Skip to main content
Dataminr Redefines Cyber Defense with AI-Powered Client-Tailored Intelligence and Autonomous Threat and Exposure Management
Learn More
Request a Demo
ThreatConnect blog

Read insights, thought leadership, and platform updates.

Showing 510 posts
Sort

No Blogs Match Your Results

Please try again or contact marketing@threatconnect.com for more information on our blogs.

ThreatConnect Platform

ThreatConnect and Cisco Secure Access by Duo: Save time during IdAM Investigations

ThreatConnect has partnered with Cisco Security to deliver a Playbook App for joint customers to use Cisco Secure Access by Duo (formerly Cisco Duo). Now, users can automate processes during an internal security investigation when it’s critical to quickly get user information or suspend users involved with a security incident. The App allows you to: […]

ThreatConnect Platform

Playbook Fridays: Have You Been Pwned?

Enriching Indicators with haveibeenpwned ThreatConnect developed the Playbooks capability to help analysts automate time consuming and repetitive tasks so they can focus on what is most important. And in many cases, to ensure the analysis process can occur consistently and in real time, without human intervention. Why Was the Playbook Created? Data breaches come and […]

ThreatConnect Platform

ThreatConnect and VirusTotal: Enable YARA Hunting and Better Malware Analysis

ThreatConnect and VirusTotal have improved our collaboration with a new Playbook App! This app will allow you to send malware to a sandbox to be further examined and retrieve the results from VirusTotal.  Leveraging this App, you will be able to perform Phishing Email Triage, Endpoint Investigation, and Malware Hunting. This all leads to more […]

ThreatConnect Platform

ThreatConnect Research Roundup: Wizard Spider / UNC1878 / Ryuk Campaign

Howdy, and welcome to the ThreatConnect Research Roundup, a collection of recent findings by our Research Team and items from open source publications that have resulted in Observations of related indicators across ThreatConnect’s CAL™ (Collective Analytics Layer). In this Roundup, we highlight the Late 2020 Wizard Spider / UNC1878 / Ryuk Campaign. In late September […]

ThreatConnect Platform

ThreatConnect and McAfee DXL: Better Integrations with the McAfee Stack

ThreatConnect has partnered with security giant McAfee and released multiple Playbook Apps and one App Service for McAfee DXL. McAfee DXL is a communication fabric and it allows us to easily connect with nearly every piece of McAfee technology.  The Playbook Apps will allow you to Publish Events and Invoke Services on DXL topics while […]

Collective Analytics Layer (CAL) ThreatConnect Platform

Who’s Next: A look at CAL 2.6’s latest additions

We’re proud to announce the release of CAL 2.6, our latest addition to our Collective Analytic Layer’s featureset.  As the latest in our ongoing quest to find the most interesting intelligence and deliver it to you, we’ve decided to incorporate some additional datasets in the form of WHOIS records, a partnership with Quad9, and even […]

Threat Research

ThreatConnect Research Roundup: Ryuk and Domains Spoofing ESET and Microsoft

Howdy, and welcome to the ThreatConnect Research Roundup, a collection of recent findings by our Research Team and items from open source publications that have resulted in Observations of related indicators across ThreatConnect’s CAL™ (Collective Analytics Layer). Note: Viewing the pages linked in this blog post requires a ThreatConnect account. Roundup Highlight: Ryuk In this […]

ThreatConnect Platform

ThreatConnect Research Roundup: Possible Ryuk Infrastructure

Howdy, and welcome to the ThreatConnect Research Roundup, a collection of recent findings by our Research Team and items from open source publications that have resulted in Observations of related indicators across ThreatConnect’s CAL™ (Collective Analytics Layer). Note: Viewing the pages linked in this blog post requires a ThreatConnect account. Roundup Highlight: Possible Ryuk Infrastructure […]

Collective Analytics Layer (CAL) ThreatConnect Platform

Caught in our Net

Using neural networks to identify algorithmically generated domains (AGDs) The problem with today’s generation A while back, we released a new CAL Feed that leveraged our ability to detect domains that were generated via an algorithm.  This is an interesting cohort of domains — they’re typically generated by machines and for machines.  That alone makes […]

ThreatConnect Platform

ThreatConnect and Check Point: Better Endpoint Protection

ThreatConnect has partnered with Check Point and built a Playbook App for our joint customers to leverage. With the addition of this new Playbook App, immediate actions can be taken to investigate, stop, and remediate potential threats at the endpoint based on external threat intelligence. Check Point’s Unified Security Management gives you unified management control […]

Threat Research

Research Roundup: Kimsuky Phishing Operations Putting in Work

Howdy, and welcome to the ThreatConnect Research Roundup, a collection of recent findings by our Research Team and items from open source publications that have resulted in Observations of related indicators across ThreatConnect’s CAL™ (Collective Analytics Layer). Note: Viewing the pages linked in this blog post requires a ThreatConnect account. In this edition, we cover: […]

Get Context from MISP Warning Lists as You Work Using the Polarity Integration
Polarity

Get Context from MISP Warning Lists as You Work Using the Polarity Integration

Today’s post continues an ongoing series on Polarity Integrations. Data tells a story, Polarity helps you see it with Augmented Reality overlaying contextual information from the applications you use every day. With over 100 powerful integrations the Polarity open-source Integrations Library arms you with the right data at the right time to make informed decisions […]

Browse More Resources