How do attackers see your company? Threat Intelligence offers an outside-in view

/ /

24. 08. 2026

It began with an email impersonating JPMorgan. The link did not lead directly to an obviously suspicious website. Instead, it sent the recipient through redirects that included legitimate Cisco domains. A well-known bank, a trusted technology company and URLs with no malicious reputation made the journey appear safe.

That was exactly what the attackers were counting on. Checking the first URL would not have been enough. A deeper dynamic analysis made the difference: we followed the entire chain as a user would. At its end was the campaign’s true objective — a fake Microsoft 365 sign-in page designed to steal the victim’s username and password. Microsoft 365 sign-in page designed to steal the victim’s username and password.

The campaign could not be reliably attributed to a specific threat actor, but attribution was not essential to protecting our clients. We extracted concrete indicators from the emails and related infrastructure, warned clients about the activity, and prepared our SOC analysts for what to look for. The attack did not have to appear inside a client’s network first. The information needed to defend against it already existed outside. That is where Threat Intelligence begins.

Upozornenie na phishingovú kampaň vydávajúcu sa za JPMorgan. Reťaz presmerovaní využívala aj legitímne domény Cisco a končila pokusom o krádež údajov do Microsoft 365. Zdroj: Recorded Future.
An alert about a phishing campaign impersonating JPMorgan. The redirect chain also used legitimate Cisco domains and ended in an attempt to steal Microsoft 365 credentials. Source: Recorded Future.

An attack does not have to begin inside your network

Firewalls, EDR and SIEM monitor the network perimeter, endpoints and internal logs. Threat Intelligence, also known as cyber threat intelligence, extends this visibility beyond the organization.

It monitors threat actor activity, targets, infrastructure, exploited vulnerabilities, and leaked corporate data. Sources range from the open web and malware databases to the dark web, Telegram, and closed forums.

“Threat Intelligence gives an organization a clearer view of how attackers see its infrastructure from the outside. It also allows the organization to monitor groups that may one day target it,” explains Jakub Zuber, Threat Intelligence expert at Binary Confidence.

A threat feed alone is not Threat Intelligence

Security platforms process vast numbers of malicious domains, IP addresses, files, vulnerabilities, and data leaks every day. But a list of indicators alone will not protect an organization. A threat feed provides data. Threat Intelligence validates it, links it to a campaign and places it in the context of the client’s environment. Only then can it support a decision or defensive action.

“We do not send clients raw data. We analyze and filter the information, then deliver a finished assessment: what is relevant to them, what they should investigate, and what steps they need to take,” says Zuber. Without an analyst who understands the client and can separate signal from noise, even a high-quality feed may become just another stream of alerts.

A hospital faces different risks from a manufacturer, bank or defense contractor. That is why we create an individual Threat Intelligence profile for every client, based on their industry, technology stack and public digital footprint.

We monitor direct mentions of the organization, attacks on similar companies and wider sector activity. The profile also helps us prioritize vulnerabilities. A critical flaw in technology the client does not use has a different priority from an actively exploited vulnerability in one of its internet-facing systems.

Technology captures the signal. An analyst gives it meaning

At Binary Confidence, we combine several sources. Recorded Future provides intelligence on campaigns, threat actors and vulnerabilities. Google Threat Intelligence adds context around malware, files and domains. Hudson Rock is used to monitor compromised accounts and infostealer infections.

We connect the data in OpenCTI, to see relationships between campaigns, threat actors, malware, vulnerabilities, targets and technical indicators. Platforms can collect and correlate the information, but an analyst must assess its credibility, timeliness and relevance to a specific client.

From a detected campaign to concrete defensive action

  1. We detect a signal. A campaign, vulnerability, data leak or mention of the client.
  2. We verify it. We cross-check sources and add context.
  3. We assess its relevance. We compare the signal with the client’s profile.
  4. We identify the traces. Indicators and behaviors that can be searched for across the network.
  5. We recommend action. What to investigate, block, patch or change.

The results go to both the client and the SOC, which can tune detections or launch targeted threat hunting. In the opening campaign, we could act without knowing the attacker’s identity. What mattered was the method, objective and traces left behind.

Indicators and techniques associated with the analyzed campaign. For an analyst, they are inputs to the analysis, not a ready-made verdict. Source: Recorded Future.
Indicators and techniques associated with the analyzed campaign. For an analyst, they are inputs to the analysis, not a ready-made verdict. Source: Recorded Future.

Threat Intelligence gives the SOC a head start

If the SOC knows that a campaign is targeting a particular sector, it can scrutinize similar emails, sign-ins and network events more closely. Indicators can be checked against historical logs, added to detection rules or used to hunt for traces that have not yet triggered an alert.

Threat Intelligence also supports incident response. Comparing observed behavior with known attacker techniques helps the team determine where to look for the next step. It is not proof of attribution, but it provides a stronger working hypothesis.

Employee identity as a target for hackers

Our own experience shows that employees also use their work email addresses for personal purposes, such as gaming platforms or online shopping. As a result, an employee’s corporate account may appear at any time in data obtained through phishing, a database breach or an infostealer infection.

Today, user identities are involved in more than 60% of all attacks. Research conducted by security organizations around the world confirms this. Palo Alto Networks Unit 42 research team reports that 65% of successful intrusions involve credentials belonging to ordinary users.. This can also happen on a personal device where an employee has used their work email address. This is precisely why we also monitor credential leaks for our clients.

Hudson Rock provides context about the affected device and the services the user accessed from it. An analyst determines whether the finding is an old, invalid credential or a genuine risk to the corporate environment. After detection, the response may include changing the password, revoking active sessions, reviewing MFA, inspecting the device or analyzing unusual sign-ins.

Threat Intelligence sees the stolen “key” outside the organization. Microsoft 365 monitoring can then detect whether someone is trying to use it inside.

Hudson Rock displays compromised credentials and context about affected devices, accounts, domains and applications.
Hudson Rock displays compromised credentials and context about affected devices, accounts, domains and applications.

Threat Intelligence leaves hackers less room to maneuver

Threat Intelligence delivers the greatest value when it feeds directly into the work of the SOC, detection engineering and Incident Response teams. It does not replace firewalls, EDR, SIEM or analysts. However, it helps them focus on the most likely and most important threats.

Threat Intelligence cannot predict every attack, but it reduces the element of surprise. It allows an organization to see itself through an attacker’s eyes, prepare its defenses for the attacker’s techniques and detect warning signs before they become an incident.

At Binary Confidence, we create individual Threat Intelligence profiles for our clients, monitor relevant campaigns, data leaks, vulnerabilities and threat actor activity, and connect our findings with practical protection in the SOC. This allows our clients to see their company through an attacker’s eyes before the attacker takes a closer look.

European Union and Digital Europe Programme funding logos displayed in partnership section.

This activity is supported by the European Cybersecurity Competence Centre (ECCC) as part of the project under grant code 101145856, and by the Ministry of Investments, Regional Development and Informatization as part of the state programme of the Recovery and Resilience Plan of the Slovak Republic under project grant code 17I04-04-V02-00001.

Join our newsletter

Sign up to get the latest information and news from Binary Confidence.