Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:checkpoint_research, report:microsoft_mstic, report:secureworks, report:the_hacker_news, report:trend_micro
tags: report:talos, report:the_hacker_news, report:trend_micro
tags: report:the_hacker_news, report:unit42
tags: report:checkpoint_research, report:the_hacker_news
tags: report:checkpoint_research, report:the_hacker_news
tags: report:checkpoint_research, report:the_hacker_news
tags: report:crowdstrike, report:talos
tags: report:secureworks, report:the_hacker_news
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict Key Findings Introduction During the recent geopolitical tensions in the Middle East, we reported on multiple Iran-nexus threat actors advancing Iran’s strategic objectives through cyber operati
Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting Learn how Cisco Talos Threat Hunting uses hypothesis-driven methods and multi-domain telemetry correlation to find stealthy threats operating below automated detection thresholds. By Ron Scott-Adams Mo
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzs
Webworm: New burrowing techniques ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal Webworm: New burrowing techniques Award-winning news, views, and insight from the ESET security community English Español Deutsch Portug
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem Research by: Alexey Bukhteyev Key Takeaways Introduction When we search Google for a popular piece of software, we usually click the first result, sometimes without even looking at the rest, be
Deduped connector weight from graph context.