Skip to content

CDIC Blog

Insights, research, and updates from the Cyber Defense and Intelligence Center.

All Posts

The 6.98 Second Hand-off: Tracking a Mirai-Family Botnet Across Five Nodes!

The 6.98 Second Hand-off: Tracking a Mirai-Family Botnet Across Five Nodes!

When one attacker IP fell silent after an 88-second assault on our honeypot, another picked up the exact same exploit chain; 6.98 seconds later. That near-seamless hand-off was the thread …

Jonathan Williams
Anatomy of an Outlaw: 28 Minutes Inside a Cryptomining Botnet Intrusion

Anatomy of an Outlaw: 28 Minutes Inside a Cryptomining Botnet Intrusion

No zero-days. No hackers in hoodies. Just a bot in Benin patiently guessing passwords every 2.5 minutes until one worked; then it owned the box in two seconds flat. This …

Jonathan Williams Jul 25, 2026
Inside the Honeypot: "Iranian Origin" Reconnaissance and Cryptomining Against a Public Facing Sensor

Inside the Honeypot: "Iranian Origin" Reconnaissance and Cryptomining Against a Public Facing Sensor

A public facing honeypot recorded four Iranian origin IPs over 21 June to 17 July 2026, together forming the full opportunistic attack lifecycle.

Jonathan Williams Jul 17, 2026
Following the Breadcrumbs: How Investigative Research Strengthens Cyber OSINT

Following the Breadcrumbs: How Investigative Research Strengthens Cyber OSINT

Cyber OSINT is not only about collecting technical indicators. It also depends on careful research, source verification, and the ability to connect small pieces of information without forcing conclusions. This …

Nichole Baucum Jul 17, 2026
From Intelligence to Evidence: Turning Threat Intelligence into Actionable Digital Forensics

From Intelligence to Evidence: Turning Threat Intelligence into Actionable Digital Forensics

Cyber threat intelligence provides valuable context for identifying emerging threats, but intelligence alone cannot confirm that an intrusion occurred. This article explores how investigators can transform threat intelligence into actionable …

Dielle De Noon Jul 11, 2026
Anatomy of a USPS Phishing Campaign: Google-Authenticated Delivery, Rotating Hosts, and Real-Time Backend Control

Anatomy of a USPS Phishing Campaign: Google-Authenticated Delivery, Rotating Hosts, and Real-Time Backend Control

How a phishing email led to understanding of phishing infrastructure.

Devin Fontenot Jul 11, 2026