AUTO-UPDATED

Modat enhances Magnify with Passive DNS for faster threat hunting and infrastructure analysis

Modat has integrated native Passive DNS intelligence into its Magnify platform, allowing security teams to conduct faster threat hunting by unifying domain, IP, and certificate data in one interface.

Key Points

  • Modat added Passive DNS to the Magnify platform to enable seamless pivoting between domains, IP addresses, TLS certificates, and device fingerprints.
  • The platform uses clustering-based device fingerprinting and geo-native scanning to identify infrastructure often missed by traditional internet scanners.
  • Analysts can perform retrospective infrastructure analysis by querying Passive DNS alongside existing IP, device, and certificate timelines.
  • The system features automated correlation of new domains and IPs with known indicators of compromise, malware families, and threat actor tactics.
  • Magnify offers an API-first design for integration with existing SIEM, SOAR, and threat intelligence tools.

Why it Matters

This integration reduces the manual effort required for security analysts to correlate disparate data points during complex threat investigations. By streamlining infrastructure analysis into a single graph, organizations can accelerate incident response times and improve the accuracy of their exposure management strategies.
Help Net Security Published by Industry News
Read original