This category is for sharing of recent, perhaps unpolished threat intel. Consider this a workshop space before intel is committed to MISP or elsewhere, or simply a place to seek confirmation/corroboration of your observed activity. All posts at this level are to be considered TLP:CLEAR, with the understanding that this forum section is globally visible. Learn more about TLP (Traffic Light Protocol) here:
How to Post Useful Intelligence
Posts here use an optional template to help organize shared intelligence. Consider classifying your shared observables with types (domain, IP address, etc.).
Provide context. What activity was seen from the sources? Was it detected automatically?
When sharing lists of observables, format the list using tables when the list is under 20 items. Anything over 20 items should be uploaded as a CSV and attached to the post.