Company
Date Published
Author
Coralogix Team
Word count
599
Language
English
Hacker News points
None

Summary

Coralogix has enhanced its Unified Threat Intelligence (UTI) capabilities by expanding its Indicators of Compromise (IOC) matching beyond just IP addresses to include new fields like JA3, JA4, domain, URL, and file hash. This expansion is designed to address the evolving nature of cyber threats, where attackers often use encrypted traffic, disposable domains, and polymorphic files to evade detection. The updated UTI features are integrated into the Snowbit Utilities Extension, providing faster detection and richer context, and are available for immediate use by customers. The enhancements enable more comprehensive threat detection across multiple attack surfaces by supporting new dedicated alerts for malicious URLs, domains, JA3/JA4 fingerprints, and file hashes, which work alongside existing IP-based detection for full-spectrum IOC monitoring.