Cl0p affiliate is chaining a FlexPLM information disclosure with an unauthenticated RCE in PTC Windchill to plant JSP web shells and run double-extortion data theft. Here are the detection signals and the triage workflow.

7 min read
GitHub Actions and CI/CD Pipeline Compromise: A Growing Supply Chain Attack Vector
Supply ChainAug 5, 2026

GitHub Actions and CI/CD Pipeline Compromise: A Growing Supply Chain Attack Vector

CI/CD pipeline compromises keep recurring across GitHub Actions ecosystems. Learn the detection signals, hardening steps, and enrichment workflow security teams need.

6 min read
Agentic AI Threat Mapping: MITRE ATT&CK Needs Evidence-Rich Workflows
AI & MLJul 8, 2026

Agentic AI Threat Mapping: MITRE ATT&CK Needs Evidence-Rich Workflows

Anthropic mapped AI-enabled cyber activity to MITRE ATT&CK and found gaps around autonomous orchestration. SOC teams need AI summaries tied to evidence, not unsupported verdicts.

4 min read
AI-Enabled Cyberattacks and MITRE ATT&CK: Turning New Threat Maps Into SOC Action
SOCJun 4, 2026

AI-Enabled Cyberattacks and MITRE ATT&CK: Turning New Threat Maps Into SOC Action

AI-enabled threats are being mapped into ATT&CK language, but mapping is only useful when it drives enrichment, detection, triage, and response workflows.

8 min read
SOC Alert Fatigue: How Threat Intelligence Reduces False Positives Without Hiding Real Attacks
SOCJun 4, 2026

SOC Alert Fatigue: How Threat Intelligence Reduces False Positives Without Hiding Real Attacks

Alert fatigue is not a staffing problem alone. SOC teams need better evidence, source quality, confidence bands, and enrichment workflows that turn noisy alerts into defensible decisions.

8 min read
Threat Intelligence Risk Scoring: How to Calibrate Reputation, Reduce False Positives, and Defend Your Decisions
ResearchApr 30, 2026

Threat Intelligence Risk Scoring: How to Calibrate Reputation, Reduce False Positives, and Defend Your Decisions

A noisy score is worse than no score. Learn what makes a reputation model trustworthy, how to combine multi-source evidence, and how to communicate uncertainty to your SOC and your executives.

5 min read
ASN Reputation for Threat Intelligence: How Autonomous System Intelligence Improves Prioritization and Hunt Programs
GuideApr 27, 2026

ASN Reputation for Threat Intelligence: How Autonomous System Intelligence Improves Prioritization and Hunt Programs

An IP address is a snapshot; an autonomous system (ASN) is a neighborhood. Learn how to use ASN context safely for triage, fraud, and security operations—without mistaking a giant cloud for a monolithic "bad host".

5 min read
Threat Intelligence Platforms: Architecture, Data Quality, and High-Signal Feeds
ResearchApr 26, 2026

Threat Intelligence Platforms: Architecture, Data Quality, and High-Signal Feeds

Design TIPs and intel pipelines that scale: normalization, confidence scoring, deduplication, API-first delivery, and how to pair platform investments with analyst workflows.

9 min read
IOC Enrichment APIs: A Security Operations Guide to Faster Triage, Fewer False Positives, and Measurable ROI
APIApr 26, 2026

IOC Enrichment APIs: A Security Operations Guide to Faster Triage, Fewer False Positives, and Measurable ROI

An indicator without context is a ticket without an owner. Learn how IOC enrichment APIs work, which fields SOC teams need at each tier, and how to wire them into case management without building a data swamp.

6 min read
OSINT for SOC Analysts: Turning Open Source Intelligence Into Threat intelligence analysts can use
SOCApr 23, 2026

OSINT for SOC Analysts: Turning Open Source Intelligence Into Threat intelligence analysts can use

A complete guide to open source intelligence (OSINT) for security operations—tools, techniques, workflows, and legal considerations for collecting, analyzing, and operationalizing open threat data in a modern SOC.

9 min read
Hash Reputation at Scale: Building Detection Rules That Survive Real Networks
ResearchApr 22, 2026

Hash Reputation at Scale: Building Detection Rules That Survive Real Networks

Move beyond one-off hash blocks: design reputation pipelines, reduce false positives, and integrate file intelligence with IP and domain context for production-ready detection engineering.

9 min read
File Hash Reputation Lookups: Accelerating Incident Response With IOC Enrichment
Incident ResponseApr 22, 2026

File Hash Reputation Lookups: Accelerating Incident Response With IOC Enrichment

A practitioner's guide to file hash reputation lookups—how they work, which data sources power them, how to build automated IOC enrichment pipelines, and how to integrate hash intelligence into SOC, SOAR, and incident response workflows.

9 min read
Operational Threat Intelligence: Turning IOCs into Prioritized Security Actions
GuideApr 19, 2026

Operational Threat Intelligence: Turning IOCs into Prioritized Security Actions

Define operational CTI that SOC teams can use daily: IOC lifecycle, confidence scoring, feed hygiene, and how to align indicators with detection engineering and incident response.

9 min read