All use cases

Intelligence feeds

Customized Threat Intelligence

Investigate, curate, and build feeds in one place, so the most relevant intelligence reaches your team.

Challenge

Commercial feeds are tuned for the average

The barrier to targeting organizations has never been lower. Leverage Validin’s historical context to proactively discover new infrastructure.
  • Define a feed from a fingerprint, a hosting pattern, or a saved query
  • Search 7 years of data to detect false positives and discover long-running infrastructure
  • Share and collaborate on detections directly in the Validin Platform with your team
CANDIDATE MATCHES 1,284 Exclude shared hosting Require body match TESTED AGAINST FULL HISTORY IN THE FEED 37

Isolate malicious infrastructure from false positives using high-fidelity fingerprints

Approach

A single detection keeps returning matches

Attackers dynamically rotate infrastructure. To track it, you need a query that keeps running: as we collect new data, new hosts that match your rule are detected automatically. Write the rule once and it keeps working, without manually searching each one individually.
ONE SAVED FINGERPRINT · NEW MATCHES PER WEEK 4 W1 none W2 11 W3 2 W4 none W5 19 W6 7 W7 3 W8 WRITTEN ONCE, REVIEWED WHEN IT FIRES

A single fingerprint can uncover new infrastructure for months

In practice

From one confirmed domain to a feed the team relies on

  1. 01

    Begin with what you already know

    A single confirmed domain from an incident, a report, or an alert.

  2. 02

    Find the features that tie it together

    DNS records, certificates, response bodies, or hashes, any attribute that identifies the cluster

  3. 03

    Test your rule against years of history

    Review every matching host to eliminate false positives

  4. 04

    Publish your rule and keep watching

    Refine and modify your rule as new matches arrive

Get in touch

Contact us

Validin is the first tab I open every morning.
Senior Analyst, Financial Services IT Company