Skip to main content
Blog

Threat Intelligence Blog

Research, insights, and updates from the isMalicious team.

Government Threat Intelligence Procurement: A Practical Guide
Threat Intel2026-09-18

Government Threat Intelligence Procurement: A Practical Guide

Specify a public-sector threat intelligence service with clear evidence, data-handling rules, acceptance tests and an exit plan for UK and European teams.

10 min readRead
CTI Analyst OPSEC: Scan URLs Without Exposing Secrets
Threat Intel2026-09-17

CTI Analyst OPSEC: Scan URLs Without Exposing Secrets

Protect CTI investigations before scanning URLs or files: assess public visibility, signed links, hash lookups, and the right environment for sensitive evidence.

11 min readRead
CTI Analyst Portfolio: Build a Safe, Reproducible Lab
Threat Intel2026-09-17

CTI Analyst Portfolio: Build a Safe, Reproducible Lab

Build a CTI analyst portfolio with offline datasets, evidence-led assessments, reproducible results, and a review rubric that shows how you make decisions.

11 min readRead
Cyber Attribution: Confidence and Competing Hypotheses
Threat Intel2026-09-17

Cyber Attribution: Confidence and Competing Hypotheses

Assess cyber attribution with evidence, competing hypotheses, and explicit confidence. Use a practical judgment record without treating an IOC as an identity.

11 min readRead
Threat Intelligence PIRs: A Workbook and Collection Plan
Threat Intel2026-09-17

Threat Intelligence PIRs: A Workbook and Collection Plan

Turn threat intelligence requests into useful PIRs with a decision worksheet, collection plan, evidence requirements, ownership, and practical stopping rules.

10 min readRead
Diamond Model: A Practical CTI Investigation Walkthrough
Threat Intel2026-09-17

Diamond Model: A Practical CTI Investigation Walkthrough

Use the Diamond Model to connect evidence, test competing explanations, build activity threads, and turn a phishing investigation into defensible decisions.

11 min readRead
IOC Retrohunting: Investigating Historical Logs Reliably
Threat Intel2026-09-17

IOC Retrohunting: Investigating Historical Logs Reliably

Run reliable IOC retrohunts by separating event time, intelligence availability, and validity, then document historical evidence and the limits of negative results.

11 min readRead
Threat Intelligence Feed Poisoning: Protect Your Evidence
Threat Intel2026-09-17

Threat Intelligence Feed Poisoning: Protect Your Evidence

Protect CTI decisions from misleading data with source provenance, mirror detection, contradiction handling, safe ingestion, human review, and tested rollback.

10 min readRead
Threat Intelligence Feed ROI: Build a Reliable Benchmark
Threat Intel2026-09-17

Threat Intelligence Feed ROI: Build a Reliable Benchmark

Evaluate threat intelligence feeds with an independent sample, complete operating costs, and a measure of incremental value before buying or renewing a contract.

10 min readRead
Threat Intelligence Reports for Executives: A Practical Template
Threat Intel2026-09-17

Threat Intelligence Reports for Executives: A Practical Template

Write a CTI brief executives can use: the required decision, business impact, evidence, uncertainties, options, and follow-up, with a template and worked example.

11 min readRead
TLP 2.0: Share Threat Intelligence Without Leaking Data
Threat Intel2026-09-17

TLP 2.0: Share Threat Intelligence Without Leaking Data

Apply TLP 2.0 to CTI reports, indicators, and supplier exchanges with practical sharing boundaries, permission checks, data minimization, and export controls.

10 min readRead
IOC Expiration: When to Remove an IP From a Blocklist
Threat Intel2026-09-09

IOC Expiration: When to Remove an IP From a Blocklist

Manage IOC expiration with separate DNS, evidence and STIX validity clocks. Review stale IP blocks, process withdrawals and preserve the audit trail.

6 min readRead
Investigate an IOC Alert: Link IP, DNS and Process Logs
Threat Intel2026-09-09

Investigate an IOC Alert: Link IP, DNS and Process Logs

An IOC match is an investigation lead. Correlate DNS, network connections and process records to establish what happened on the endpoint.

6 min readRead
Smart Lookup: Check Any Threat Indicator from One Search
Threat Intel2026-09-02

Smart Lookup: Check Any Threat Indicator from One Search

Paste an IP, domain, URL, email, phone number, wallet, file hash, or a complete suspicious message. Smart Lookup routes each indicator to the right threat report.

5 min readRead
Composite Threat Reports: Triage Multiple IOCs Together
Threat Intel2026-09-02

Composite Threat Reports: Triage Multiple IOCs Together

A phishing message or security alert rarely contains one indicator. Use a composite threat report to scope several IOCs without losing the evidence behind each result.

5 min readRead
Threats Dashboard: Turn Current Intelligence into Priorities
Threat Intel2026-09-02

Threats Dashboard: Turn Current Intelligence into Priorities

Use the isMalicious Threats dashboard to move from a broad threat picture to the sectors, ransomware groups, malware, victims, and evidence that matter to your team.

5 min readRead
TAXII Threat Feeds: Build a Continuous SIEM Integration
Threat Intel2026-09-02

TAXII Threat Feeds: Build a Continuous SIEM Integration

Connect an isMalicious TAXII collection to your SIEM with safe pagination, durable checkpoints, validation, monitoring, and recovery.

6 min readRead
Blocklists for Operational Threat Prevention: Test and Roll Back
Threat Intel2026-09-02

Blocklists for Operational Threat Prevention: Test and Roll Back

Use /app/blocklists to select, test, deploy, measure, and safely reverse IP or domain prevention controls.

7 min readRead
Threat Report History: Recheck, Monitor, and Reuse Evidence
Threat Intel2026-09-02

Threat Report History: Recheck, Monitor, and Reuse Evidence

Use isMalicious report history to find earlier lookups, run fresh checks, add indicators to monitoring, create cases, and export a reusable lookup index.

5 min readRead
Threat Intelligence Sources: Evaluate Evidence Before You Act
Threat Intel2026-09-02

Threat Intelligence Sources: Evaluate Evidence Before You Act

Use isMalicious Sources and Threat Patterns to examine freshness, contribution, agreement, coverage, and corpus-wide patterns before turning a detection into action.

5 min readRead
isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers
Threat Intel2026-08-25

isMalicious vs Spamhaus: DNSBL Blocklists and Threat Enrichment Serve Different Layers

Spamhaus DROP and SBL are the standard for mail and network DNSBL blocking. isMalicious adds REST enrichment, URL scoring, CVE context, and STIX feeds. Most mature stacks use both at different layers.

6 min readRead
Bulletproof Hosting: Map Criminal Infrastructure
Threat Intel2026-08-24

Bulletproof Hosting: Map Criminal Infrastructure

Identify bulletproof hosting through ASN, prefix, domain, abuse, migration, and campaign signals without treating an entire network as malicious.

4 min readRead
IPv6 Threat Intelligence: Reputation Beyond IPv4
Threat Intel2026-08-24

IPv6 Threat Intelligence: Reputation Beyond IPv4

Build IPv6 threat intelligence with correct normalization, prefix context, dual-stack logging, enrichment, and reputation decisions that avoid overblocking.

4 min readRead
isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs
Threat Intel2026-08-24

isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs

Censys maps what exists on the internet — hosts, certificates, open ports. isMalicious assesses what is malicious. Most teams comparing the two need the second question answered, not the first.

5 min readRead

Expert Threat Intelligence Analysis

Our blog features in-depth analysis from our threat research team. Each article is backed by real data from our analysis of millions of malicious domains, IPs, and URLs across the global threat landscape. Topics include ransomware campaigns, phishing techniques, malware distribution networks, and emerging threat trends. We publish specific intelligence that security teams can immediately use to improve their defenses.

Practical Security Guidance

Beyond threat analysis, we share practical guidance for security practitioners. Our tutorials cover API integration, SIEM configuration, threat hunting techniques, and building effective threat intelligence programs. Whether you're a SOC analyst, security engineer, or CISO, you'll find content tailored to your role and experience level.

Stay Ahead of Emerging Threats

The threat landscape evolves constantly. Our blog keeps you informed about the latest attack techniques, newly discovered vulnerabilities, and emerging threat actors. Subscribe to our newsletter for weekly digests of the most important developments in cybersecurity.

Subscribe to Our Newsletter

Weekly threat intelligence insights delivered to your inbox.