The reporting and the infrastructure, in one record
A profile collects what is known about a threat group or malware family: the indicators attributed to it, the open source reporting behind those attributions, and the infrastructure it operates.
Because the indicators sit on top of our own collection, a profile is more than a reading list. Every domain and address in it opens into full DNS and reputation history, so you can see what the actor’s infrastructure is doing now, not only what a report said it was doing then.
- Identify active and emerging threat groups
- Investigate the infrastructure associated with an actor
- Track newly added indicators and research reports
- Pivot straight into detailed DNS and reputation data
Assets rotate between campaigns. The practices in the profile hold.