All use cases

Enrichment

Security Stack Enrichment

Reputation, resolution history, hosting, services, and registration, delivered into the SIEM and SOAR your team already works in, with enough depth to turn an alert into a verdict.

Challenge

A lone indicator is not enough to act on

A single domain in your logs forces every SOC analyst to resolve alerts manually. Each one means the same set of questions, answered one at a time: is it shared hosting, has it ever served content, what has it resolved to, has anyone reported it.
  • Enrich alerts in the SIEM with reputation, hosting, and history
  • Give SOAR playbooks fields concrete enough to route on
  • Verdicts backed by evidence you can inspect
7.8 RISK SCORE 0 10 Maltrail: TA569 malware Block lists 3 hits OSINT sources 9 sightings Popularity rank unranked

Aggregate risk and the individual signals behind it, returned together.

What comes back

Dozens of indexed pivots, with the history behind each

A verdict alone is not enough. Analysts need evidence to establish whether an indicator is malicious, and enough granularity to know what to search for next in their own logs.

Reputation and sightings

Blocklist matches, OSINT references, and popularity signals, each attributed directly to the source.

Resolution history

Every IP address a domain has resolved to and every domain an IP address has hosted, going back 7 years.

Hosting and location

Provider, ASN, and region, including whether the address is shared infrastructure.

Response characteristics

What the host was serving and when, so detections can match on how a host behaves, not on names.

Approach

Extended history turns a lookup into a verdict

A reputation score tells an analyst what someone else concluded. History lets them conclude it themselves: what the address hosted last month, which domains were hosted together, and what those hosts were serving while they were live.
  • Pivot from one indicator through shared DNS, registration, certificates, and responses
  • Settle maliciousness from the host’s history, not from a score
  • Sweep your logs for the related infrastructure while the alert is still open
SEED · ONE CONFIRMED DOMAIN 1 HOP 1 · SHARED A RECORD 6 HOP 2 · SHARED NAME SERVER 34 HOP 3 · SHARED TLS CERTIFICATE 112 HOP 4 · SHARED RESPONSE BODY HASH 287

One confirmed domain reaches 287 related hosts in four pivots. Each one is a candidate to search your logs for.

Beyond triage

A feed of what targets you

Leverage Validin’s insights while triaging alerts to build custom detections and feeds of infrastructure targeting your organization directly. Eliminate false positives by searching through our data for hosts that matched on specific features.
CANDIDATE MATCHES 1,284 Exclude shared hosting Require body match TESTED AGAINST FULL HISTORY IN THE FEED 37

Candidates reduced by rules your team wrote, tested against our historic database.

In practice

One alert, turned into a feed

An external address flagged by a detection, taken from the triage queue to an entire cluster

  1. 01

    The enriched alert routes itself

    The SOC holds two neighbouring alerts that are on shared hosting and flagged by a public phishing feed

  2. 02

    Historic data identifies malicious activity

    Three weeks ago the address hosted four domains serving a cloned login page. The score said suspicious; the historic record tells you why.

  3. 03

    Related infrastructure goes to the logs

    Those four domains and the hosts that succeeded them become a log search.

  4. 04

    The cluster becomes a feed

    The response fingerprint that tied it together is run periodically as a standing query. The next domain the operator stands up lands in the SIEM on its own.

Get in touch

Contact us

Validin is the first tab I open every morning.
Senior Analyst, Financial Services IT Company