For the complete documentation index, see llms.txt. This page is also available as Markdown.

Threat Data

Is this bad?

Use this page for indicator reputation, enrichment, passive DNS, certificate history, blockchain analysis, and quick lookup tools. Detection engineering, YARA, sandboxes, reverse engineering, active recon, and exploit research live in their own sections.

How to Use This Page

Reputation checks are starting points, not verdicts. An indicator can still be malicious even if it does not appear on any blacklist, and a shared service, CDN, or compromised host can create false positives. Use multiple sources, document what each source said, and keep the surrounding context: ASN, registrar, creation date, passive DNS history, related certificates, associated malware families, and analyst comments.

Threat Maps

Threat maps can help with situational awareness, but they should not be treated as precise telemetry for a specific incident.

Threat Actor Information

Malware

Blacklist Checks and Reputation Data

Multi-Source Lookups

IP Reputation

URL and Domain Reputation

File Hash Reputation

For full sandboxing and malware behavior analysis, use DFIR sandboxing.

Sandboxing

Email and Spam Data

Indicator Enrichment

These platforms add context to indicators through scanner telemetry, historical data, abuse reports, and related infrastructure.

Threat intelligence platforms and feed management tools live in Intel Feeds and Sources.

Intel Feeds and Sources

Passive DNS and Historical Data

Domain-focused passive investigation workflows live in Domain OSINT.

Domain

Certificate Transparency and SSL/TLS Analysis

Browser Extensions and Quick Lookup Tools

Cryptocurrency and Blockchain Analysis

Investigation Tools

Some tools require more complex URL structures than simple parameter appending. Additional functionality may be needed for full automation.

Local helper copy: EasyOSINT.html

The following mind map illustrates commonly used tools for indicator analysis and their relationships:

The interactive version can be found here:

372KB
Open
  • Internet-wide search engines such as Shodan, Censys, FOFA, ZoomEye, BinaryEdge, Onyphe, and FullHunt live in Cyber Search.

Cyber Search Engines
  • YARA rules and malware signature hunting live in DFIR.

YARA
  • Sigma rules, MITRE CAR, detection content, and detection engineering live in Event Detection.

Event Detection
  • LOLBAS, GTFOBins, LOLDrivers, LOLAPPS, and WADComs are useful for detection and adversary tradecraft context. Keep them with detection engineering or technique-specific pages rather than reputation lookup.

Detection Use Cases
  • Vulnerability databases, CISA KEV, EPSS, SSVC, and CVSS live in Asset and Vulnerability Management.

Asset and Vulnerability Management
  • Exploit archives and offensive exploit research live in Red Offensive.

Vulnerability and Exploit Research

Best Practices for Indicator Analysis

  1. Validate across multiple sources.

  2. Preserve context such as ASN, registrar, domain age, passive DNS, certificates, and comments.

  3. Document sources consulted and the time of lookup.

  4. Use passive analysis first when you do not want to alert adversaries.

  5. Treat blocklist absence as unknown, not benign.

  6. Verify indicators before blocking or alerting on them.

Deprecated and Legacy Tools

  • ThreatCrowd - Deprecated. Data migrated to AlienVault OTX; original service is no longer maintained.

  • Digital Attack Map - Discontinued by Arbor Networks/NETSCOUT.

  • Malware Domain List (MDL) - No longer actively maintained.

  • Ransomwhere - Bitcoin ransomware tracker that appears inactive.

  • CybOX - Legacy observable specification largely superseded by STIX 2.x observables.

  • Sigmac - Deprecated Sigma converter; pySigma and sigma-cli replaced it.

  • YARA-Rules/rules - Archived community YARA rules repository.

Tool Accuracy Notes

  • Blacklist source counts change frequently, so this page avoids hard-coding source counts.

  • Free APIs often have rate limits or require registration.

  • Browser extension links can change; search by extension name if a store link breaks.

  • Passive DNS retention varies by provider.

  • Advanced malware may detect sandbox environments and alter behavior.

Last updated