When I use this
You have a domain, IP, URL, or hash and want to read it as a defensive signal.
IOC workflow
A workflow for checking IPs, domains, URLs, and hashes as defensive signals.
Passive and safe research workflow
When I use this
You have a domain, IP, URL, or hash and want to read it as a defensive signal.
What you get
Indicator context, source comparison, freshness note, and defensive action.
What I would be careful with here
The order I follow
Write the indicator type, source, and observation time.
The type and time are visible.
Compare reputation, passive DNS, malware feeds, and reports.
One feed is not the only basis.
Record first seen, last seen, and whether the signal is old.
Old indicators are not treated as current activity.
Suggest monitoring, blocking, or review only when the evidence supports it.
Attribution is not overstated.
Sources I open
What I can and cannot say
The indicator appears in open threat sources, but freshness, context, and local relevance must be checked before action.
Move to evidence notesSources
AlienVault OTX
Threat intelligence
Open threat exchange for pulses, indicators, and community threat intelligence.
Open sourceANY.RUN
Malware intelligence
Interactive malware sandbox and public task repository.
Open sourceAwesome Threat Intelligence
Threat intelligence
A broad GitHub list of threat-intelligence datasets, tools, platforms, and learning resources.
Open sourceCISA Known Exploited Vulnerabilities Catalog
CVE and vulnerability tracking
Authoritative CISA catalog of vulnerabilities known to be exploited in the wild.
Open sourceCVE.org
CVE and vulnerability tracking
Official CVE program site for CVE records and CNA information.
Open sourceFeodo Tracker
Malware intelligence
Abuse.ch tracker for botnet command-and-control infrastructure.
Open source