Back to workflows

IOC workflow

Read threat indicators without overclaiming.

A workflow for checking IPs, domains, URLs, and hashes as defensive signals.

Passive and safe research workflow

When to use it

You have a domain, IP, URL, or hash and want to read it as a defensive signal.

What you get

Indicator context, source comparison, freshness note, and defensive action.

Safety boundary

This workflow is not for exploitation, probing, or unauthorized scanning. It reads public records, records dates and uncertainty, and avoids turning signals into final claims.

Simple order

Work through the steps in order.

  1. Classify the indicator

    Write the indicator type, source, and observation time.

    Check: The type and time are visible.

  2. Check several sources

    Compare reputation, passive DNS, malware feeds, and reports.

    Check: One feed is not the only basis.

  3. Read freshness

    Record first seen, last seen, and whether the signal is old.

    Check: Old indicators are not treated as current activity.

  4. Write a defensive conclusion

    Suggest monitoring, blocking, or review only when the evidence supports it.

    Check: Attribution is not overstated.

Report language

The indicator appears in open threat sources, but freshness, context, and local relevance must be checked before action.

Move to evidence notes

Sources

Start with these sources.

Open resource archive
  • AlienVault OTX logo

    AlienVault OTX

    Threat intelligence

    Use for IOC context, reputation checks, and defensive security notes.

    Open source
  • CISA Known Exploited Vulnerabilities Catalog logo

    CISA Known Exploited Vulnerabilities Catalog

    CVE and vulnerability tracking

    Use for vendor advisories, CVE status, exploitation context, and defensive reporting.

    Open source
  • CVE.org logo

    CVE.org

    CVE and vulnerability tracking

    Use for vendor advisories, CVE status, exploitation context, and defensive reporting.

    Open source
  • FIRST EPSS logo

    FIRST EPSS

    CVE and vulnerability tracking

    Use for vendor advisories, CVE status, exploitation context, and defensive reporting.

    Open source
  • GitHub Advisory Database logo

    GitHub Advisory Database

    CVE and vulnerability tracking

    Use for vendor advisories, CVE status, exploitation context, and defensive reporting.

    Open source
  • GreyNoise Visualizer logo

    GreyNoise Visualizer

    IP and ASN intelligence

    Use for infrastructure context, hosting traces, and network ownership checks.

    Open source