MetaDefender InSights is a threat intelligence solution that provides curated technical indicators of compromise (IOCs), such as IP addresses, domains, and URLs, as well as data on adversary tactics, techniques, and procedures (TTPs). The system is designed to identify adversary infrastructure like command and control servers, phishing campaigns, and malware staging sites. Its purpose is to facilitate threat detection, breach detection analysis, and the proactive detection of post-exploit activity and emerging threats across both IT and OT environments.
The system aggregates data from proprietary research, backend file processing, intelligence partners, and open-source intelligence (OSINT). It utilizes Deep File Inspection (DFI) to extract network indicators from documents and analyzes network activity including connection attempts and domain resolutions. Automated filtering and expiration of aged indicators are used to maintain data relevance. The intelligence is distributed via JSON-formatted API lookups and snapshot downloads for integration into security tools like firewalls and proxies, enabling real-time file blocking and network monitoring.