Skip to main content
Blog

Threat Intelligence Blog

Research, insights, and updates from the isMalicious team.

GitHub Actions OIDC: Secure Cloud Deployments
Cloud5 d ago

GitHub Actions OIDC: Secure Cloud Deployments

Replace long-lived cloud secrets with GitHub Actions OIDC while constraining claims, permissions, environments, reusable workflows, and incident response.

4 min readRead
Kubernetes Audit Logs: Threat Detection Guide
Research5 d ago

Kubernetes Audit Logs: Threat Detection Guide

Turn Kubernetes audit logs into detections for privilege abuse, secret access, persistence, risky exec, and control-plane compromise.

4 min readRead
eBPF Runtime Security for Kubernetes
Research5 d ago

eBPF Runtime Security for Kubernetes

Use eBPF runtime security to observe processes, files, privileges, and network activity in Kubernetes while controlling noise and enforcement risk.

4 min readRead
Sigstore and Cosign: Verify Container Images
AI & ML5 d ago

Sigstore and Cosign: Verify Container Images

Sign and verify container images with Cosign, keyless identities, transparency evidence, digest pinning, and admission policies that check the signer.

4 min readRead
SLSA Provenance: Verify the Software Supply Chain
Supply Chain5 d ago

SLSA Provenance: Verify the Software Supply Chain

Use SLSA provenance to trace artifacts to source and build systems, verify expectations, improve CI controls, and respond to tampering.

4 min readRead
Malicious PyPI Packages: Detect Supply-Chain Attacks
Supply Chain5 d ago

Malicious PyPI Packages: Detect Supply-Chain Attacks

Detect malicious PyPI packages through provenance, dependency controls, install behavior, network telemetry, hashes, and a Python incident playbook.

3 min readRead
YARA vs Sigma: Which Detection Rule Should You Use?
Research5 d ago

YARA vs Sigma: Which Detection Rule Should You Use?

Compare YARA and Sigma by data source, purpose, portability, performance, false positives, testing, and threat-intelligence workflow.

4 min readRead
MFA Fatigue: Stop Push-Bombing Attacks
Research5 d ago

MFA Fatigue: Stop Push-Bombing Attacks

Detect and prevent MFA fatigue with number matching, rate limits, risk signals, phishing-resistant authentication, and an identity incident playbook.

3 min readRead
HTML Smuggling: Detection and Incident Response
Incident Response5 d ago

HTML Smuggling: Detection and Incident Response

Detect HTML smuggling by correlating browser file creation, JavaScript Blob behavior, download telemetry, endpoint execution, and threat intelligence.

3 min readRead
Browser-in-the-Browser Phishing: Detection Guide
Phishing5 d ago

Browser-in-the-Browser Phishing: Detection Guide

Understand browser-in-the-browser phishing, spot fake SSO windows, detect campaign infrastructure, and reduce risk with phishing-resistant authentication.

4 min readRead
Subdomain Takeover: Find Dangling DNS First
DNS5 d ago

Subdomain Takeover: Find Dangling DNS First

Prevent subdomain takeover by finding dangling DNS records, linking names to cloud owners, monitoring certificates, and fixing decommissioning order.

4 min readRead
Bulletproof Hosting: Map Criminal Infrastructure
Research5 d ago

Bulletproof Hosting: Map Criminal Infrastructure

Identify bulletproof hosting through ASN, prefix, domain, abuse, migration, and campaign signals without treating an entire network as malicious.

4 min readRead
Domain Shadowing: Detect Compromised DNS at Scale
DNS5 d ago

Domain Shadowing: Detect Compromised DNS at Scale

Detect domain shadowing by monitoring DNS changes, certificate issuance, subdomain behavior, account security, and infrastructure relationships.

4 min readRead
JA4 TLS Fingerprinting for Threat Hunting
Research5 d ago

JA4 TLS Fingerprinting for Threat Hunting

Use JA4 TLS fingerprints for threat hunting, malware clustering, allowlisting, and anomaly detection without treating a fingerprint as identity.

4 min readRead
DNS over HTTPS Security: Detect DoH Abuse
DNS5 d ago

DNS over HTTPS Security: Detect DoH Abuse

Secure DNS over HTTPS without losing visibility: govern resolvers, detect bypass attempts, correlate endpoint telemetry, and preserve user privacy.

4 min readRead
Certificate Transparency for Phishing Detection
Security5 d ago

Certificate Transparency for Phishing Detection

Use Certificate Transparency logs to find rogue certificates, phishing subdomains, brand impersonation, and exposed assets before they become incidents.

4 min readRead
IPv6 Threat Intelligence: Reputation Beyond IPv4
Research5 d ago

IPv6 Threat Intelligence: Reputation Beyond IPv4

Build IPv6 threat intelligence with correct normalization, prefix context, dual-stack logging, enrichment, and reputation decisions that avoid overblocking.

4 min readRead
Residential Proxy Abuse: Detect Fraud Without Blocking Users
Research5 d ago

Residential Proxy Abuse: Detect Fraud Without Blocking Users

Detect residential proxy abuse by combining IP reputation, identity, velocity, device, and behavioral signals without penalizing legitimate users.

4 min readRead
DGA Detection: Find Algorithmically Generated Domains
AI & ML5 d ago

DGA Detection: Find Algorithmically Generated Domains

Detect domain generation algorithms with lexical, DNS, endpoint, and reputation signals while controlling false positives in production.

4 min readRead
Fast-Flux DNS: Detect Rotating Attack Infrastructure
DNS5 d ago

Fast-Flux DNS: Detect Rotating Attack Infrastructure

Learn how to detect fast-flux DNS using TTL, passive DNS, ASN diversity, reputation signals, and a repeatable SOC investigation workflow.

4 min readRead
isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs
Research5 d ago

isMalicious vs Censys: Internet Discovery and Reputation Verdicts Are Different Jobs

Censys maps what exists on the internet — hosts, certificates, open ports. isMalicious assesses what is malicious. Most teams comparing the two need the second question answered, not the first.

5 min readRead
isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)
Research6 d ago

isMalicious vs OpenCTI: Why This Is the Wrong Comparison (and How They Work Together)

OpenCTI is a threat intelligence platform and knowledge graph. isMalicious is a data provider that feeds it. Teams searching for an OpenCTI alternative usually need a feed, not a replacement TIP.

6 min readRead
isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program
API2026-08-22

isMalicious vs Recorded Future: When a Threat Data API Makes More Sense Than an Enterprise Intel Program

Recorded Future delivers finished intelligence and analyst support at enterprise scale. isMalicious delivers self-serve enrichment and feeds without a sales cycle. The right choice depends on whether you need strategic reports or automated verdicts.

6 min readRead
Firewall Blocklist Automation: Pulling IP and Domain Feeds Without Outages
AI & ML2026-08-21

Firewall Blocklist Automation: Pulling IP and Domain Feeds Without Outages

External dynamic lists can block malware and phishing at the edge — or break payroll, CDN traffic, and vendor portals. This guide covers staged rollout, allowlists, fail-open vs fail-closed, and measuring hit rates for IP and domain blocklists.

8 min readRead

Expert Threat Intelligence Analysis

Our blog features in-depth analysis from our threat research team. Each article is backed by real data from our analysis of millions of malicious domains, IPs, and URLs across the global threat landscape. Topics include ransomware campaigns, phishing techniques, malware distribution networks, and emerging threat trends. We publish specific intelligence that security teams can immediately use to improve their defenses.

Practical Security Guidance

Beyond threat analysis, we share practical guidance for security practitioners. Our tutorials cover API integration, SIEM configuration, threat hunting techniques, and building effective threat intelligence programs. Whether you're a SOC analyst, security engineer, or CISO, you'll find content tailored to your role and experience level.

Stay Ahead of Emerging Threats

The threat landscape evolves constantly. Our blog keeps you informed about the latest attack techniques, newly discovered vulnerabilities, and emerging threat actors. Subscribe to our newsletter for weekly digests of the most important developments in cybersecurity.

Subscribe to Our Newsletter

Weekly threat intelligence insights delivered to your inbox.