logo

Scaling detection: When 1 + 1 = 3 (grouping IPs to find bad actors across orgs)

ID: ea7da543-5a06-5ca9-855d-74c61196cda5

STIX ID: report--ea7da543-5a06-5ca9-855d-74c61196cda5

Feed Name: Expel Blog

Threat Score
50/100

Date Published: 2025-05-19

Date Updated: 2026-04-27

Author: Nathan Sorrel

...
...

This blog explains how aggregating incident telemetry across many customers enables detection of malicious login activity by grouping IPs and ASNs, surfacing patterns (e.g., repeated ASNs, same-day clusters, reused IPv4 octets), and identifying previously undetected compromises; it illustrates this with ASN tables and specific IP examples and highlights remediation and detection-improvement practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.