Threat Intelligence Blog
Research, insights, and updates from the isMalicious team.

GitHub Actions OIDC: Secure Cloud Deployments
Replace long-lived cloud secrets with GitHub Actions OIDC while constraining claims, permissions, environments, reusable workflows, and incident response.

Kubernetes Audit Logs: Threat Detection Guide
Turn Kubernetes audit logs into detections for privilege abuse, secret access, persistence, risky exec, and control-plane compromise.

eBPF Runtime Security for Kubernetes
Use eBPF runtime security to observe processes, files, privileges, and network activity in Kubernetes while controlling noise and enforcement risk.

Sigstore and Cosign: Verify Container Images
Sign and verify container images with Cosign, keyless identities, transparency evidence, digest pinning, and admission policies that check the signer.

SLSA Provenance: Verify the Software Supply Chain
Use SLSA provenance to trace artifacts to source and build systems, verify expectations, improve CI controls, and respond to tampering.

Malicious PyPI Packages: Detect Supply-Chain Attacks
Detect malicious PyPI packages through provenance, dependency controls, install behavior, network telemetry, hashes, and a Python incident playbook.

YARA vs Sigma: Which Detection Rule Should You Use?
Compare YARA and Sigma by data source, purpose, portability, performance, false positives, testing, and threat-intelligence workflow.

MFA Fatigue: Stop Push-Bombing Attacks
Detect and prevent MFA fatigue with number matching, rate limits, risk signals, phishing-resistant authentication, and an identity incident playbook.

HTML Smuggling: Detection and Incident Response
Detect HTML smuggling by correlating browser file creation, JavaScript Blob behavior, download telemetry, endpoint execution, and threat intelligence.

Browser-in-the-Browser Phishing: Detection Guide
Understand browser-in-the-browser phishing, spot fake SSO windows, detect campaign infrastructure, and reduce risk with phishing-resistant authentication.

Subdomain Takeover: Find Dangling DNS First
Prevent subdomain takeover by finding dangling DNS records, linking names to cloud owners, monitoring certificates, and fixing decommissioning order.

Bulletproof Hosting: Map Criminal Infrastructure
Identify bulletproof hosting through ASN, prefix, domain, abuse, migration, and campaign signals without treating an entire network as malicious.

Domain Shadowing: Detect Compromised DNS at Scale
Detect domain shadowing by monitoring DNS changes, certificate issuance, subdomain behavior, account security, and infrastructure relationships.

JA4 TLS Fingerprinting for Threat Hunting
Use JA4 TLS fingerprints for threat hunting, malware clustering, allowlisting, and anomaly detection without treating a fingerprint as identity.

DNS over HTTPS Security: Detect DoH Abuse
Secure DNS over HTTPS without losing visibility: govern resolvers, detect bypass attempts, correlate endpoint telemetry, and preserve user privacy.

Certificate Transparency for Phishing Detection
Use Certificate Transparency logs to find rogue certificates, phishing subdomains, brand impersonation, and exposed assets before they become incidents.

IPv6 Threat Intelligence: Reputation Beyond IPv4
Build IPv6 threat intelligence with correct normalization, prefix context, dual-stack logging, enrichment, and reputation decisions that avoid overblocking.

Residential Proxy Abuse: Detect Fraud Without Blocking Users
Detect residential proxy abuse by combining IP reputation, identity, velocity, device, and behavioral signals without penalizing legitimate users.

DGA Detection: Find Algorithmically Generated Domains
Detect domain generation algorithms with lexical, DNS, endpoint, and reputation signals while controlling false positives in production.

Fast-Flux DNS: Detect Rotating Attack Infrastructure
Learn how to detect fast-flux DNS using TTL, passive DNS, ASN diversity, reputation signals, and a repeatable SOC investigation workflow.
isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs
Censys maps what exists on the internet — hosts, certificates, open ports. isMalicious assesses what is malicious. Most teams comparing the two need the second question answered, not the first.
isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)
OpenCTI is a threat intelligence platform and knowledge graph. isMalicious is a data provider that feeds it. Teams searching for an OpenCTI alternative usually need a feed, not a replacement TIP.
isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program
Recorded Future delivers finished intelligence and analyst support at enterprise scale. isMalicious delivers self-serve enrichment and feeds without a sales cycle. The right choice depends on whether you need strategic reports or automated verdicts.
Firewall Blocklist Automation: Pulling IP and Domain Feeds Without Outages
External dynamic lists can block malware and phishing at the edge — or break payroll, CDN traffic, and vendor portals. This guide covers staged rollout, allowlists, fail-open vs fail-closed, and measuring hit rates for IP and domain blocklists.
Expert Threat Intelligence Analysis
Our blog features in-depth analysis from our threat research team. Each article is backed by real data from our analysis of millions of malicious domains, IPs, and URLs across the global threat landscape. Topics include ransomware campaigns, phishing techniques, malware distribution networks, and emerging threat trends. We publish specific intelligence that security teams can immediately use to improve their defenses.
Practical Security Guidance
Beyond threat analysis, we share practical guidance for security practitioners. Our tutorials cover API integration, SIEM configuration, threat hunting techniques, and building effective threat intelligence programs. Whether you're a SOC analyst, security engineer, or CISO, you'll find content tailored to your role and experience level.
Stay Ahead of Emerging Threats
The threat landscape evolves constantly. Our blog keeps you informed about the latest attack techniques, newly discovered vulnerabilities, and emerging threat actors. Subscribe to our newsletter for weekly digests of the most important developments in cybersecurity.
Subscribe to Our Newsletter
Weekly threat intelligence insights delivered to your inbox.