Skip to main content
Tag

IOC

7 articles on ioc.

← All blog posts
IOC Expiration: When to Remove an IP From a Blocklist
ResearchSep 9, 2026

IOC Expiration: When to Remove an IP From a Blocklist

Manage IOC expiration with separate DNS, evidence and STIX validity clocks. Review stale IP blocks, process withdrawals and preserve the audit trail.

6 min read
Investigate an IOC Alert: Link IP, DNS and Process Logs
DNSSep 9, 2026

Investigate an IOC Alert: Link IP, DNS and Process Logs

An IOC match is an investigation lead. Correlate DNS, network connections and process records to establish what happened on the endpoint.

6 min read
Threat Intelligence Platforms: Architecture, Data Quality, and High-Signal Feeds
ResearchApr 26, 2026

Threat Intelligence Platforms: Architecture, Data Quality, and High-Signal Feeds

Design TIPs and intel pipelines that scale: normalization, confidence scoring, deduplication, API-first delivery, and how to pair platform investments with analyst workflows.

8 min read
Building IOC Pipelines: From Raw Indicators to Operational Threat Intelligence in 2026
ResearchApr 26, 2026

Building IOC Pipelines: From Raw Indicators to Operational Threat Intelligence in 2026

A practical engineering guide to building indicator of compromise (IOC) pipelines—ingestion, normalization, deduplication, enrichment, scoring, distribution, and feedback—to turn raw threat feeds into operational defense.

10 min read
Operational Threat Intelligence: Turning IOCs into Prioritized Security Actions
GuideApr 19, 2026

Operational Threat Intelligence: Turning IOCs into Prioritized Security Actions

Define operational CTI that SOC teams can use daily: IOC lifecycle, confidence scoring, feed hygiene, and how to align indicators with detection engineering and incident response.

8 min read
File Hash Check: Is This SHA-256 Malware?
MalwareApr 18, 2026

File Hash Check: Is This SHA-256 Malware?

How to check MD5, SHA-1, and SHA-256 hashes against threat intelligence, and how SOC teams use hash reputation to cut false positives.

8 min read
File Hash Analysis: MD5, SHA-1, and SHA-256 for Malware Detection and Threat Hunting
MalwareApr 18, 2026

File Hash Analysis: MD5, SHA-1, and SHA-256 for Malware Detection and Threat Hunting

A practical guide to file hashes in cybersecurity—how MD5, SHA-1, and SHA-256 work, why they matter for malware detection, incident response, and threat hunting, and how to use hash lookups to enrich indicators of compromise.

9 min read