Platform

Threat Actor Profiles

Validin aggregates IOCs and intelligence from malware feeds, DNS telemetry, OSINT sources, and infrastructure scanning, and makes it available as Threat Profiles.

app.validin.com
How it works

The reporting and the infrastructure, in one record

A profile collects what is known about a threat group or malware family: the indicators attributed to it, the open source reporting behind those attributions, and the infrastructure it operates.

Because the indicators sit on top of our own collection, a profile is more than a reading list. Every domain and address in it opens into full DNS and reputation history, so you can see what the actor’s infrastructure is doing now, not only what a report said it was doing then.

  • Identify active and emerging threat groups
  • Investigate the infrastructure associated with an actor
  • Track newly added indicators and research reports
  • Pivot straight into detailed DNS and reputation data
January April August Domains 14 new 9 new 22 new IP addresses 6 new 11 new 8 new Registrar same same same Hosting region same same same Cert issuer same same same Panel response same same same ROTATES PERSISTS SAME OPERATOR, THREE CAMPAIGNS

Assets rotate between campaigns. The practices in the profile hold.

Sources

Built from multiple intelligence sources

Profiles are assembled from DNS telemetry, OSINT feeds, and threat research databases, alongside Validin’s own collection and infrastructure scanning. Where a well-known source has named a group, the profile carries that name and the reference behind it.
J F M A M J J A S O N D Campaign A Campaign B Campaign C NEW REGISTRAR NEW HOSTING REGION

Indicator activity for one group, quarter by quarter.

Get in touch

Contact us

Validin is the first tab I open every morning.
Senior Analyst, Financial Services IT Company