A Failed Lookup Is Not a Clean Verdict
The most dangerous line in a threat scanner is the catch block. We have found and removed the same defect twelve times in IntelStack: a provider call fails, and the scanner reports the indicator as clean.
Notes on threat intelligence scoring, detection engineering and interface design — written from the decisions and the mistakes behind IntelStack, not from a content calendar.
The most dangerous line in a threat scanner is the catch block. We have found and removed the same defect twelve times in IntelStack: a provider call fails, and the scanner reports the indicator as clean.
Most multi-source scanners count votes. But a MalwareBazaar hit means somebody submitted the actual binary, and a GreyNoise hit means the address scans the internet. Treating those as equal votes produces confident nonsense.
Interface decisions in a security console are not aesthetic. A monospace font prevents an l/1 confusion in an indicator, and a colour choice decides what an analyst believes before they have read a word.