Threats Tagged 'ioc'
View all threats tagged with 'ioc'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ioc'
Click on any threat for detailed analysis and mitigation recommendations
This is an open-source project focused on early detection of phishing infrastructure by monitoring newly registered domains (NRDs) and applying structural and keyword analysis to identify suspicious domains before they become known indicators of compromise (IOCs). The detection pipeline integrates with Suricata rulesets to enable DNS and TLS detection of these suspicious domains, aiming to reduce the time gap between domain registration and network detection. The project is evolving and seeks community feedback for improvement. Join the discussion | Reddit Cybersecurity | 08/09/2026, 00:34:13 UTC Added: 08/09/2026, 00:56:04 UTC |
BRIEFR is a self-hosted, open-source tool designed to provide CVE and IOC intelligence as part of a modular SIEM approach. It aggregates data from multiple threat intelligence sources such as NVD, CISA KEV, FIRST EPSS, and various exploit feeds, scoring CVEs against a user's technology stack. The tool also supports IOC lookups via free-tier VirusTotal, AbuseIPDB, MalwareBazzar, and URLHaus, and integrates Sigma community rules and SIEM query starters tied to ATT&CK. BRIEFR is currently in early alpha, intended for personal use with no major issues reported, and is not a vulnerability or threat itself. It is a security tool aimed at improving threat intelligence and situational awareness. Join the discussion | Reddit Cybersecurity | 08/03/2026, 10:20:47 UTC Added: 08/03/2026, 17:02:49 UTC |
OffSeq Mirage honeypot sensors observed this SHA-256 file hash 2 time(s) in attacker activity between 2026-07-09 and 2026-07-09. Observed technique: T1105 (Ingress Tool Transfer). Seen from attacker infrastructure in US. File hashes fingerprint a specific malicious payload (a dropper, web shell, miner, or post-exploitation tool) that was staged or delivered during the attack. Match it against files in your environment and your EDR/AV and threat-intel feeds. Join the discussion | OffSeq Mirage | 07/09/2026, 20:35:45 UTC Added: 07/09/2026, 21:32:59 UTC |
OffSeq Mirage honeypot sensors observed this SHA-256 file hash 2 time(s) in attacker activity between 2026-07-09 and 2026-07-10. Observed technique: T1105 (Ingress Tool Transfer). Seen from attacker infrastructure in TZ, TH. File hashes fingerprint a specific malicious payload (a dropper, web shell, miner, or post-exploitation tool) that was staged or delivered during the attack. Match it against files in your environment and your EDR/AV and threat-intel feeds. Join the discussion | OffSeq Mirage | 07/09/2026, 19:14:11 UTC Added: 07/10/2026, 10:48:15 UTC |
OffSeq Mirage honeypot sensors observed this attacker URL 9 time(s) in attacker activity between 2026-07-09 and 2026-07-09. Observed technique: T1105 (Ingress Tool Transfer). Seen from attacker infrastructure in TH, TZ. This URL was observed in attacker payloads (tool download, callback, or exploitation target). Block and monitor it, and search your proxy/web/WAF logs for requests to it. Join the discussion | OffSeq Mirage | 07/09/2026, 13:14:06 UTC Added: 07/09/2026, 19:32:59 UTC |
OffSeq Mirage honeypot sensors observed this SHA-256 file hash 2 time(s) in attacker activity between 2026-07-09 and 2026-07-09. Observed technique: T1105 (Ingress Tool Transfer). Seen from attacker infrastructure in GB. File hashes fingerprint a specific malicious payload (a dropper, web shell, miner, or post-exploitation tool) that was staged or delivered during the attack. Match it against files in your environment and your EDR/AV and threat-intel feeds. Join the discussion | OffSeq Mirage | 07/09/2026, 11:58:19 UTC Added: 07/09/2026, 12:20:11 UTC |
OffSeq Mirage honeypot sensors observed this SHA-256 file hash 2 time(s) in attacker activity between 2026-07-09 and 2026-07-09. Observed technique: T1105 (Ingress Tool Transfer). Seen from attacker infrastructure in GB. File hashes fingerprint a specific malicious payload (a dropper, web shell, miner, or post-exploitation tool) that was staged or delivered during the attack. Match it against files in your environment and your EDR/AV and threat-intel feeds. Join the discussion | OffSeq Mirage | 07/09/2026, 11:58:18 UTC Added: 07/09/2026, 12:20:11 UTC |
OffSeq Mirage honeypot sensors observed this SHA-256 file hash 2 time(s) in attacker activity between 2026-07-09 and 2026-07-09. Observed technique: T1105 (Ingress Tool Transfer). Seen from attacker infrastructure in GB. File hashes fingerprint a specific malicious payload (a dropper, web shell, miner, or post-exploitation tool) that was staged or delivered during the attack. Match it against files in your environment and your EDR/AV and threat-intel feeds. Join the discussion | OffSeq Mirage | 07/09/2026, 11:58:16 UTC Added: 07/09/2026, 12:20:11 UTC |
This report announces the release of IOCX v0.7.5, an open-source PE (Portable Executable) structural validator, and provides detailed notes on PE format ambiguities related to delay-load imports, exports, VS_VERSIONINFO, and resource hierarchy. The release includes new parser/validator pairs and reason codes to improve detection of structural anomalies in PE files. The tool aims to enhance PE format validation with precise handling of ambiguous cases and robust error reporting. Join the discussion | Reddit ExploitDev | 07/08/2026, 13:46:55 UTC Added: 07/10/2026, 12:03:03 UTC |
OffSeq Mirage honeypot sensors observed this SHA-256 file hash 24 time(s) in attacker activity between 2026-07-07 and 2026-07-09. Observed technique: T1105 (Ingress Tool Transfer). Seen from attacker infrastructure in GB. File hashes fingerprint a specific malicious payload (a dropper, web shell, miner, or post-exploitation tool) that was staged or delivered during the attack. Match it against files in your environment and your EDR/AV and threat-intel feeds. Join the discussion | OffSeq Mirage | 07/07/2026, 21:43:54 UTC Added: 07/08/2026, 22:59:00 UTC |
Showing 1 to 10 of 52 results