hero-background-color-red-orange-gradient
image
https://assets.lumen.com/is/image/Lumen/img-blog-hero-threat-intelligence?Creativeid=7181ed0f-2967-41ee-afc0-0cabc3ec41d3
https://assets.lumen.com/is/image/Lumen/img-blog-hero-threat-intelligence?Creativeid=7181ed0f-2967-41ee-afc0-0cabc3ec41d3
https://assets.lumen.com/is/image/Lumen/img-blog-hero-threat-intelligence?Creativeid=7181ed0f-2967-41ee-afc0-0cabc3ec41d3
A business professional in a green turtleneck sits at their desk, looking intently at the desktop in front of them. There is a large, blurred screen in the background, showing code that spans the wall.
content
content-col-11
What goes into an actionable threat intelligence feed?

Security teams have no shortage of threat data. They continuously consume feeds from commercial providers, open-source repositories, information-sharing communities and vendors across the cybersecurity ecosystem. The harder problem is determining which signals matter, what they reveal and what action to take next.

Threat intelligence is the output of collecting, analyzing and contextualizing information about cyberthreats to help security teams identify risks, understand attacker behavior and take informed action to defend their enterprise assets.

Most mature security operations center (SOC) teams already consume multiple threat intelligence feeds to correlate against their security information and event management (SIEM) alerts and detection sources. The challenge isn't accessing data. It's determining which intelligence is relevant to your organization, how it fits into ongoing investigations and what actions should come next.

For Black Lotus Labs®, helping security teams enrich their threat intelligence with global network visibility involves enrichment from third-party intelligence and expert threat research to drive attribution and actionable insights.

This article explores what goes into the Black Lotus Labs threat intelligence feed, how researchers transform raw data into actionable intelligence and how that intelligence helps organizations strengthen cyber defenses across a rapidly evolving threat landscape.

Key takeaways

Why indicators alone aren’t enough

Most threat intelligence begins with indicators of compromise (IOCs): IP addresses, domains, hashes and other observable artifacts associated with malicious activity.

These indicators provide important clues, but they rarely explain the bigger picture. An IP address can be blocked, a domain can be taken down and malware infrastructure can be replaced in hours. Without context, security teams often find themselves reacting to symptoms rather than understanding the underlying cause.

Lumen Director of Specialized Sales and Security Larry Callahan explains that many organizations consume multiple threat intelligence feeds yet still struggle to operationalize the information they receive. "The challenge isn't getting more threat intelligence. The challenge is enriching that intelligence, applying it to the right parts of the security program and making it operational," Callahan says. A lot of businesses believe more is better in terms of intel but end up overspending because it doesn’t fit their environment.

The real value of intelligence lies in answering deeper questions:

Answering these questions requires visibility, analysis and experience.

Here are some examples of how raw indicators can turn into actionable insights.

https://assets.lumen.com/is/image/Lumen/img-threatintelligence-table?$JPG$&Creativeid=bc1dc9d8-5f85-47d9-bf5a-e3ef25692c8d
https://assets.lumen.com/is/image/Lumen/img-threatintelligence-table?$JPG$&Creativeid=bc1dc9d8-5f85-47d9-bf5a-e3ef25692c8d
https://assets.lumen.com/is/image/Lumen/img-threatintelligence-table?$JPG$&Creativeid=bc1dc9d8-5f85-47d9-bf5a-e3ef25692c8d
Three-column table showing how raw indicators of compromise (IOCs) are transformed into enriched threat intelligence and recommended security actions. Examples include an IP address linked to command-and-control servers with guidance to block communications, a spoofed domain tied to phishing activity with recommendations to alert users, a file hash associated with ransomware that prompts endpoint isolation, abnormal network traffic indicative of botnet activity requiring investigation and containment, and DNS requests to an unknown domain correlated with healthcare-targeted attacks that warrant increased monitoring. The table illustrates the progression from detection to context to response in cybersecurity threat analysis.

This is where threat intelligence evolves from data collection into threat understanding.

The inputs: building visibility across the threat landscape

Organizations rarely rely on a single intelligence source. Security teams must balance their intelligence requirements for operational, tactical and technical components among commercial and open-source feeds, internal telemetry and industry-sharing communities to build a complete picture of risk. From there, sources must be normalized and playbooks defined to ensure utility and continuous optimization.

To help ensure robust threat visibility, Black Lotus Labs researchers unify network intelligence with third-party sources to provide preliminary correlation through a single, powerful feed.

Proprietary network intelligence

Lumen operates one of the world's largest global IP backbones. This vantage point provides visibility into internet activity at tremendous scale, allowing researchers to observe infrastructure, traffic patterns and communications that would otherwise remain hidden.

When a threat deploys, they know a researcher may be watching them. They will cycle their public-facing infrastructure frequently to avoid being caught. The visibility of the Lumen Network allows Black Lotus Labs to help prevent and mitigate damage before the malware can propagate.

This visibility can also help researchers identify attacker activity before vulnerabilities are publicly disclosed. In one recent campaign, Black Lotus Labs observed infrastructure associated with a Check Point exploitation campaign more than three weeks before the vulnerability was publicly identified.¹ By tracking attacker behavior at the network layer, researchers were able to see activity developing before traditional endpoint alerts or vendor disclosures provided warning.

Rather than focusing on isolated events, researchers can proactively observe relationships across vast portions of the internet and recognize how threats develop.

Third-party intelligence sources

No single organization sees everything. To expand visibility, Black Lotus Labs incorporates carefully selected intelligence from trusted commercial, open-source and community sources. These feeds provide additional context, external validation and insights into activity occurring beyond any single network's view.

Together, proprietary and third-party intelligence create a broader picture of the threat landscape than either source could provide alone.

The intelligence layer: where signals become actionable

Collecting data is only the beginning. The real challenge is transforming enormous volumes of information into intelligence that defenders can use.

As security teams map threat intelligence to the MITRE ATT&CK® framework or a cyber kill chain, researcher validation paired with AI-powered analytics provides a more comprehensive view. When tactics, techniques and procedures (TTPs) are correlated across visibility to the internet backbone, analysts can more easily identify where an adversary fits within the broader attack lifecycle.

Correlation and enrichment

Individual data points often seem insignificant on their own. A domain registration, an unusual connection pattern or a newly detected server may not appear suspicious in isolation.

Correlation connects these signals. Researchers compare infrastructure, ownership patterns, behavioral characteristics and historical observations to identify relationships that reveal larger campaigns. Additional enrichment adds details such as geolocation, reputation data, hosting information and known threat actor associations.

According to Black Lotus Labs Principal Security Researcher Mark Dehus, understanding who is behind a piece of threat infrastructure is often what transforms raw data into actionable intelligence.

https://assets.lumen.com/is/image/Lumen/img-blog-calloutquote-threat-intelligence?Creativeid=97b615bb-3ac5-478c-ae42-6f1a2ca6131b
https://assets.lumen.com/is/image/Lumen/img-blog-calloutquote-threat-intelligence?Creativeid=97b615bb-3ac5-478c-ae42-6f1a2ca6131b
https://assets.lumen.com/is/image/Lumen/img-blog-calloutquote-threat-intelligence?Creativeid=97b615bb-3ac5-478c-ae42-6f1a2ca6131b
Design: An orange gradient text box surrounds a quote, with a large orange opening quotation mark in the box's upper left. Text: By identifying who or what owns a threat infrastructure, we can narrow the scope of who they are targeting. Once a target group is identified, we can analyze communications between the malware and those specific organizations. The result is a clearer understanding of what activity is occurring and, more importantly, why. Mark Dehus, Principal Security Researcher, Black Lotus Labs.

This approach helps researchers move beyond isolated indicators and develop a more complete understanding of threat actor behavior.

Analytics at scale

Modern adversaries operate at internet scale. Identifying meaningful threats requires advanced analytics capable of separating truly suspicious activity from the background noise of everyday internet traffic.

Dehus describes it like this: “Think of it like a phone bill that shows every incoming and outgoing call during a billing period. Lumen receives similar records from our routers on an enormous scale. Analysts then process that data, measured in petabytes, to identify patterns, uncover threats and distinguish meaningful activity from the noise.”

This level of visibility enables researchers to detect emerging threats and uncover activity that might otherwise remain hidden within the vast volume of internet traffic.

Researcher validation

AI and automation play a growing role in security operations, but expert analysis remains a critical component of effective threat intelligence.

Black Lotus Labs researchers validate findings, investigate suspicious activity and apply real-world threat knowledge to determine whether a signal represents meaningful risk. That human expertise is especially important when connecting isolated indicators to broader threat activity.

One example is Black Lotus Labs’ work supporting the FBI and Department of Justice (DOJ) in supporting their takedown of the “KV Botnet” associated with “Volt Typhoon,” a state-sponsored actor based in China that typically focuses on espionage and information gathering. From July 2022 through February 2023, Black Lotus Labs observed overlap between NETGEAR ProSAFE firewalls acting as relay nodes for networks compromised by the threat group, Volt Typhoon. After researchers verified the findings, Microsoft assessed that the campaign was attempting to disrupt critical communication infrastructure between the United States and Asia during future crises.

The example shows why researcher validation matters. Proprietary network intelligence can surface suspicious patterns, but expert analysis helps determine whether those patterns represent meaningful risk, how they connect to broader activity and what security teams should do next.

The outcomes: intelligence that supports security operations

Threat intelligence creates value when it helps organizations make better security decisions. The intelligence produced by Black Lotus Labs supports a variety of security outcomes across the Lumen portfolio.

Threat actors rely on infrastructure to conduct operations. Command-and-control servers, malware distribution systems, botnets and proxy networks all leave traces that can be tracked and analyzed. By identifying and monitoring this infrastructure, defenders gain earlier visibility into malicious activity before attacks reach critical systems.

Threat intelligence provides additional context that helps security teams distinguish routine activity from malicious behavior. When integrated into detection workflows, intelligence enables earlier identification of threats and helps improve investigation efficiency.

For example, a security analyst receives an alert indicating that an employee device communicated with an unfamiliar IP address. On its own, the IP address is simply an indicator that requires further investigation.

Using threat intelligence from Black Lotus Labs, the analyst discovers that the IP address is associated with command-and-control infrastructure linked to an active malware campaign. Further enrichment reveals related domains, previous sightings across multiple networks and known attacker tactics.

Rather than treating the alert as an isolated event, the analyst can quickly determine the potential scope of the threat, search for additional affected systems and take action to contain the activity. What began as a single indicator becomes a clearer picture of attacker behavior, helping the organization respond faster and with greater confidence.

Enhancing DDoS protection

Modern DDoS attacks often leverage rapidly evolving infrastructure and botnet ecosystems.

Threat intelligence helps identify malicious sources, emerging attack infrastructure and changes in adversary behavior—helping improve the ability to detect and mitigate attacks before they create business disruption.

Supporting broader cyber defense

Threat intelligence also contributes to broader security capabilities, helping organizations prioritize risk, improve visibility and adapt defenses as new threats emerge.

As adversaries evolve, intelligence helps defenders stay informed rather than reactive.

Intelligence works best as part of an ecosystem

No single feed can provide complete coverage of every threat. Modern security teams build intelligence programs around a combination of SIEM and endpoint detection and response (EDR) tools, threat intelligence feeds, internal telemetry and analyst expertise. The most valuable intelligence sources are those that enrich and strengthen the tools and playbooks organizations already use.

Effective threat intelligence helps security teams answer critical questions:

By combining network visibility, intelligence enrichment and expert analysis, Black Lotus Labs helps organizations answer those questions faster and with greater confidence, strengthening the threat intelligence capabilities and workflows they already rely on.

This intelligence is integrated into Lumen products including Lumen Defender℠, Lumen DDoS protection, Defender Threat Feed and Defender Advanced Managed Detection and Response (AMDR) services to help customers identify and respond to threats more effectively. These are some of the ways an organization can introduce threat intelligence into their own infrastructure.

Explore the latest findings from Black Lotus Labs researchers in the 2026 Threatscape Report and learn more about why actionable threat intelligence matters now.

Raw indicators only tell part of the story. See how Black Lotus Labs transforms global network visibility and expert threat research into actionable intelligence that helps security teams detect, understand and mitigate cyberthreats fast.

primaryOrange
Explore solutions
https://www.lumen.com/en-us/security/black-lotus-labs.html
_blank

¹Lumen Technologies, 2026 Lumen Defender Threatscape Report, 2026.

This content is provided for informational purposes only and may require additional research and substantiation by the end user. In addition, the information is provided "as is" without any warranty or condition of any kind, either express or implied. Use of this information is at the end user's own risk. Lumen does not warrant that the information will meet the end user's requirements or that the implementation or usage of this information will result in the desired outcome of the end user. All third-party company and product or service names referenced in this article are for identification purposes only and do not imply endorsement or affiliation with Lumen. This document represents Lumen products and offerings as of the date of issue. Services not available everywhere. Lumen may change or cancel products and services or substitute similar products and services at its sole discretion without notice. © 2026 Lumen Technologies. All Rights Reserved.

image
https://assets.lumen.com/is/image/Lumen/Harry-Rossoff-headshot-300x300?$PNG$&Creativeid=d1e2d442-5e9a-4a23-9260-2b3bbe102c41
https://assets.lumen.com/is/image/Lumen/Harry-Rossoff-headshot-300x300?$PNG$&Creativeid=d1e2d442-5e9a-4a23-9260-2b3bbe102c41
https://assets.lumen.com/is/image/Lumen/Harry-Rossoff-headshot-300x300?$PNG$&Creativeid=d1e2d442-5e9a-4a23-9260-2b3bbe102c41
Harry Rossoff, Senior Director of Product Marketing – Security & M&E, headshot.
content
Author

Harry Rossoff

Harry Rossoff is Senior Director of Product Marketing for Security and Media & Entertainment at Lumen Technologies, where he leads cproduct marketing across a portfolio of network security and managed security solutions. With more than 10 years of experience in technology spanning sales, GTM strategy, and product marketing, Harry has helped both startups and enterprise organizations accelerate growth and bring innovative solutions to market. Prior to Lumen, he led cloud security go-to-market efforts for Microsoft Americas. Harry lives in Arlington, Massachusetts, with his family, two dogs, and one-year-old child.