Security teams have no shortage of threat data. They continuously consume feeds from commercial providers, open-source repositories, information-sharing communities and vendors across the cybersecurity ecosystem. The harder problem is determining which signals matter, what they reveal and what action to take next.
Threat intelligence is the output of collecting, analyzing and contextualizing information about cyberthreats to help security teams identify risks, understand attacker behavior and take informed action to defend their enterprise assets.
Most mature security operations center (SOC) teams already consume multiple threat intelligence feeds to correlate against their security information and event management (SIEM) alerts and detection sources. The challenge isn't accessing data. It's determining which intelligence is relevant to your organization, how it fits into ongoing investigations and what actions should come next.
For Black Lotus Labs®, helping security teams enrich their threat intelligence with global network visibility involves enrichment from third-party intelligence and expert threat research to drive attribution and actionable insights.
This article explores what goes into the Black Lotus Labs threat intelligence feed, how researchers transform raw data into actionable intelligence and how that intelligence helps organizations strengthen cyber defenses across a rapidly evolving threat landscape.
Key takeaways
- Black Lotus Labs combines proprietary network visibility with third-party intelligence sources to identify malicious infrastructure, botnets and emerging adversary activity.
- Researchers enrich and validate raw data through correlation, enrichment, analytics and expert investigation, turning signals into intelligence security teams can trust.
- Intelligence generated by Black Lotus Labs powers multiple security outcomes across the Lumen Defender ℠ security portfolio, including threat detection, DDoS protection and infrastructure defense.
- Threat intelligence is most effective when combined with other security technologies, helping organizations move faster and make more informed decisions.
Why indicators alone aren’t enough
Most threat intelligence begins with indicators of compromise (IOCs): IP addresses, domains, hashes and other observable artifacts associated with malicious activity.
These indicators provide important clues, but they rarely explain the bigger picture. An IP address can be blocked, a domain can be taken down and malware infrastructure can be replaced in hours. Without context, security teams often find themselves reacting to symptoms rather than understanding the underlying cause.
Lumen Director of Specialized Sales and Security Larry Callahan explains that many organizations consume multiple threat intelligence feeds yet still struggle to operationalize the information they receive. "The challenge isn't getting more threat intelligence. The challenge is enriching that intelligence, applying it to the right parts of the security program and making it operational," Callahan says. A lot of businesses believe more is better in terms of intel but end up overspending because it doesn’t fit their environment.
The real value of intelligence lies in answering deeper questions:
- Who is operating the infrastructure?
- How are they acquiring victims?
- What tactics are they using?
- What is likely to happen next?
Answering these questions requires visibility, analysis and experience.
Here are some examples of how raw indicators can turn into actionable insights.
This is where threat intelligence evolves from data collection into threat understanding.
The inputs: building visibility across the threat landscape
Organizations rarely rely on a single intelligence source. Security teams must balance their intelligence requirements for operational, tactical and technical components among commercial and open-source feeds, internal telemetry and industry-sharing communities to build a complete picture of risk. From there, sources must be normalized and playbooks defined to ensure utility and continuous optimization.
To help ensure robust threat visibility, Black Lotus Labs researchers unify network intelligence with third-party sources to provide preliminary correlation through a single, powerful feed.
Proprietary network intelligence
Lumen operates one of the world's largest global IP backbones. This vantage point provides visibility into internet activity at tremendous scale, allowing researchers to observe infrastructure, traffic patterns and communications that would otherwise remain hidden.
When a threat deploys, they know a researcher may be watching them. They will cycle their public-facing infrastructure frequently to avoid being caught. The visibility of the Lumen Network allows Black Lotus Labs to help prevent and mitigate damage before the malware can propagate.
This visibility can also help researchers identify attacker activity before vulnerabilities are publicly disclosed. In one recent campaign, Black Lotus Labs observed infrastructure associated with a Check Point exploitation campaign more than three weeks before the vulnerability was publicly identified.¹ By tracking attacker behavior at the network layer, researchers were able to see activity developing before traditional endpoint alerts or vendor disclosures provided warning.
Rather than focusing on isolated events, researchers can proactively observe relationships across vast portions of the internet and recognize how threats develop.
Third-party intelligence sources
No single organization sees everything. To expand visibility, Black Lotus Labs incorporates carefully selected intelligence from trusted commercial, open-source and community sources. These feeds provide additional context, external validation and insights into activity occurring beyond any single network's view.
Together, proprietary and third-party intelligence create a broader picture of the threat landscape than either source could provide alone.
The intelligence layer: where signals become actionable
Collecting data is only the beginning. The real challenge is transforming enormous volumes of information into intelligence that defenders can use.
As security teams map threat intelligence to the MITRE ATT&CK® framework or a cyber kill chain, researcher validation paired with AI-powered analytics provides a more comprehensive view. When tactics, techniques and procedures (TTPs) are correlated across visibility to the internet backbone, analysts can more easily identify where an adversary fits within the broader attack lifecycle.
Correlation and enrichment
Individual data points often seem insignificant on their own. A domain registration, an unusual connection pattern or a newly detected server may not appear suspicious in isolation.
Correlation connects these signals. Researchers compare infrastructure, ownership patterns, behavioral characteristics and historical observations to identify relationships that reveal larger campaigns. Additional enrichment adds details such as geolocation, reputation data, hosting information and known threat actor associations.
According to Black Lotus Labs Principal Security Researcher Mark Dehus, understanding who is behind a piece of threat infrastructure is often what transforms raw data into actionable intelligence.
This approach helps researchers move beyond isolated indicators and develop a more complete understanding of threat actor behavior.
Analytics at scale
Modern adversaries operate at internet scale. Identifying meaningful threats requires advanced analytics capable of separating truly suspicious activity from the background noise of everyday internet traffic.
Dehus describes it like this: “Think of it like a phone bill that shows every incoming and outgoing call during a billing period. Lumen receives similar records from our routers on an enormous scale. Analysts then process that data, measured in petabytes, to identify patterns, uncover threats and distinguish meaningful activity from the noise.”
This level of visibility enables researchers to detect emerging threats and uncover activity that might otherwise remain hidden within the vast volume of internet traffic.
Researcher validation
AI and automation play a growing role in security operations, but expert analysis remains a critical component of effective threat intelligence.
Black Lotus Labs researchers validate findings, investigate suspicious activity and apply real-world threat knowledge to determine whether a signal represents meaningful risk. That human expertise is especially important when connecting isolated indicators to broader threat activity.
One example is Black Lotus Labs’ work supporting the FBI and Department of Justice (DOJ) in supporting their takedown of the “KV Botnet” associated with “Volt Typhoon,” a state-sponsored actor based in China that typically focuses on espionage and information gathering. From July 2022 through February 2023, Black Lotus Labs observed overlap between NETGEAR ProSAFE firewalls acting as relay nodes for networks compromised by the threat group, Volt Typhoon. After researchers verified the findings, Microsoft assessed that the campaign was attempting to disrupt critical communication infrastructure between the United States and Asia during future crises.
The example shows why researcher validation matters. Proprietary network intelligence can surface suspicious patterns, but expert analysis helps determine whether those patterns represent meaningful risk, how they connect to broader activity and what security teams should do next.
The outcomes: intelligence that supports security operations
Threat intelligence creates value when it helps organizations make better security decisions. The intelligence produced by Black Lotus Labs supports a variety of security outcomes across the Lumen portfolio.
Threat actors rely on infrastructure to conduct operations. Command-and-control servers, malware distribution systems, botnets and proxy networks all leave traces that can be tracked and analyzed. By identifying and monitoring this infrastructure, defenders gain earlier visibility into malicious activity before attacks reach critical systems.
Threat intelligence provides additional context that helps security teams distinguish routine activity from malicious behavior. When integrated into detection workflows, intelligence enables earlier identification of threats and helps improve investigation efficiency.
For example, a security analyst receives an alert indicating that an employee device communicated with an unfamiliar IP address. On its own, the IP address is simply an indicator that requires further investigation.
Using threat intelligence from Black Lotus Labs, the analyst discovers that the IP address is associated with command-and-control infrastructure linked to an active malware campaign. Further enrichment reveals related domains, previous sightings across multiple networks and known attacker tactics.
Rather than treating the alert as an isolated event, the analyst can quickly determine the potential scope of the threat, search for additional affected systems and take action to contain the activity. What began as a single indicator becomes a clearer picture of attacker behavior, helping the organization respond faster and with greater confidence.
Enhancing DDoS protection
Modern DDoS attacks often leverage rapidly evolving infrastructure and botnet ecosystems.
Threat intelligence helps identify malicious sources, emerging attack infrastructure and changes in adversary behavior—helping improve the ability to detect and mitigate attacks before they create business disruption.
Supporting broader cyber defense
Threat intelligence also contributes to broader security capabilities, helping organizations prioritize risk, improve visibility and adapt defenses as new threats emerge.
As adversaries evolve, intelligence helps defenders stay informed rather than reactive.
Intelligence works best as part of an ecosystem
No single feed can provide complete coverage of every threat. Modern security teams build intelligence programs around a combination of SIEM and endpoint detection and response (EDR) tools, threat intelligence feeds, internal telemetry and analyst expertise. The most valuable intelligence sources are those that enrich and strengthen the tools and playbooks organizations already use.
Effective threat intelligence helps security teams answer critical questions:
- Is this activity relevant to my organization?
- What adversary or campaign is behind it?
- What action should I take next?
By combining network visibility, intelligence enrichment and expert analysis, Black Lotus Labs helps organizations answer those questions faster and with greater confidence, strengthening the threat intelligence capabilities and workflows they already rely on.
This intelligence is integrated into Lumen products including Lumen Defender℠, Lumen DDoS protection, Defender Threat Feed and Defender Advanced Managed Detection and Response (AMDR) services to help customers identify and respond to threats more effectively. These are some of the ways an organization can introduce threat intelligence into their own infrastructure.
Explore the latest findings from Black Lotus Labs researchers in the 2026 Threatscape Report and learn more about why actionable threat intelligence matters now.
Raw indicators only tell part of the story. See how Black Lotus Labs transforms global network visibility and expert threat research into actionable intelligence that helps security teams detect, understand and mitigate cyberthreats fast.
¹Lumen Technologies, 2026 Lumen Defender Threatscape Report, 2026.
This content is provided for informational purposes only and may require additional research and substantiation by the end user. In addition, the information is provided "as is" without any warranty or condition of any kind, either express or implied. Use of this information is at the end user's own risk. Lumen does not warrant that the information will meet the end user's requirements or that the implementation or usage of this information will result in the desired outcome of the end user. All third-party company and product or service names referenced in this article are for identification purposes only and do not imply endorsement or affiliation with Lumen. This document represents Lumen products and offerings as of the date of issue. Services not available everywhere. Lumen may change or cancel products and services or substitute similar products and services at its sole discretion without notice. © 2026 Lumen Technologies. All Rights Reserved.