Collection through Correlation: Operationalizing IP and Domain Indicators of Compromise
ID: 7ecf7b6b-d140-5817-8dbe-aa0b98a1fcb2
STIX ID: report--7ecf7b6b-d140-5817-8dbe-aa0b98a1fcb2
Feed Name: Pulsedive Blog
This blog explains how to extract greater value from IP and domain IOCs in cyber threat intelligence by enriching alerts, informing detections, and guiding hunts, while acknowledging their ephemerality per the Pyramid of Pain. It demonstrates practical pivoting methods—geolocation/reputation checks, ASN/VPN analysis, and TLS certificate fingerprints—to cluster related activity and uncover additional IOCs, using examples such as Mystic Stealer control panels and DCRat-related certificates, with tooling references including Pulsedive, GreyNoise, Shodan/FOFA, Censys, and others.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
