Intelligence that reaches your alerts, not your inbox.
Most threat intelligence is sold as a feed — a list delivered to a team that has to build everything around it. Hello SOC runs intelligence inside the detection pipeline: every event is checked as it arrives, and a match raises the alert with the reason already attached.
- →Botnet C2, malware hosts, brute-force sources and Tor exits
- →Applied at correlation time, to every ingested event
- →The reason travels with the alert into AI triage
- →Included on every plan — not a premium tier
What we watch for
Four categories of indicator, refreshed continuously, checked against every event that lands in your tenant.
Botnet command-and-control
Known C2 servers for active banking-trojan and loader families. A host in your network talking to one of these is not a maybe — it is an infected machine reporting in, and it is the single highest-signal thing in the set.
Malware distribution hosts
Domains and URLs actively serving malware payloads. Matched against DNS query telemetry, this catches the click before the download completes, on the resolver rather than the endpoint.
Known brute-force sources
Addresses currently running credential attacks against SSH, SMTP, and web login surfaces across the internet. Useful less as a block list than as context: a login failure from one of these is a different event from a login failure from your branch office.
Tor exit nodes
Not malicious in themselves, and we do not treat them as such. But an admin login from a Tor exit at 3am is worth a human look, and knowing the connection came from Tor is what makes that judgement possible.
What it changes in the queue
The same firewall event, with and without intelligence applied. This difference is the entire argument for enrichment.
Outbound connection allowed
10.4.2.19 → 203.0.113.45:443
One line in a log file that nobody reads, indistinguishable from the several million other allowed connections that day.
HIGH · Internal host contacted known botnet C2
10.4.2.19 → 203.0.113.45:443
4 attempts · 12 min · first seen 03:14
An incident with a verdict, a count and a timeline — which an analyst can act on without opening a single log file.
Illustrative example using documentation-reserved addresses (RFC 5737); not a real customer event.
What intelligence does not do
It is not prevention
A match tells you something already happened — a host already reached out, a login already came in. Intelligence shortens the time between compromise and discovery; it does not replace your firewall policy, MFA or endpoint controls.
It is not complete
Every indicator list lags the attacker who registered a domain an hour ago. Intelligence catches the commodity attacks that make up most of what actually hits you; the novel ones are caught by behavioural rules instead, which is why we run both.
It is not automatic blocking
Lists carry false positives, and shared hosting means one bad tenant can taint an address serving legitimate sites. Blocking goes through the approved, reversible SOAR path with a human in it.
Threat intelligence — questions we get
- What is threat intelligence, in practical terms?
- Threat intelligence is a continuously updated set of indicators — IP addresses, domains and URLs — known to be involved in attacks right now: botnet command-and-control servers, hosts distributing malware, addresses running credential attacks. On its own it is just a list. It becomes useful when something checks your actual network traffic against it automatically, which is the difference between buying a feed and running intelligence operationally.
- Which threat intelligence feeds does Hello SOC use?
- Hello SOC runs curated open threat-intelligence sources covering four categories: botnet command-and-control infrastructure, malware distribution hosts and domains, addresses currently conducting brute-force attacks, and Tor exit nodes. These are well-regarded community and research sources rather than a repackaged commercial feed, and we name the categories openly because a buyer comparing vendors deserves to know what is behind the claim. Feeds refresh continuously; the exact source list is in the technical brief we send on request.
- How is this different from buying a threat intelligence feed?
- A feed is a subscription that delivers a list to your team, who then have to build the plumbing to apply it, tune out the noise, and keep it current. Hello SOC applies intelligence at correlation time inside the detection pipeline: every ingested event is checked as it arrives, a match raises the severity of the resulting alert, and the reason travels with the alert into triage. You are buying the outcome, not the raw material.
- Does a threat-intel hit automatically block the traffic?
- Not on its own, by design. A match raises severity and lands in your queue with the context attached; blocking runs through the same approved, audit-trailed SOAR path as any other response action, with a human approving it in the dashboard and every action time-bound and reversible. Intelligence feeds have false positives — shared hosting and recycled cloud addresses in particular — and automatically blackholing on a list match is how a SOC takes down its own customer.
- Is threat intelligence an add-on or extra cost?
- It is included in every plan, including Core. Intelligence enrichment is what makes the difference between an alert saying "connection to 203.0.113.45" and one saying "connection to a known botnet C2, fourth time today" — that is not a premium tier, it is the baseline for detection being worth reading.
See what is already talking to the internet.
Send 24 hours of firewall logs. We’ll run them against our intelligence set and tell you what we found — including, quite often, nothing at all.