Indicators
Block and hunt

Network and TLS indicators that are most useful right now

This layer combines network IOCs and TLS signals into a compact worklist for perimeter, SOC and hunt teams. The goal is not to show as many indicators as possible, but to isolate the signals that currently deliver the most defensive value.

Network IOCs ...

Recent C2 and network indicators with direct block or hunt value.

JA3 / TLS ...

Malicious TLS client profiles and related fingerprint pressure.

Live sources ...

Number of sources currently returning usable indicators.

Indicator Type Context Action First seen
Feed is loading ... ... ... ...
Operational use

How this indicator layer should be read and used

The quality of an indicator layer shows in its ability to separate noise from signals that should lead directly to blocking, hunting or validation.

Block where speed actually reduces risk

Not every indicator belongs on a blocklist. The value sits in distinguishing signals that can prevent damage immediately from signals that mainly provide context or confirmation.

  • Prioritise network IOCs with current C2 pressure or broad validation for perimeter, proxy and mail controls.
  • Use JA3 and TLS signals where detection, validation or controlled blocking fits better than blind filtering.
  • Do not confuse exploit pressure around vulnerabilities with IOCs, but use it to accelerate patching and mitigation.

Steer hunts by repetition, context and correlation

Indicators gain weight when they are read as clusters. A single IP address says little; recurring combinations of infrastructure, fingerprinting and malware families can drive concrete hunt questions.

  • Search by recent first seen, recurring malware labels and similar access patterns.
  • Use clusters to test SIEM, EDR and network telemetry against the same behaviour pattern.
  • Always connect matches back to campaigns, victims and vulnerabilities so context does not disappear into loose signals.

Validate whether your own environment can actually be hit

The key question remains whether an indicator has meaning in your own environment. Only then does intelligence move from market information to concrete defensive relevance.

  • Compare indicators with internet-facing assets, identity behaviour and mail flows in your own environment.
  • Use exploit pressure to verify whether vulnerable technology is actually present in the stack.
  • Escalation deserves breadth only when multiple indicators confirm the same risk story.
Next layer

Connect indicators to behaviour and attack patterns

Indicators show what is visible now. The TTP layer explains the behaviour behind it, how it repeats and where the same attack pattern may appear again.

Open TTP Matrix