Context

A network operator with national IP resources needed threat visibility beyond single-IP indicators — infrastructure abuse, C2 hosting and campaign activity visible only at Autonomous System (AS) level. Existing monitoring was reactive and IP-centric; cross-IP correlation, sinkhole enrichment and proactive disruption of malicious infrastructure were not operationalised in a single intelligence model.

Outcome

Threat intelligence platform architected for ASN-centric collection and analysis — multi-source aggregation from OSINT feeds, sinkhole telemetry, DNS intelligence, infrastructure reputation data and external sharing ecosystems.

Graph-based relationship engine deployed — correlating domains, IP addresses, ASNs, C2 nodes, malware campaigns and hosting providers.

DNS-oriented disruption strategies implemented — static mitigation models for known C2 domains, sinkhole enrichment, beaconing-pattern detection.

Automated IOC enrichment, campaign clustering, infrastructure pivoting and abuse-pattern detection operationalised.

Use cases enabled: ISP-level infrastructure protection, support for the national monitoring model, early warning for malicious infrastructure and threat-actor infrastructure tracking.

Proactive intelligence capability established — visibility and disruption at network-operator scale, not limited to point indicators.

Frameworks referenced in this engagement:
  • ISO/IEC 27001
  • NIS2

04 Managed Security Service Provider

Managed SOC monitoring and detection with CSIRT incident coordination under agreed SLAs — without building a full in-house operations stack first.

09 Internet Service Provider

Managed IP connectivity with Anti-DDoS, CDN and NGFW under documented SLAs, change and incident processes.

All services →