Assess the dangerousness of your IP
et Domains with AlienVault OTX.
Faced with a suspicious IP address or an unknown domain, there is no room for doubt. Akuity SOC natively integrates AlienVault OTX and Google Web Risk to assess the reputation of adversary infrastructures and block IOCs across your entire fleet.
Manual OSINT is slow, non-standardized and non-scalable
Browsing VirusTotal, Whois, security blogsfor each suspicious IP or hash. A 10-15 minute process per indicator.
Integrated analysis: direct querying of AlienVault OTX and Google Web Risk from the Threat Hunting console in one click.
Subjective analysisof the analyst faced with the raw data found. No standardized score, risk of interpretation error.
OTX Radial Gauge: algorithmic calculation of risk out of 100 points with contextualized bonus/malus.
Manual manipulation of Firewall / Proxy rulesbusiness. Deployment delay, risk of configuration error.
1-Click IOC Blocking: direct injection into Microsoft Defender for Endpoint for 90 days via API.
How Akuity SOC is revolutionizing Threat Intelligence
AlienVault OTX & Google Web Risk Integration
Backend interfaced with the two largest global reputation databases.Google Safe Browsingidentifies active phishing campaigns.AlienVault OTXreports the presence of C2 malware via Community Pulses.
Scoring Algorithm — Radial Risk Gauge
Colorful circular gauge0 to 100with algorithmic weighting. Bonus if the IP belongs to a recognized cloud (Microsoft, AWS) validated by ASN. Critical penalty if recent domain (< 100 days) hosting malware.
Blocking IOC Global in Defender for Endpoint
As soon as the score confirms the danger, the analyst clicksblockIocOnTenant. SOAR immediately injects the IOC (SHA256 Hash, IP or Domain) via the Microsoft API. BlockingAction=Blockthroughout the park for 90 days.
Preventive neutralization of a Command & Control domain
Search — Unknown domain in network logs
InvestigationThe analyst spots an unknown domain in the logs (update-system-win32.com). He enters the domain into the console's Threat Hunting tool.
The Verdict — OTX Gauge at 90/100 (Review)
Score 90/100The OTX Gauge explodes at90/100 Review. The IA note says: "Recent registration (< 100 days), zero popularity, critical C2 server signatures."
The Shield — Global blocking validated by MFA
IOC Blocked 90 daysThe analyst enters hisMFA codeand adds the indicator to the blacklist. Any workstation attempting to contact this C2 server is natively blocked by Windows Defender.
Deepen the assessment of threats and IOCs
What is an Indicator of Compromise (IOC) and how to exploit it?
Learn what an Indicator of Compromise (IOC), the Pyramid of Pain, and how to leverage OSINT to block cyberattacks.
AlienVault OTX: The IP address reputation algorithm
Assessing a suspicious IP address (OSINT) is crucial. Learn how the Akuity SOC algorithm and AlienVault OTX calculate risk score.
Google Web Risk: Block phishing infrastructures
Phishing regularly bypasses your spam filters. Learn how to leverage Google Web Risk within your SOC to block these threats at the source.
Why inject a blocking IOC for a strict duration of 90 days?
Banning a malicious IP permanently is a strategic mistake in SOC. Find out why 90-day validity in Defender is best practice.