logo

Supercharge Your Threat Investigations with IrisQL

ID: 0c75c538-fa18-5104-982d-bf4ee7ad3c48

STIX ID: report--0c75c538-fa18-5104-982d-bf4ee7ad3c48

Feed Name: DomainTools

Threat Score
85/100

Date Published: 2026-04-24

Date Updated: 2026-04-27

Author: domaintools.com

...
...

This document introduces IrisQL — a text-based query language for threat hunting — and supplies example queries, IOC lists, and hunting patterns for multiple active campaigns and actor types (LummaC2 infostealer, SocGholish TDS, Tycoon PhaaS, APT28/FrostArmada DNS hijacking, RansomHub reconnaissance, typosquatting, etc.), referencing government and vendor advisories and providing time-bound, risk-scored search templates to locate malicious domains, infrastructure, and attribution pivots.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.