CDIC Blog
Insights, research, and updates from the Cyber Defense and Intelligence Center.
All Posts
The 6.98 Second Hand-off: Tracking a Mirai-Family Botnet Across Five Nodes!
When one attacker IP fell silent after an 88-second assault on our honeypot, another picked up the exact same exploit chain; 6.98 seconds later. That near-seamless hand-off was the thread …
Inside the Honeypot: "Iranian Origin" Reconnaissance and Cryptomining Against a Public Facing Sensor
A public facing honeypot recorded four Iranian origin IPs over 21 June to 17 July 2026, together forming the full opportunistic attack lifecycle.
Following the Breadcrumbs: How Investigative Research Strengthens Cyber OSINT
Cyber OSINT is not only about collecting technical indicators. It also depends on careful research, source verification, and the ability to connect small pieces of information without forcing conclusions. This …
From Intelligence to Evidence: Turning Threat Intelligence into Actionable Digital Forensics
Cyber threat intelligence provides valuable context for identifying emerging threats, but intelligence alone cannot confirm that an intrusion occurred. This article explores how investigators can transform threat intelligence into actionable …
Anatomy of a USPS Phishing Campaign: Google-Authenticated Delivery, Rotating Hosts, and Real-Time Backend Control
How a phishing email led to understanding of phishing infrastructure.