BlackBeam dashboard — system overview with real-time metrics
210M+
Domains Tracked
250K+
IOC Rows Synced
10+
Detection Engines
7
OSINT Platforms
What is BlackBeam?
BlackBeam is a cyber threat intelligence research platform developed by DefendEdge. It continuously scans, classifies, and correlates internet infrastructure data at scale — processing over 210 million domain names, tracking DNS history across millions of records, and maintaining a curated database of verified threat actors.
Rather than repackaging third-party threat feeds, BlackBeam generates primary intelligence through its own scanning engines and correlation pipelines. It operates at blackbeam.defendedge.io and is accessible to authorized security researchers, enterprise security teams, and DefendEdge partners.
Platform Capabilities
Ten specialized detection and intelligence engines, each with dedicated data pipelines
Threat Actor Database
Curated database of verified threat actors with alias tracking, IOC associations, and automated merge intelligence from the Valdore IOC feed.
Nexus IOC Intelligence
Real-time sync from Valdore API — IPs, domains, hashes, actors, CVEs, malware, and STIX objects in the intelligence data lake.
Who Is It Designed For?
Built for teams that need primary-source threat intelligence
Security Researchers
Threat intelligence analysts who need primary-source data on emerging infrastructure threats, DGA activity, and threat actor relationships.
Enterprise Security Teams
SOC and CSIRT teams that require daily intelligence reports, IOC correlation, and proactive detection of threats targeting their organization.
Executive Protection Teams
Personnel responsible for C-suite safety who need OSINT-based executive discovery and social media exposure monitoring.
DefendEdge Partners
Organizations integrated with DefendEdge’s broader intelligence network (Nexus Data Lake, iDNA) that need cross-platform correlation.
How It Differs
Primary intelligence vs. repackaged feeds
📦 Conventional TIP
Data Source
Repackages third-party threat feeds
Detection
Feed-based — alerts on known-bad indicators
Correlation
Manual pivot between indicators
OSINT
Limited or manual social media checks
Infrastructure
Traditional databases
Primary Use Cases
From emerging threat detection to daily intelligence briefings
Emerging Threat Detection
Identify DGA-based C2 infrastructure, fast-flux bot networks, and DNS tunneling before they appear in commercial feeds. Behavioral detection, not known-bad lists.
Threat Actor Investigation
Research verified threat actors with full alias tracking and IOC associations. Pivot from a single indicator to an actor’s complete infrastructure footprint.
IOC Correlation & Wildcard Monitoring
Cross-reference wildcard DNS patterns against known IOCs in near real-time. Receive automated email alerts with daily summary reports at 06:00 UTC.
Executive Exposure Assessment
Discover C-level executives at target organizations through proprietary search algorithms. Enrich with verified social media profiles to assess digital exposure.
Daily Intelligence Briefings
Automated daily reports covering DGA, fast-flux, wildcard anomalies, Russian-language keyword threats, and new domain registrations — delivered every morning.
Domain Infrastructure Research
Search and analyze 210M+ domain names with TLD classification, DNS history, and RDAP data. Investigate combinationsquatting, typosquatting, and infrastructure clustering.
Research Methodology
A multi-layered pipeline: primary collection → detection → correlation → verification
Data Collection Layer
- DNS Scanning: Continuous DNS resolution and history tracking across millions of domains (A, AAAA, MX, TXT, NS, CNAME records).
- RDAP Enrichment: Registration data via IANA bootstrap RDAP protocol for domain attribution and timing analysis.
- IOC Synchronization: Near real-time sync from Valdore IOC API — IPs, domains, hashes, actors, CVEs, malware, STIX objects.
- OSINT Aggregation: Proprietary multi-source search for social media discovery and executive research.
Detection & Classification Layer
- DGA Detection: Algorithmic detection of domain generation patterns with malware family classification.
- Fast-Flux Analysis: Identification of rapidly rotating IP associations with RDAP enrichment for registrar attribution.
- Wildcard Scanning: Detection of wildcard DNS configurations and correlation with known IOCs in near real-time.
- DNS Tunneling Detection: Pattern-based identification of DNS-based data exfiltration and covert C2 channels.
Correlation Layer
- Wildcard-IOC Correlation: Automated near real-time cross-referencing of wildcard DNS patterns against the full IOC corpus, with 8 match types and automated email alerting.
- Threat Actor Merge Pipeline: Automated merging of new actor intelligence from IOC feeds into the curated bad actor database, with alias tracking and deduplication.
- Executive Social Enrichment: Linking discovered executives to verified social profiles with confidence scoring (minimum 0.4 confidence threshold, name-score ≥ 0.3).
Verification Layer
- Server-Side Verification: Social media profiles verified via server-side checks (HTTP status, OpenGraph meta tags, page content analysis) — not just search result snippets.
- Confidence Scoring: All OSINT matches receive a 0.0–1.0 confidence score with negative signals for mismatched names. Only matches exceeding minimum thresholds are accepted.
- Human Review Workflow: Bad actors and IOC entries support review states (investigate, dismiss, escalate) with audit logging for analyst accountability.
Infrastructure: All intelligence is stored in the DefendEdge intelligence data lake — a columnar analytics platform optimized for billion-row queries at sub-second latency. The domains table alone contains 210+ million rows. SQLite is used for user management, audit logs, and review state tracking. Data pipelines run on systemd timers with automated retry logic.
The DefendEdge Intelligence Ecosystem
BlackBeam is part of a broader intelligence network
BlackBeam generates the intelligence → the Nexus Data Lake shares it across the network → iDNA attributes it to real actors → DefendEdge orchestrates the ecosystem.
BlackBeam is a product of DefendEdge. © 2026 DefendEdge. All rights reserved.
