> For the complete documentation index, see [llms.txt](https://breachtrace.gitbook.io/vulnkeeper/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://breachtrace.gitbook.io/vulnkeeper/chapter-f/17-17-threat-intelligence-malware-ransomware-and-in-the-wild-exploitation-context.md).

# 17. Threat intelligence, malware, ransomware & in-the-wild exploitation context

## 17.1 Major threat research sources

<table><thead><tr><th width="89.9453125" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>Mandiant / Google Cloud Threat Intelligence</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence">cloud.google.com/blog/topics/threat-intelligence</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog; commercial threat intel products separate</td><td><strong><code>Relevance</code>:</strong> Threat intelligence &#x26; exploitation-in-the-wild context.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for campaign-level vulnerability exploitation context.</td></tr><tr><td align="right">2</td><td><strong>Microsoft Threat Intelligence blog</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.microsoft.com/en-us/security/blog/topic/threat-intelligence/">www.microsoft.com/en-us/security/blog/topic/threat-intelligence</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog</td><td><strong><code>Relevance</code>:</strong> Microsoft threat intel &#x26; exploitation reports.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for attacker behavior, exploitation campaigns, &#x26; mitigations.</td></tr><tr><td align="right">3</td><td><strong>Google Threat Analysis Group</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://blog.google/threat-analysis-group/">blog.google/threat-analysis-group</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog</td><td><strong><code>Relevance</code>:</strong> Nation-state &#x26; high-end threat research.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for exploited-in-the-wild context.</td></tr><tr><td align="right">4</td><td><strong>Palo Alto Unit 42</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://unit42.paloaltonetworks.com/">unit42.paloaltonetworks.com</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog; commercial threat intel services separate</td><td><strong><code>Relevance</code>:</strong> Threat research &#x26; vulnerability exploitation reporting.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for campaign &#x26; malware context.</td></tr><tr><td align="right">5</td><td><strong>Cisco Talos</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://blog.talosintelligence.com/">blog.talosintelligence.com</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog; commercial Cisco products separate</td><td><strong><code>Relevance</code>:</strong> Threat intel, malware, &#x26; vulnerability research.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for IOCs &#x26; exploit campaigns.</td></tr><tr><td align="right">6</td><td><strong>Rapid7 vulnerability management blog</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.rapid7.com/blog/tag/vulnerability-management/">www.rapid7.com/blog/tag/vulnerability-management</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog; commercial products separate</td><td><strong><code>Relevance</code>:</strong> Vulnerability management &#x26; exploitability commentary.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for operational triage context.</td></tr><tr><td align="right">7</td><td><strong>Sophos X-Ops</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://news.sophos.com/en-us/category/threat-research/">news.sophos.com/en-us/category/threat-research</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog; commercial products separate</td><td><strong><code>Relevance</code>:</strong> Threat research &#x26; incident reports.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for exploitation context &#x26; malware behavior.</td></tr><tr><td align="right">8</td><td><strong>CrowdStrike Blog</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.crowdstrike.com/en-us/blog/">www.crowdstrike.com/en-us/blog</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog; commercial products separate</td><td><strong><code>Relevance</code>:</strong> Threat intelligence &#x26; incident research.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for adversary behavior &#x26; vulnerability exploitation context.</td></tr><tr><td align="right">9</td><td><strong>SentinelOne Labs</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.sentinelone.com/labs/">www.sentinelone.com/labs</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog; commercial products separate</td><td><strong><code>Relevance</code>:</strong> Malware &#x26; threat research.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for exploit chains &#x26; malware analysis.</td></tr><tr><td align="right">10</td><td><strong>Kaspersky Securelist</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://securelist.com/">securelist.com</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog; commercial products separate</td><td><strong><code>Relevance</code>:</strong> Threat research &#x26; malware analysis.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for campaign-level context.</td></tr><tr><td align="right">11</td><td><strong>ESET WeLiveSecurity</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.welivesecurity.com/">www.welivesecurity.com</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog; commercial products separate</td><td><strong><code>Relevance</code>:</strong> Threat research &#x26; malware analysis.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for exploitation narratives &#x26; IOCs.</td></tr><tr><td align="right">12</td><td><strong>Trend Micro Research</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.trendmicro.com/en_us/research.html">www.trendmicro.com/en_us/research.html</a><br><br><strong><code>Access / Cost</code>:</strong> Free public research; commercial products separate</td><td><strong><code>Relevance</code>:</strong> Threat &#x26; vulnerability research.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for active exploitation context.</td></tr><tr><td align="right">13</td><td><strong>FortiGuard Labs</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.fortiguard.com/research">www.fortiguard.com/research</a><br><br><strong><code>Access / Cost</code>:</strong> Free public research; commercial products separate</td><td><strong><code>Relevance</code>:</strong> Fortinet threat research.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for attack patterns &#x26; indicators.</td></tr><tr><td align="right">14</td><td><strong>Check Point Research</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://research.checkpoint.com/">research.checkpoint.com</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog; commercial products separate</td><td><strong><code>Relevance</code>:</strong> Threat research &#x26; vulnerability analysis.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for campaign &#x26; exploit analysis.</td></tr><tr><td align="right">15</td><td><strong>Elastic Security Labs</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.elastic.co/security-labs">www.elastic.co/security-labs</a><br><br><strong><code>Access / Cost</code>:</strong> Free public research; commercial products separate</td><td><strong><code>Relevance</code>:</strong> Detection engineering &#x26; threat research.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for detection logic &#x26; adversary behavior.</td></tr><tr><td align="right">16</td><td><strong>Sekoia Threat Intelligence</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://blog.sekoia.io/">blog.sekoia.io</a><br><br><strong><code>Access / Cost</code>:</strong> Free public blog; commercial threat intel separate</td><td><strong><code>Relevance</code>:</strong> Threat intelligence research.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for IOCs &#x26; campaign context.</td></tr></tbody></table>

## 17.2 Malware & IOC repositories

<table><thead><tr><th width="93.04296875" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>MISP</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.misp-project.org/">www.misp-project.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source; data sharing depends on communities/instances</td><td><strong><code>Relevance</code>:</strong> Threat intelligence sharing platform.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for IOC correlation &#x26; sharing.</td></tr><tr><td align="right">2</td><td><strong>AlienVault OTX</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://otx.alienvault.com/">otx.alienvault.com</a><br><br><strong><code>Access / Cost</code>:</strong> Free community access; commercial AT&#x26;T Cybersecurity products separate</td><td><strong><code>Relevance</code>:</strong> Open threat exchange for IOCs.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Quality varies by pulse/source. Validate before enforcement.</td></tr><tr><td align="right">3</td><td><strong>AbuseIPDB</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.abuseipdb.com/">www.abuseipdb.com</a><br><br><strong><code>Access / Cost</code>:</strong> Free tier / paid plans</td><td><strong><code>Relevance</code>:</strong> IP abuse reputation database.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for IP enrichment; not vulnerability-specific.</td></tr><tr><td align="right">4</td><td><strong>URLhaus</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://urlhaus.abuse.ch/">urlhaus.abuse.ch</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Malware URL tracking.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for IOC enrichment.</td></tr><tr><td align="right">5</td><td><strong>MalwareBazaar</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://bazaar.abuse.ch/">bazaar.abuse.ch</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Malware sample sharing.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for malware family &#x26; hash enrichment.</td></tr><tr><td align="right">6</td><td><strong>ThreatFox</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://threatfox.abuse.ch/">threatfox.abuse.ch</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Threat intelligence indicators.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for IOCs.</td></tr><tr><td align="right">7</td><td><strong>Feodo Tracker</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://feodotracker.abuse.ch/">feodotracker.abuse.ch</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Botnet C2 tracking.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for malware infrastructure context.</td></tr><tr><td align="right">8</td><td><strong>PhishTank</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://phishtank.org/">phishtank.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free community access; API/account may be required</td><td><strong><code>Relevance</code>:</strong> Phishing URL database.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for phishing exposure &#x26; IOC enrichment.</td></tr><tr><td align="right">9</td><td><strong>OpenPhish</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://openphish.com/">openphish.com</a><br><br><strong><code>Access / Cost</code>:</strong> Free limited feed / paid premium feeds</td><td><strong><code>Relevance</code>:</strong> Phishing intelligence.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Commercial/community source; check terms.</td></tr><tr><td align="right">10</td><td><strong>YARA</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/VirusTotal/yara">github.com/VirusTotal/yara</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Malware classification &#x26; pattern matching engine.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for detection signatures.</td></tr><tr><td align="right">11</td><td><strong>YARA-Rules</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/Yara-Rules/rules">github.com/Yara-Rules/rules</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Community YARA rules.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Validate rule quality before production use.</td></tr><tr><td align="right">12</td><td><strong>SigmaHQ</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/SigmaHQ/sigma">github.com/SigmaHQ/sigma</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Generic SIEM detection rule format.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for detection engineering.</td></tr><tr><td align="right">13</td><td><strong>LOLBAS</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://lolbas-project.github.io/">lolbas-project.github.io</a><br><br><strong><code>Access / Cost</code>:</strong> Free public / open-source project</td><td><strong><code>Relevance</code>:</strong> Living-off-the-land binaries/scripts catalog.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for attack behavior detection.</td></tr><tr><td align="right">14</td><td><strong>GTFOBins</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://gtfobins.github.io/">gtfobins.github.io</a><br><br><strong><code>Access / Cost</code>:</strong> Free public / open-source project</td><td><strong><code>Relevance</code>:</strong> Unix binary abuse catalog.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for privilege escalation &#x26; post-exploitation detection.</td></tr><tr><td align="right">15</td><td><strong>Ransomware.live</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.ransomware.live/">www.ransomware.live</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Ransomware group/leak-site tracking.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for ransomware exploitation context &#x26; trend analysis.</td></tr></tbody></table>

## Discussion

This chapter section keeps the latest table structure, source titles, access/cost fields, relevance notes, & operational notes from the source inventory. Review the table entries as ingestion candidates, then validate source freshness, licensing, authentication requirements, & link-check behavior before production use.

***

#### [Back to Index](/vulnkeeper/index.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://breachtrace.gitbook.io/vulnkeeper/chapter-f/17-17-threat-intelligence-malware-ransomware-and-in-the-wild-exploitation-context.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
