Posts

Showing posts with the label SOC

IP and Domain Reputation: Using Blocklists Without Breaking Production

Reputation data is the easiest threat intelligence to obtain and the easiest to misuse. Feeds of known-bad IP addresses and domains are abundant, mostly free, and trivially importable. The hard part is deciding what to do with an indicator once you have it, because the naive answer — block everything on every list — will take production down within a week. What Reputation Data Is A reputation feed is a list of network identifiers associated with malicious activity, usually with some metadata: what the indicator was seen doing, when it was last observed, and how confident the source is. Sources vary in quality and in what they actually measure. Community-reported abuse databases aggregate submissions from operators whose systems were attacked. Commercial feeds derive indicators from sensor networks and sandbox detonations. Sinkhole and honeypot data captures what is scanning and exploiting right now. Internet-wide scanning services such as those described in Censys and...