Sources & response ecosystem

Context from many sources.
Responsibility stays clear.

External intelligence helps orient an investigation. Direct observations, careful interpretation and appropriate routing make a report useful.

References, not affiliations.

The organizations below are relevant sources or parts of the response ecosystem. Inclusion does not claim a commercial relationship, account access, membership, accreditation or endorsement. Use of any data is subject to its provider’s terms.

01 /Domain & IP reputation

Spamhaus

Reputation and blocklist context can help identify leads. A listing is a signal to investigate, not a substitute for direct evidence.

Official website
02 /Multi-source analysis

VirusTotal

URL, domain and file analysis can support cross-checking. Private evidence must not be uploaded to public scanning services.

Official website
03 /Threat intelligence

Cisco Talos

Reputation information and threat research provide infrastructure context. Findings require independent interpretation.

Official website
04 /Community phishing reports

PhishTank

Submitted and verified phishing records can provide leads and corroboration; timing and current site behavior still matter.

Official website
05 /Domain policy & processes

ICANN

Registration policy, lookup resources and applicable complaint routes help identify responsibilities in the domain ecosystem.

Official website
06 /Domain-abuse ecosystem

Domain Patrol

A reference for cooperation between competent organizations and registrars in the Russian domain space. No membership is claimed.

Official website
07 /Incident coordination

CERT / CSIRT

Relevant incident response teams may receive reports within their remit. The FIRST directory helps identify published team contacts.

Official website
08 /Action within their remit

Infrastructure providers

Registrars, registries, hosting and DNS/CDN providers receive evidence relevant to the service they control. Registration data can help locate the correct party.

Official website

Reach the party
able to review the issue.

Registrars and registries handle matters within their registration policies. Hosts and DNS/CDN providers assess abuse involving their services. CERT/CSIRT teams can help coordinate incidents within their constituency.

Regulators and other competent authorities may be appropriate for issues within their jurisdiction. Recipient selection depends on the facts; the same report is not indiscriminately sent to every organization.

A clear route to review

Have information
we should examine?

Share context, raise a concern, or request a correction. Start with a concise summary and safely formatted domains.

Contact the team