Supercharge Your Threat Investigations with IrisQL
ID: 0c75c538-fa18-5104-982d-bf4ee7ad3c48
STIX ID: report--0c75c538-fa18-5104-982d-bf4ee7ad3c48
Feed Name: DomainTools
This document introduces IrisQL — a text-based query language for threat hunting — and supplies example queries, IOC lists, and hunting patterns for multiple active campaigns and actor types (LummaC2 infostealer, SocGholish TDS, Tycoon PhaaS, APT28/FrostArmada DNS hijacking, RansomHub reconnaissance, typosquatting, etc.), referencing government and vendor advisories and providing time-bound, risk-scored search templates to locate malicious domains, infrastructure, and attribution pivots.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
