// Investigation

Threat intelligence

Indicators are matched against the whole event window on every sweep, so intel added today surfaces telemetry already stored. Indicators at 60% confidence or above raise alerts; below that they enrich without adding to the queue.

6indicators6active0with sightings5feeds

Indicator feed

0 total sightings recorded across all indicators.

OnTypeIndicatorSeverityConfidenceContextSightingsLast seenAction
IP address185.100.200.50Critical95%Source of the interactive logon in the jsmith takeover.Internal IR · takeover chain · Analyst0never
IP address45.137.21.9High80%Reported command-and-control node, active in the last 30 days.Abuse.ch feed · Analyst0never
Domaincdn-update-delivery.netHigh75%Payload staging domain masquerading as a content delivery host.Abuse.ch feed · Analyst0never
File hashe3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855High70%Loader observed alongside encoded PowerShell staging.Vendor advisory 2026-08 · Analyst0never
Domainpaste-share-quick.ioMedium45%Paste site used for exfiltration in unrelated campaigns.OSINT · analyst submission · Analyst0never
User agentpython-requests/2.31Low30%Scripted client. Common in automation as well as tooling, so it enriches rather than alerts.Internal baseline · Analyst0never