Skip to content
Latest
AI-Assisted Exploits Make OT Reachability the Real ControlWhite-Label Router Backdoors Show Why Edge Provenance MattersPaperCut Zero-Day Exploitation Shows Why Print Servers Need Edge-Asset DisciplineAI Infrastructure Is Becoming a Control Plane Attack SurfaceQScan and QTRouter Show Why Proxy Infrastructure Is an Espionage Force MultipliervCenter Exploitation Shows Patching Alone Is Not Incident ResponseEdge Infrastructure Convergence Shows Why Perimeter Devices Need Their Own Patch SLAsSigned ClickOnce Lures Show Why Hiring Workflows Need Endpoint GuardrailsShieldBreak Shows Why Endpoint Protection Needs Compensating ControlsAI-Enabled Malware Still Behaves Like MalwarePrivate APNs Are Becoming OT Attack PathsvCenter Exploitation Shows Why Control Planes Need ContainmentApollo Breach Shows Why Helpdesk Vishing Is a Cloud-Control ProblemBTR.sys Shows Why Trusted Security Drivers Need Behavioral Monitoring

Bulwark Black // Intel Workbench

From report to indicator to action.

Search indicators extracted from Bulwark Black reporting, trace where they appeared, explore automated infrastructure correlations, download the current verified threat feed, or extract IOCs from your own text. Article-derived observations and policy-admitted feed indicators are labeled separately.

Unique typed observations
4,285
Reports with IOCs
302
Current verified feed
108
Correlation clusters
9

Feed status: checking live guard

Live

IOC Passport

Passports are live for qualifying indicators that recur across Bulwark Black reports. Each Passport shows the indicator type, the reports in which it appeared, related observations, and an option to start a watch.

The lookup checks exactly one value against the live, guarded feed. It does not upload or analyze a log, and a value that is absent from the feed is not therefore clean.

Enter one domain, IP, URL, or supported file hash. For a report or larger block of text, use the IOC Extractor.

Branded intelligence views

What is live, beta, and planned

Live

IOC Passport

Open a qualifying recurring indicator to see where it appeared in Bulwark Black reporting and which observations occurred alongside it.

Find an IOC Passport →

Beta · Automated correlation

Campaign Constellation

Explore report clusters created when two or more non-CVE indicators recur across reports. These links suggest relationships worth investigating; they do not establish actor attribution.

Explore the Constellation →

Planned · Not yet available

Defender Pack Builder

Planned: choose reports and indicators, then assemble a downloadable package for your environment. Today, report-level IOC and YARA downloads, verified global feeds, and the IOC Extractor are available separately.

Operational tools

Available today

Observational data

Indicator Database

Search the IOCs automatically extracted from published reports. These are observations, not maliciousness verdicts; verify before acting.

Search observations →

Live · Policy admitted

Verified Threat Feeds

Download indicators backed by fresh, exact positive evidence under the current admission policy. Unknown, clean, pending, stale, and unsupported values remain out.

Open verified feeds →

Live

IOC Extractor

Paste a report or advisory, highlight extracted values, and download defanged or live TXT, CSV, JSON, and YARA output. Nothing pasted is stored.

Extract indicators →

Live

Threat Alerts

Watch a keyword, category, CVE, domain, IP, or hash and receive a daily email only when new Bulwark Black reporting matches.

Start a watch →

What the labels mean

Observed
Extracted from published reporting; not independently a malicious verdict.
Verified feed
Admitted by fresh, exact positive evidence under the current policy.
Beta
Usable today, but based on automated inference and still evolving.
Planned
A named product direction, not a currently available feature.

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.