Investigating threats using IBM X-Force Exchange
IBM X-Force Exchange is a threat intelligence sharing platform that SOC analysts can use to investigate IPs, domains, URLs, and hashes. By accessing the IBM X-Force website (https://exchange.xforce.ibmcloud.com/), analysts can find the search form, which allows them to enter the artifacts such as IPs, domains, URLs, and hashes. See Figure 14.15:
Figure 14.15 – The IBM X-Force website
As you can see, the main web page includes the most trending threats in the form of hashtags and dashboards; most of them are analyzed and collected by the X-Force researcher teams.
Investigating suspicious domains
As we mentioned, the IBM X-Force platform allows you to investigate suspicious domains and URLs. Let us start investigating the antibasic[.]ga
domain by entering it into the search form. See Figure 14.15:
Figure 14.16 – Investigating the antibasic[.]ga domain
As you...