Skip to main content

Unified Threat Intelligence

Malware detection is an essential capability for modern businesses that helps them identify threats and malicious activity posing a risk to their environments, investigate them, and respond quickly.

Threat intelligence feeds are trusted sources of information about potential cyber threats, such as malicious activity. With that said, incorporating threat feeds into your data to detect suspicious activity can require complex configuration, often leading to the sub-utilization of this important source of information.

The Coralogix Unified Threat Intelligence relies on our Streama© technology to provide you with built-in seamless integration with some of the world’s leading threat intelligence feeds with hundreds of thousands threat entities curated by our security experts.

Coralogix does not require any API integration, special syntax, or format change. It automatically enriches your data with malicious indicators in real-time as they are streamed, allowing you to query, visualize, and alert on potential threats.

Enriched information is then stored to your own remote storage. This allows you to query directly from Coralogix with infinite retention and even research the data with external tools.

What you need

  • SECURITY-ENRICHMENT:READCONFIG: view Unified Threat Intelligence Enrichment configuration (Data Admin, Observability Lead, Platform Admin, Security User).
  • SECURITY-ENRICHMENT:UPDATECONFIG: create or manage Unified Threat Intelligence Enrichment (Data Admin, Platform Admin, Security User).

How can the Unified Threat Intelligence help to improve my security?

Take a look at these use-cases to get a feel for the many ways that our Unified Threat Intelligence can serve you.

Use-Case 1: Detection of Phishing Attempts

Phishing is a social engineering attack practice, causing people to share credentials, sensitive information or install malware by impersonating a legitimate website. The Unified Threat Intelligence helps you detect any network activity from your organization’s environment to a reported phishing website, allowing you to identify which users were involved and investigate the impact.

Use-Case 2: Detection of Browsing of Malicious Websites

Phishing is the number one attack vector to infiltrate your organization by obtaining user credentials. The Unified Threat Intelligence helps you detect any user visiting a phishing site (through domain/URL) or a phishing site that is hosted on your infrastructure.

Use-Case 3: Detection of Potential Data Exfiltration

Malware installed on an internal machine in your environment may gain access to your sensitive data and exfiltrate it by uploading this data to an attacker’s website. The Unified Threat Intelligence helps you to immediately detect network activities to such websites reported as malicious, block them, and assess the data leakage that may have occurred.

Use-Case 4: Bot Detection by Command and Control Communication Monitoring

Hackers use bots to perform large scale attacks. These include denial of service (DDoS) attacks that can flood a website with connection requests, causing it to stop serving legitimate customers, distribute spam emails, make fraudulent purchases, and more. C&C communication is used by hackers to send the operation commands to the bots. The Unified Threat Intelligence allows you to detect this command and control communication by inspecting your network activity logs and discovering communication to/from command and control servers. Using this feature, you can easily see which machines perform this network activity and are infected with bots.

Use-Case 5: Detection of Brute-Force Scanning

Hackers use brute-force scanning to scan your network environment and find exposed resources which allow them to penetrate your environment and attack it. The Unified Threat Intelligence allows you to detect incoming network traffic coming from IPs and servers reported as malicious. With this improved security posture, you can block those requests, assess any risk and its impact, and immediately decide upon mitigation steps.

How it works

Coralogix operates a dedicated Threat Intel Platform that collects indicators of compromise (IOCs) from multiple source classes, then validates, scores, and maintains them before they are used for enrichment.

The flow has three stages:

1.

Collection. Open-source feeds, security research publications, internal incident investigations, and structured threat reports are polled continuously for new indicators.

2.

Processing. The Threat Intel Platform removes duplicate IOCs, applies AI-based context enrichment, assigns each indicator a confidence score from 0 to 100, and applies a time-based decay rule so stale intelligence loses weight over time.

3.

Enrichment and detection. Scored indicators are pushed to the Coralogix platform, where incoming logs are normalized, matched against the indicator set, and enriched in real time. Enriched logs feed the out-of-the-box alerts and dashboards described below.

Threat intelligence sources

Indicators are collected from four complementary source classes. All sources are aggregated, de-duplicated, and validated before they reach your account.

Source classDescription
Open-source feedsContinuously polled public IOC feeds covering IP addresses, domains, URLs, and file hashes.
Security research publicationsMore than 70 vendor and independent research blogs, monitored for fresh IOCs from emerging campaigns.
Internal incident collectionIndicators surfaced by Snowbit MDR investigations and live incident response.
Threat reports and CISA KEVStructured threat reports and the CISA Known Exploited Vulnerabilities catalog.

Monitored open-source feeds

FeedFocus
ThreatFoxCommunity-shared malware and botnet C2 indicators: IPs, domains, URLs, and hashes with malware family tags.
URLhausMalicious URLs used for malware distribution and payload delivery.
LevelBlue Open Threat Exchange (OTX)Community threat-sharing platform, formerly AlienVault OTX, covering all indicator types.
Feodo TrackerBotnet C2 IP addresses associated with banking trojans and loaders.
Criminal IP C2-Daily-FeedDaily malicious and C2 IP addresses from the Criminal IP threat-hunting engine.
drb-ra C2IntelFeedsAutomated C2 IP, domain, and URL feeds covering Cobalt Strike, Sliver, Mythic, and other frameworks.
VX VaultMalware distribution URLs with payload hashes.
Red Flag DomainsDaily lists of probably malicious newly registered domains.
Emerging ThreatsProofpoint ET Open IDS rulesets and block IP lists across broad threat categories.
TweetFeedIOCs published by the infosec community on X (Twitter): URLs, domains, IPs, and hashes.
OpenPhishAutomated phishing URL detection with targeted-brand metadata.
Tor Bulk Exit ListThe Tor Project's official list of current Tor exit node IP addresses.
Binary Defense banlistAttacker and scanner IPs from the Binary Defense Artillery honeypot network.
Coralogix in-built C2 trackerAutomated C2 IP tracking that covers a variety of trending C2 frameworks used by adversaries.

Supported indicator types

Six indicator types are scored, contextualized, and matched against your telemetry in real time.

Indicator typeDescription
IP addressMalicious source and destination addresses, including botnet nodes and Tor exit nodes.
DomainKnown-bad and newly registered domains used for phishing, malware delivery, and command and control.
URLPhishing, command and control, and malware-hosting links.
File hashMalware sample hashes (MD5 and SHA families).
JA3 fingerprintTLS client fingerprints used to identify command and control tooling.
JA4 fingerprintNext-generation TLS fingerprints with improved resistance to evasion.

How confidence scores are assigned

The initial confidence score reflects the threat category the indicator belongs to. Confirmed command and control infrastructure receives the highest scores, while uncorroborated or aging intelligence starts low and must earn a higher score through additional reporting. The scores in the table below are normalized to a 0 to 10 band.

ScoreCategoryExamplesRationale
10APT / C2UNC6771, APT36, Cobalt Strike, Havoc, Brute Ratel, Sliver, MythicActive command and control frameworks on confirmed malicious infrastructure.
9Offensive security toolsMetasploit, Meterpreter, PoshC2, Empire, CovenantKnown attack frameworks found on open ports; a strong indicator of compromise.
9Remote access trojansAsyncRAT, Remcos, QuasarRAT, NjRAT, DarkCometRemote access trojans with confirmed C2 panels.
8Malware hostingDomains serving FakeApp, ClearFakeConfirmed malicious domains distributing malware.
8Phishing kits / campaignsGophish, Evilginx, ModlishkaDetected phishing infrastructure.
8Information stealersRedLine, Raccoon, Vidar, LummaC2, StealCStealer families with active C2.
7Exploit kits and fake updatesClearFake, SocGholish, fake browser update campaignsDrive-by download infrastructure.
7CryptominersXMRig and other Monero miners on serversUnauthorized mining activity that indicates compromise.
6Botnet C2Mirai, Mozi, and Gafgyt command serversBotnet command servers, as opposed to the devices they control.
5Botnet-infected devicesMirai-infected devices, IoT botsInfected endpoints; often victims rather than attackers.
5Scanner activityPort scanners, SSH brute force, web scannersMay be attackers or legitimate security researchers.
4SuspiciousSingle-source report with no corroborationRequires more evidence; the score rises as additional feeds report the indicator.
3UnverifiedAged IOCs, expired domains, inactive IPsMay no longer be relevant; subject to decay and revocation.

Scores are not static. An indicator reported by multiple independent feeds gains confidence, while an indicator that stops appearing in fresh intelligence decays toward the revoke threshold and is eventually retired.

Risk scoring and indicator lifecycle

Every indicator carries a risk score that reflects current confidence in its maliciousness.

  • Initial score. When an indicator is created, it receives a score on a 0 to 100 scale, assigned from the incoming feed or set by the Snowbit Threat Intel team.
  • Time-based decay. A decay rule steadily lowers the score as the intelligence ages. New corroborating evidence raises the score again.
  • Revocation. When an indicator's score falls below the revoke threshold, it is retired from the active set. This keeps the indicator set current and cuts alert noise from stale intelligence.
  • Normalization on ingestion. When indicators are pushed into Coralogix, the score is normalized to a 0 to 10 band, which simplifies alert thresholds.

For example, an IP address reported by a C2 tracker might enter the platform with a score of 8. If no further sightings occur, decay reduces the score toward the revoke threshold over the following weeks. If a new report confirms the address is still active, the score rises again and the indicator remains in the active set.

Indicator risk score rising on new sightings and decaying toward the revoke threshold over time

Enriched fields

If an IP, URL, or domain value in your log is reported as malicious, a new field named <key_name>_suspected is added to the relevant log, with key_name serving as the original log key. The field records the matched value, the number of feeds that reported it, and per-feed detail.

The <key_name>_suspected field contains the following fields:

FieldDescription
malicious_valueActual value reported to be malicious
reporting_feedsList of feeds that reported this value as malicious
total_feedsIncludes the number of the feeds in reporting_feeds and can be used in queries and alerts as a confidence level.

Feeds that supply adversary context add the following detail to their entry under reporting_feeds:

{
"adversary": {
"confidence_level": 8,
"date_identified": "2026-07-26",
"feed_name": "Coralogix",
"industry": "Multi-sector",
"ioc_source": "blog",
"malware_family": "AdaptixC2",
"notes": "Traffic seen on port 4321",
"reference": "",
"tags": [
"confidence:high",
"status:unclassified",
"type:ipv4"
],
"targeted_countries": [
"Global"
],
"type": "IPv4"
}
}

This enrichment is executed automatically while your logs are being streamed into Coralogix. All you need to do is to define which log keys contain IPs, URLs, or domains that should be looked up in the threat intelligence feeds and enriched upon a match.

To get the best value, it is recommended to create alerts based on these enriched logs, to be notified as soon as possible upon detection of potential malicious network traffic and respond immediately.

Get started

1.

Navigate to Data Flow, then Data Enrichment.

2.

Select Enrich threat intelligence to open the editor.

3.

Select the JSON keys containing IPs, URLs, or domains to look up and enrich with malicious activity indicators.

4.

Select Add Key.

Note

If your logs don’t have a dedicated field for IP, URL, or domain, or your data isn’t JSON-formatted, you can use our parsing rules to extract these precise values from your log record into a dedicated key, to be looked up in the threat intelligence fields and enriched if they match.

From that point on, every incoming log with a value in a selected key is checked against the indicator set and enriched automatically.

Query enriched logs

Use DataPrime to explore enriched logs.

Find all logs where an IP was flagged as malicious:

source logs
| filter $d.cx_security.source_ip_suspected != null

Surface the most frequently seen malicious values so you can prioritize investigation:

source logs
| filter $d.cx_security.source_ip_suspected != null
| groupby $d.cx_security.source_ip_suspected.malicious_value aggregate count() as hits
| orderby hits desc
| limit 10

Focus on high-confidence matches only:

source logs
| filter $d.cx_security.source_ip_suspected.reporting_feeds.Coralogix.confidence_level >= 7

Dashboards

Unified Threat Intelligence ships with dashboards that answer both executive and analyst questions.

  • Executive overview. A single-pane summary of threat activity across your environment: match volumes, trends, and the most active threat types.

Executive overview dashboard summarizing threat match volumes, trends, and the most active threat types

  • Threat type deep dive. Drill into individual threat families, from ransomware and malware variants to connection-level source and destination mapping per threat type.

Threat type deep dive dashboard breaking down individual threat families and their connections

  • Geo intelligence maps. World-map views aggregate malicious source and destination IPs by geography for fast attribution and region-based awareness.

World map aggregating malicious source and destination IP addresses by country

  • Most targeted ports. Identifies which services attackers probe most, useful for prioritizing exposure reduction.

Dashboard panel ranking the ports most frequently targeted by malicious traffic

  • Network threat activity. Time-series charts and enriched connection logs track malicious IPs, Tor exit nodes, and targeted destinations with application-level context.

Network threat activity dashboard with time-series charts and enriched connection logs

You can also build your own custom dashboards by querying logs that contain the enriched <key_name>_suspected field.

Bring your own intelligence

The platform is fully extensible. You can layer your own intelligence and enrichment on top of everything Coralogix delivers.

Custom threat intelligence. Ingest commercial feeds, ISAC and sharing-group intelligence, and internal IOC lists via STIX and TAXII. Your indicators are scored and decayed alongside Coralogix sources.

Out-of-the-box alerts

Pre-built Unified Threat Intelligence alerts fire the moment enriched telemetry matches a malicious indicator.

AlertTriggers when
Outgoing traffic to Malicious IPA log records a connection from your environment to a known-malicious IP address.
Incoming traffic from Malicious IPA log records a connection into your environment from a known-malicious IP address.
Malicious URL detectedA log contains a URL that matches a malicious indicator.
Malicious domain detectedA log contains a domain that matches a malicious indicator.
Malicious JA3 fingerprint detectedA TLS connection log carries a JA3 hash that matches known malicious tooling.
Malicious JA4 fingerprint detectedA TLS connection log carries a JA4 fingerprint that matches known malicious tooling.
Malicious file hash detectedA log contains a file hash that matches a known malware sample.

Some of the extensions, such as "Snowbit STA", automatically configure their product log keys to be enriched by the Unified Threat Intelligence, as well as add predefined alerts to notify you immediately upon detection of malicious activity.

Additional resources

Simplify Threat Detection with Unified Threat Intelligence

Next steps

Add geographic location data to your logs based on IP addresses with Geo enrichment.

Last updated on