A global leader for internet #intel that enables security practitioners to proactively defend their organization in a constantly evolving threat landscape.
Our team at DomainTools Investigations (DTI) took a deep dive into the ZionSiphon malware sample(“SCADA_SecurityPatch_v8.4.exe”) that’s been circling in sandboxes since 2025.
Read our investigation here⬇️ https://t.co/hwGARkLRo3
#Cybersecurity#ICS#Malware#InfoSec#DomainTools
We are excited to announce our IP risk and IP hotlist are now available in real-time feeds. These feeds give you access to all IP addresses which can be filtered to show only the most dangerous and currently active infrastructure. Learn more: https://t.co/ExC9dLUmyM
📰Real Fake News: DTI’s latest research on the Russian-backed Doppelgänger campaigns breaks down the organizational structure and operational distribution model that pushes “fake news” to real news feeds.
Read more: https://t.co/qt6dSNgVEj
#Cybersecurity#Infosec#News
The sun is out in Seattle and the April DTI newsletter is live! 📰☀️
@danonsecurity breaks down the DPRK’s modular malware pipelines, the MOIS-linked Handala ecosystem, and the AI Frame campaign. Plus, Ian Campbell's monthly reading list! 📚
Catch up: https://t.co/NwYmWeXU3J
Government agencies are advancing Zero Trust, but are they leveraging DNS intelligence to its full potential? DomainTools helps defenders uncover adversary infrastructure before it becomes a threat.
Learn how DomainTools empowers proactive defense here: https://t.co/ZKkZyi8cl8
DTI just released an analysis of the DPRK’s “Contagious Interview” campaign😷.
Read the investigation to learn how the campaign targets software developers through fraudulent job interview processes.⬇️
https://t.co/cwvk0pDObQ
#Cybersecurity#InfoSec#NorthKorea#ThreatIntel
Join our webinar: Supercharging the SOC with DomainTools MCP to learn how to supercharge your workflow using DomainTools MCP.
🗓️May 07, 2026
🕜 10:00 AM PT/1:00 PM ET
🔗https://t.co/sQEOsugLFW
ICYMI: IrisQL, our new query language, makes it easier than ever to share logic across teams and ticketing systems.
Explore how to optimize your security stack here: https://t.co/I51lxcknri
#ThreatHunting#IrisQL#Infosec#DataScience
💥Level up your threat hunting with IrisQL, our new query language for deeper, more flexible access to the Iris Investigate database.
Explore the full breakdown and start optimizing your security stack here: https://t.co/I51lxcknri
#ThreatHunting#IrisQL#Infosec#DataScience
Deploy clean, update dirty 🧼
DTI identifies a Chrome extension tied to a malicious campaign that publishes utility software that has legitimate functionality but with pre-staged capability for a future malicious update.
Learn more: https://t.co/vC6eraIfXT
#Cybersecurity#2FA
Join us for the DomainTools webinar: Supercharging the SOC with DomainTools MCP.
Key takeaways from the session:
⏱️Instant Context, 🏁 Faster Response, 🔎Enhanced Analysis, 🧠Verifiable Intelligence
🗓️May 07, 2026
🕜 1:00 PM ET
🔗https://t.co/sQEOsugLFW
📍 We’re in Singapore for #BHA2026!
Stop by DomainTools booth # 119 to see how our integrations reduce context-switching and identify evolving threats in real-time.
It's not too late to schedule a chat ➡️https://t.co/fHpARt8bFd
#BlackHatAsia#CyberSecurity
New DTI Research: The evolution of the MOIS-linked cyber ecosystem (Handala/Homeland Justice)
from the 2022 Albania attacks to the 2026 Stryker incident🛡️🇮🇷
Full research and analysis:https://t.co/AWel81Qr24
#ThreatIntel#Handala#Cybersecurity#Iran
How do you make AI work for you in the SOC?
Join our webinar with DomainTools MCP experts Taylor Wilkes-Pierce, VP of Solutions Engineering, and Dan White, VP of Product Management to learn how the MCP server acts as an instant force multiplier.
🔗https://t.co/sQEOsugLFW
📍 Singapore bound for #BHA2026!
Stop by DomainTools booth # 119 to see how our integrations reduce context-switching and identify evolving threats in real-time.
Don't leave your 2026 strategy to chance. Schedule a chat ➡️ https://t.co/fHpARt8bFd
#BlackHatAsia#CyberSecurity
Spring is here in Seattle🌷, and the March DTI newsletter is live📰.
In this edition @DanOnSecurity recaps a busy month of research, @neurovagrant's monthly reading list, and where to find us next! https://t.co/NAPjxGTRHg
#Cybersecurity#Research#DomainTools
Access DomainTools via the Model Context Protocol (MCP) 🌐
Connect your LLM or MCP enabled platform directly to our data to:
✅ Automate data retrieval and analysis
✅ Reduce context-switching
✅ Investigate at the speed of AI
Click here to learn more: https://t.co/NPaeVMaSoX.
The most critical indicators, all in one place
New enhancements to the DomainTools App for Cortex by @PaloAltoNtwks deliver real-time streaming of critical intelligence feeds, providing seamless access to DomainTools data across Cortex.
Learn more: https://t.co/UrzYhhMsTc
Want to see how the world's best CTI teams map adversary DNS? 🗺️
We’re heading to #BlackHatAsia 2026 to share how we provide 97% internet visibility and detection 10 days ahead of blocklists.
Let's grab coffee! Book 20 mins here ➡️ https://t.co/fHpARt8bFd
#BHA2026#OSINT