Silent Push Partners with Velexon Cybersecurity

Silent Push partners with Vexelon to bring preemptive cyber defense to the Western Balkans

Brad Taylor
Brad Taylor
Global Head of Strategic Partnerships and Alliances, Silent Push

I’m excited to announce our strategic partnership with Vexelon, a cybersecurity firm providing managed security operations, incident response, and advisory services across the Western Balkans. Through this partnership, Vexelon clients gain access to the Silent Push Preemptive Cyber Defense platform, bringing upstream infrastructure visibility into the heart of a managed SOC operation serving one of Europe’s most actively targeted regions.

Vexelon runs round-the-clock security operations for organisations across North Macedonia and Kosovo, with a team certified across OSCP, OSWE, CEH, and ISO 27001. Their work covers SOC-as-a-Service, managed detection and response, attack surface management, incident response, and compliance readiness. For a lot of their clients, Vexelon is the security team, full stop. That kind of relationship is where preemptive intelligence really earns its keep.

A region that has learned the hard way

The Western Balkans has spent the past few years learning something the rest of Europe is still working through. Cyber threats here are targeted, they tie into bigger geopolitical tensions, and they keep picking up pace.

Since Russia’s full-scale invasion of Ukraine, state-linked actors have used the Balkans as a testing ground for hybrid warfare tactics. Russian-speaking groups disrupted Montenegrin government services for weeks in 2022. Iranian-linked actors hit Albanian parliament and critical infrastructure, leading Albania to sever diplomatic ties with Tehran. Kosovo faced attacks on telecommunications and media bodies. North Macedonia has experienced relentless targeting of state institutions, from the Health Insurance Fund to the Agriculture Ministry, often leaving agencies without systems for weeks at a time. In March 2026, Iranian-linked hackers from Homeland Justice again targeted Albanian institutions, publishing sensitive parliamentary data.

There’s a familiar pattern running through these incidents. Attackers set up their infrastructure quietly, get their staging grounds in place, and start operating well before anyone notices. By the time a SOC alert goes off, the prep work is done and the attacker already has a head start.

What changes when the SOC starts earlier

Vexelon’s clients have outsourced their security operations entirely. What Vexelon can see, act on, and prevent directly determines what those organisations experience. That dependency makes the quality of the underlying data more important than in almost any other model.

A lot of SOC workflows kick in too late in the story. The alert lands once the attacker is already up and running, so the analyst is triaging, investigating, and responding against infrastructure that’s been live for weeks. The SOC is genuinely good at the job. The trouble is the starting position, which the adversary set in advance.

The Context Graph changes that starting position. It continuously maps how infrastructure is created, managed, and connected across DNS, WHOIS, certificates, and hosting data at internet scale. When the management patterns match the TTPs adversaries use to build and coordinate campaigns, the Context Graph surfaces those clusters as Indicators of Future Attack® (IOFA): verified signals that a staging ground exists before it has been pointed at anyone. Vexelon’s SOC now has an average of 154 days of lead time before a campaign reaches a client’s perimeter.

That lead time helps both human analysts and automated detection and response workflows. Vexelon runs these automated workflows for their clients, and the Context Graph was built to be machine-readable from day one, with APIs made for automated enrichment and triage and signals that carry clear data provenance. Feed IOFA into those workflows and automated triage gets to work from deterministic infrastructure facts instead of probabilistic scores and noisy feeds. False positives go down, decisions speed up, and the team can actually stand behind the actions those workflows take.

For a managed SOC running security on behalf of organisations that have no in-house capability to fall back on, that difference matters every single day.

Adversary operations are built on infrastructure that is assembled long before execution is visible to a SOC. Traditional detection starts at telemetry, which is already post-deployment from an attacker’s perspective. By integrating upstream infrastructure intelligence into our SOC pipeline, we extend visibility into the adversary’s build phase, allowing us to identify staging activity before it becomes an active threat.

Valon Dauti
Founder & CEO, Vexelon Cybersecurity

The right moment for the region

The Western Balkans is undergoing a significant shift in how it approaches cybersecurity. EU accession requirements are driving NIS2 alignment across the region. Countries including Albania, Montenegro, and North Macedonia are investing in national cybersecurity capacity after years of fragmented, reactive frameworks. Organisations that previously had no formal security posture are now building one, and many are turning to managed service providers like Vexelon to do it.

That’s where the foundation really matters. Organisations standing up their security programs for the first time get to build on preemptive intelligence from the start. Bringing the Context Graph into Vexelon’s managed SOC gives their clients a security operations capability that can spot adversary infrastructure being assembled before it’s ever turned against them.

To learn more about how Silent Push and Vexelon can protect your organisation, visit vexelon.io or book a walkthrough with our team.

Silent Push 6.0 Is Here

The Latest Evolution of the Preemptive Cyber Defense Platform Is Built for Speed, Signal, and Decisive Action



The launch of Silent Push 6.0 marks a major evolution of our preemptive cyber defense platform, enabling security teams to operationalize faster, navigate more easily, and get ahead of threats earlier in the attack kill chain. 

Silent Push 6.0 truly eliminates noise to build meaningful signals on attacker infrastructure to preempt potential attacks, no one else can do this in the market. Launching 6.0 gives enterprise teams and government defenders an opportunity to detect significant threats earlier to take decisive action and continuously improve their cyber risk posture as early as possible in the attack kill chain.

Ken Bagnall
Co-Founder & CEO, Silent Push

What’s New in Silent Push 6.0

Traffic Origin

Built for fraud prevention, KYC (Know Your Customer), hiring verification, and incident response, Traffic Origin now includes full-year data access and tighter permissioning controls. A new dedicated interface gives teams definitive visibility on malicious traffic, behaviors, and infrastructure changes, surfacing the true country of origin of any IP address. 

MCP Server

A new hosted endpoint connects Silent Push data directly to AI environments, including Claude and ChatGPT. Analysts can run natural-language investigations, enrich indicators, pivot across historical DNS data, cluster adversaries by fingerprint, and build reportable pivot graphs to get structured, source-grounded answers without opening the platform.

Screenshot of new hosted endpoint connecting Silent Push data directly to various AI environments
The new hosted endpoint connects platform data directly to AI environments

Navigation and Module Restructure

The platform is now organized around three intuitive modules: 

  • Defend (proactive SIEM, SOAR, and firewall integrations powered by Indicators of Future Attack® (IOFA)  
  • Insight (full artifact context in a single view for faster SOC triage)
  • Reconnaissance (threat hunting and infrastructure tracking)  

Traffic Origin is housed in a fourth module, Advanced Attribution. 

Screenshot of the Insight module that is part of the Silent Push platform
Example of the Insight module

Research Report Enhancements

Significantly improved load performance, expanded content options, including in-report video tutorials, and pivotable indicators throughout. The TLP Amber Report API is now unlocked, giving teams programmatic access to report metadata.

Screenshot of the Silent Push TLP Reports main page
Example of the Silent Push TLP Reports main page

Bulk Enrichment

Available in the Insight module, Bulk Enrichment lets analysts quickly assess a set of suspicious assets in a centralized view, filling the gap when early-stage investigations warrant more than a single-lookup interface.

Screenshot of the Bulk Enrichment feature inside of the Insight module in Silent Push platform 6.0
Screenshot of Bulk Enrichment, inside of Insight Search

Book a Demo – Sign Up for Community Edition

Interested in seeing Silent Push 6.0 in action?

Start a conversation with one of our platform experts to see how the latest capabilities can help your team neutralize threats before an attack is fully launched.

We also offer a free Community Edition so defenders can see how our platform integrates with their existing security stack.

Silent Push Unveils Platform 6.0

Driven by Traffic Origin’s proprietary data, the redesigned platform connects five key cybersecurity solutions across three clear modules: Defend, Insight, and Reconnaissance to streamline capabilities and surface what matters faster.

RESTON, VA, June 24, 2026—Silent Push, the leading preemptive cyber defense company, today announced a major evolution of its preemptive cyber defense platform with the launch of Silent Push 6.0. Designed to enable security teams with faster operationalization and easier navigation, this latest release includes enhancements to Traffic Origin and new integration/workflow capabilities so teams can play from ahead with an approach rooted in ‘threat-informed defense.’


“Silent Push 6.0 truly eliminates noise to build meaningful signals on attacker infrastructure to preempt potential attacks – no one else can do this in the market,” said Ken Bagnall, Co-Founder and CEO, Silent Push. “Launching 6.0 gives enterprise teams and government defenders an opportunity to detect significant threats earlier to inform decisive action to continuously improve cyber risk posture as early as possible in the attack kill chain to defend with a threat-informed approach to cyber defense.”


Silent Push 6.0 meets security teams where they work, surfaces what matters, and makes teams faster without requiring a new platform or different tools.

Key features and capabilities include:

  • Traffic Origin: A new dedicated capability unique to only Silent Push in the market that gives teams definitive visibility on malicious traffic, behaviors, and infrastructure changes to understand true country origin. Silent Push has built a new dedicated interface, full-year data access, with tighter permissioning controls to surface IP address true country of origin, and critical capabilities for use cases including fraud prevention, Know Your Customer (KYC), hiring verification, and Incident Response (IR).
  • MCP Server: A new hosted endpoint connects Silent Push data to AI environments, including Claude, ChatGPT, and others. Analysts can run investigations in natural language (enriching indicators, pivoting across historical DNS and shared infrastructure, clustering adversaries by fingerprint, scoring risk, and building reportable pivot graphs) and get structured, sourcegrounded answers without opening the platform. For customers, this cuts token usage through automatic context reduction and accelerates the workflow of question-to-investigation to getting an answer from Silent Push’s extensive dataset.
  • Navigation & Module Restructure: A trio of easy-to-navigate modules – Defend, Insight, and Reconnaissance – encompasses the Silent Push solution. Defend covers proactive security stack integrations, such as SIEM, SOAR, and firewall feeds, with its proprietary IOFA. (Indicators of Future Attack). Insight gives SOC teams full artifact context in a single view for faster triage. Reconnaissance is for threat hunting and IR teams building and tracking infrastructure. A fourth module, Advanced Attribution, houses Traffic Origin.
  • TLP Amber Reports: Enhanced backend and infrastructure to dramatically improve load performance. This expands content options, including video tutorials that can be accessed by teams directly in the reports. Indicators mentioned in reports are now pivotable, and the TLP Amber Report API is unlocked, giving teams programmatic access to report metadata.
  • Bulk Enrichment (Insight): Provides teams with insights on core indicators, allowing analysts to quickly see Silent Push’s intelligence in a centralized view. Designed for early investigations when teams have a set of suspicious assets and need to quickly determine what to investigate first. Available in the Insight module, Bulk Enrichment fills the gap that analysts encounter when they only have a single-lookup interface.

About Silent Push

Silent Push is the preemptive cyber defense company. It is the first and only solution to provide a complete view of emerging threat infrastructure in real time, exposing malicious intent through its Indicators Of Future Attack® (IOFA) data, enabling security teams to proactively block hidden threats and avoid loss. The Silent Push standalone platform is also available via API, integrating with various security tools, including SIEM & XDR, SOAR, TIP, and OSINT, providing automated enrichment and actionable intelligence. Customers include some of the world’s largest enterprises within the Fortune 500 as well as government agencies. A free Community Edition is available. For more information, visit www.silentpush.com or follow on
LinkedIn and X.


See Silent Push 6.0 in action

Start a conversation with one of our platform experts to see how the latest capabilities can help your team neutralize threats before an attack is fully launched.

We also offer a free Community Edition so defenders can see how our platform integrates with their existing security stack.

Partnership Announcement - CDL Cyber Intelligence

Silent Push partners with CDL Cyber Intelligence to bring preemptive defense to the United Kingdom

Brad Taylor
Brad Taylor
Global Head of Strategic Partnerships and Alliances, Silent Push

I’m pleased to share that Silent Push has entered a strategic partnership with CDL Cyber Intelligence, an intelligence-led cybersecurity firm serving organisations across the UK and Europe.

When I first sat down with the CDL team, what struck me was how clearly they had drawn their line in the sand. They built their practice on a straightforward conviction that anticipating threats requires intelligence, not just tooling. Their team includes former intelligence officers, ethical hackers, and security engineers with decades of experience across threat intelligence, incident response, attack surface management, and dark web monitoring.

That depth is why their clients across government, financial services, healthcare, and critical infrastructure turn to them when the threat picture matters most. We built Silent Push on the same conviction, which is part of why this partnership made sense to me so quickly.

The window most tools miss

The most capable threat actors targeting UK organisations spend weeks or months getting ready before anyone sees them. They register infrastructure, age domains, and stand up the hosting they will run a campaign from, all well before they go after a target. By the time a detection tool fires, the attacker has already finished the hard part.

The Context Graph maps that preparation phase. It continuously tracks how infrastructure is created, managed, and connected across DNS, WHOIS, certificates, and hosting data at internet scale, every day. When the management patterns match the operational TTPs adversaries use to build and run campaigns, the Context Graph surfaces those clusters as Indicators of Future Attack®: verified signals that a staging ground exists right now, before it has been pointed at anyone. CDL’s clients get an average of 157 days of lead time before a campaign reaches their perimeter.

Why it matters for the UK

The UK sits at a particular intersection of risk. As a NATO member, a major financial centre, and a jurisdiction with significant government and critical infrastructure targets, it draws sustained attention from state-linked threat actors alongside opportunistic campaigns hitting every sector. Silent Push Traffic Origin adds another layer that matters here. Many of the most capable actors targeting UK organisations route their activity through residential proxies and VPN infrastructure to look local and legitimate.

Traffic Origin identifies the true upstream country of origin controlling a connection, even when the observed IP looks clean. Pairing that with a team like CDL, who already know how to read and act on raw intelligence, gives their clients something I have not seen many teams able to offer.

We built CDL around the conviction that intelligence has to come before the event. That’s why the Context Graph fits the way we work. Our clients want to know what’s being pointed at them before it arrives, and Silent Push is the only platform that gives us that visibility.

Jonathan Palmer
Co-Founder, CDL Cyber Intelligence

To learn more about how Silent Push and CDL Cyber Intelligence can protect your organisation, visit cdlcyber.com or book a walkthrough with our team.

Use Case Deep Dive: Phishing Hit Your Inbox. Now Find the Other 40 Domains.

One reported phishing email is rarely the whole story.

Access the full recording to see how to work outward from one phishing email, using shared hosting, registration patterns, and infrastructure fingerprints to surface the rest of the campaign.

Watch it now.

Operation Endgame Targets SocGholish: What It Means for Defenders

Last year, Silent Push published research into SocGholish and its operator, TA569, highlighting how the group evolved from a “fake browser update” threat into one of the most sophisticated malware delivery and initial access operations active today.

Our research examined the infrastructure, traffic distribution systems, victim filtering mechanisms, and criminal partnerships that helped make SocGholish a key enabler within the broader cybercrime ecosystem.

Through compromised websites, carefully crafted social engineering, and resilient infrastructure, TA569 built an operation capable of delivering access at scale to downstream threat actors.

Today, we are encouraged to see continued international law enforcement action against this threat through Operation Endgame.

What did Operation Endgame disrupt?

Authorities announced coordinated actions targeting the infrastructure associated with SocGholish, including the remediation of thousands of compromised websites and the disruption of supporting infrastructure used in the malware delivery chain.

The action represents one of the most significant efforts to date against a threat actor ecosystem that has spent years refining techniques designed to evade detection and maintain access at scale.

For defenders, this disruption highlights the importance of attacking the infrastructure that powers cybercrime operations. While malware families and payloads may change, the underlying infrastructure and delivery mechanisms often provide opportunities for both intelligence collection and disruption.

High-level infection rundown of SocGholish (operated by TA569)

Why does disrupting an initial access broker matter?

SocGholish has long occupied a unique position in the cybercrime landscape. Rather than focusing exclusively on ransomware or data theft, TA569 specialized in obtaining and monetizing initial access, making the operation a force multiplier for other criminal groups. This is why sustained law enforcement pressure is so important.

Disrupting an initial access provider can have cascading effects across multiple criminal ecosystems that depend on that access. While sophisticated actors often attempt to rebuild after takedowns, coordinated international actions increase their operational costs, reduce attacker efficiency, and create valuable opportunities for defenders to identify successor infrastructure.

We are pleased to see Operation Endgame continue to target sophisticated cybercriminal operations such as SocGholish. Collaboration between researchers, industry partners, and law enforcement remains one of the most effective ways to disrupt threats at scale, and actions like these demonstrate the impact that coordinated efforts can have against some of the internet’s most persistent adversaries.

See adversary infrastructure before it makes the news

Silent Push gives security teams visibility into threat actor infrastructure during the preparation phase, weeks or months before attacks launch. Book a demo to see the Silent Push platform in action.

What is Operation Endgame?

Operation Endgame is a coordinated international law enforcement action targeting cybercriminal infrastructure. The operation has included actions against malware delivery networks and initial access operations, including the infrastructure associated with SocGholish and its operator TA569.

What is SocGholish?

SocGholish is a malware delivery framework operated by the threat group TA569. It works by compromising legitimate websites and serving fake browser update prompts to visitors, which deliver malware. TA569 used this access to provide entry points to downstream criminal groups, including ransomware operators.

What is an initial access broker?

An initial access broker is a threat actor that specializes in gaining unauthorized access to victim environments and selling or leasing that access to other criminal groups. TA569 operated in this way, making SocGholish a supply chain for a wide range of downstream attacks.

Why does law enforcement action against cybercriminal infrastructure matter?

Taking down the infrastructure behind malware delivery operations disrupts multiple criminal groups simultaneously, not just the original operator. It increases the cost and complexity of rebuilding, creates windows for intelligence collection on successor infrastructure, and demonstrates that coordinated international action can reach threat actors who previously operated with relative impunity.

What did Silent Push research uncover about SocGholish before Operation Endgame?

Silent Push published research examining TA569’s infrastructure, traffic distribution systems, victim filtering mechanisms, and criminal partnerships. That research is available at silentpush.com/blog/socgholish/


Silent Push Named The Best National Cyber Defense Platform of 2026

Cybersecurity Stars Awards 2026 Recognition Underscores Silent Push Preemptive Cyber Defense

With nation-state actors, criminal organizations, and APT groups building attack infrastructure long before they strike, the question of which platform gives defenders the earliest, most actionable visibility has never mattered more. Each year, The Hacker News, the world’s #1 cybersecurity publisher, recognizes the companies setting the standard through its Cybersecurity Stars Awards. This year, one platform stood out above the rest in national cyber defense.

Screenshot of Hacker News Awards to Silent Push

Silent Push has been named the “Best National Cyber Defense Platform” in the 2026 Cybersecurity Stars Awards.

Silent Push Co-Founder and CEO Ken Bagnall acknowledged the team and the customers who make it possible:

“This award reflects the hard work of our entire team and the trust of the organizations that depend on us to protect their most cricitical infrastructure. We’re proud to be recognized for the work that matters most: stopping attacks before they happen.”

Detect Adversary Infrastructure Before It Breaches Your Perimeter

Most security tools surface threats only after malicious activity is already underway. Silent Push takes a fundamentally different approach. Our Preemptive Cyber Defense platform delivers real-time visibility into previously unknown adversary-controlled infrastructure, generating Indicators of Future Attack® (IOFA) that allow security teams to neutralize threats before they are launched.

Used by U.S. government organizations, Fortune 10 companies, and prominent global brands, our technology maps the domains, IPs, and hosting providers that attackers rely on to stage and execute operations, exposing malicious intent at the preparation phase, weeks before an attack begins.

The Hacker News specifically recognized Silent Push in the National Cyber Defense category, reflecting the platform’s growing role in helping federal agencies, law enforcement, and intelligence community organizations get ahead of nation-state actors and APT groups during the setup and staging phases of an attack, not after the damage is done.

Book a Demo – Sign Up for Community Edition

Interested in learning more about the Silent Push preemptive cyber defense platform?

Start a conversation with our platform experts to see how our solutions can protect your organization by neutralizing threats before an attack is fully launched.

What is Silent Push’s Preemptive Cyber Defense Platform?
Silent Push is a Preemptive Cyber Defense Platform that gives security teams real-time visibility into adversary-controlled infrastructure before it is used in an attack. The platform maps domains, IP addresses, and hosting providers that threat actors use to stage operations, and generates Indicators of Future Attack® (IOFA) that allow security teams to act during the preparation phase of an attack, weeks before exploitation begins.

What is an Indicator of Future Attack (IOFA)?
An Indicator of Future Attack® (IOFA®) is a proprietary signal generated by Silent Push that identifies adversary infrastructure and attack patterns before any exploitation begins. Traditional Indicators of Compromise (IOCs) are forensic artifacts collected after a breach has already occurred. IOFAs give security teams actionable intelligence during the window between attacker planning and attack execution, when threats can still be neutralized.

How does Silent Push detect adversary infrastructure before an attack?
Silent Push continuously analyzes DNS records, IP ranges, hosting patterns, and other infrastructure signals to identify domains and servers being staged for malicious use. When the platform detects patterns associated with known threat actors or attack preparation, it generates an IOFA and alerts security teams. This gives defenders visibility into attacker activity during the setup phase, before any malicious traffic reaches their environment.

What is the Best National Cyber Defense Platform award?
The Best National Cyber Defense Platform award is part of the annual Cybersecurity Stars Awards program run by The Hacker News, the world’s #1 cybersecurity publisher. It recognizes the security platform that has demonstrated the strongest capability in defending national infrastructure against advanced threats, including nation-state actors and APT groups.

Why did Silent Push win the Best National Cyber Defense Platform award in 2026?
Silent Push was named the Best National Cyber Defense Platform in the 2026 Cybersecurity Stars Awards because of its ability to identify adversary infrastructure during the setup and staging phases of an attack. The platform is used by U.S. government organizations, federal agencies, and intelligence community organizations to get ahead of nation-state actors and APT groups before attacks are launched.

Who uses Silent Push?
Silent Push is used by U.S. government organizations, Fortune 10 companies, law enforcement agencies, intelligence community organizations, and prominent global brands. The platform is designed for security teams responsible for defending critical national infrastructure against nation-state actors, criminal organizations, and APT groups.

How is Silent Push different from traditional threat intelligence platforms?
Silent Push generates Indicators of Future Attack® (IOFA) that identify adversary infrastructure during the preparation phase of an attack. Traditional threat intelligence platforms deliver Indicators of Compromise (IOCs), which are collected after a breach has occurred. Silent Push gives security teams the ability to act before an attack is launched, rather than responding after the damage is done.

What did Silent Push’s CEO say about winning the 2026 Cybersecurity Stars Award?
Silent Push Co-Founder and CEO Ken Bagnall said: “This award reflects the hard work of our entire team and the trust of the organizations that depend on us to protect their most critical infrastructure. We’re proud to be recognized for the work that matters most: stopping attacks before they happen.”

FIFA World Cup: Hunting 227 Phishing Domains

FIFA World Cup: Hunting 227 Phishing Domains With the Silent Push MCP Server

Nick Roy
Nick Roy
Senior Solutions Engineer, Silent Push

When the OCCIP flash alert dropped about fraudulent World Cup ticket and merchandise sites, I figured it was a good excuse to dig in. The report tied the activity to Ghost Stadium, a Chinese-speaking cybercriminal group, and included a solid list of seed domains. That’s usually all I need.

I pulled those seeds into Silent Push and used the MCP server with Claude to run the investigation. The prompt was to find the larger cluster and generate queries I can use to track new infrastructure as it spins up.

The sites were reusing the same favicons and the domains followed a consistent registration format: two or three letter prefix, then “26fifashop.site.top.” On the first day of the World Cup, 227 new domains matching that pattern had already been registered.

From there it’s straightforward. I took the generated queries into the Context Graph, confirmed the cluster, then dropped those same queries into XSOAR to run daily. Deduplicate the results, query Splunk, push to a watchlist or blocklist. Your tools stay current without someone manually hunting for new sites every morning.

If you’re already running Claude or any agentic platform, connecting it to Silent Push via the MCP server means the pivot work, query generation, and reporting all happen in one flow. No context switching.

How the Silent Push MCP server works with threat investigations

The Silent Push MCP server connects Silent Push’s datasets directly to AI and agentic platforms like Claude. Instead of manually running pivots across DNS data, web content fingerprints, and domain registration patterns inside the platform, you describe what you’re investigating and the MCP server handles the data retrieval and correlation. It returns enriched results, identifies infrastructure patterns, and generates queries you can use to track new domains matching those patterns over time. Those queries run directly in Silent Push’s Context Graph or feed into your existing SOAR and SIEM workflows. The MCP server is available with the Silent Push Enterprise Edition.

What is Ghost Stadium?

Ghost Stadium is a Chinese-speaking cybercriminal operation that builds scalable fraud ecosystems around major events. The group spins up large volumes of lookalike sites designed to sell fake tickets and merchandise, using shared infrastructure patterns (favicons, domain naming conventions, hosting clusters) that make the sites faster to deploy at scale and, with the right tooling, faster to detect.

What is the Silent Push Context Graph?

The Context Graph is Silent Push’s infrastructure correlation engine. It aggregates DNS records, WHOIS data, host scans, SSL certificates, and web content fingerprints to map relationships between domains, IPs, and threat actor infrastructure. Analysts use it to pivot from a single seed domain to a full infrastructure cluster, identify reused assets like favicons or ASN patterns, and generate detection queries that track new infrastructure matching the same behavioral fingerprints.

Sign up for Community Edition to explore our datasets for free. To use the Silent Push MCP server, get in touch with our team.

What Is the Preparation Phase? The Part of the Attack Timeline Most Tools Miss

Attack campaigns begin weeks or months before an alert fires. By the time a detection tool has something to work with, a threat actor has already registered domains, provisioned servers, configured DNS records, and tested infrastructure. That groundwork is the preparation phase, and it sits almost entirely outside the coverage of conventional threat intelligence tooling.

What Is the Preparation Phase?

The preparation phase is the period during which a threat actor builds and stages the infrastructure they intend to use in an attack. It covers domain registration, server provisioning, DNS configuration, certificate issuance, and pre-deployment testing. It ends when the campaign goes live.

Because no malicious events have occurred yet during this phase, the infrastructure being assembled appears indistinguishable from legitimate activity. There’s no endpoint behavior to flag, no connection to a known-bad indicator, and no log entry to correlate. Conventional detection tools have no signal to act on. Traditional threat data, as a result, captures roughly the final 5% of the offensive lifecycle, the point at which infrastructure is already operational and a malicious campaign is already running.

Where the IOC Timeline Actually Starts

When an Indicator of Compromise (IOC) surfaces in your stack, the threat actor behind it has often been working for weeks, and in many campaigns, months, before that point. Domains were registered and often deliberately left dormant to avoid new-registration scrutiny. Servers have also been provisioned, configured, and tested well before the campaign launched.

Security platforms built around SIEMs, EDR, and blocklists were designed around event-driven logic: something needs to happen at the endpoint, in the logs, or against a known-bad indicator before a rule can fire. That design reflects a deliberate architectural choice about where in the attack lifecycle those tools were intended to operate. The preparation phase sits upstream of all of it, which is why those tools don’t see it, and why expecting them to is asking them to do something they were never designed for.

What Happens During the Preparation Phase

The preparation phase follows a recognizable operational pattern across campaigns, even as specific assets rotate.

Some preparation-phase activities are generic, with infrastructure being built before a target is even selected. Other campaigns involve highly tailored staging, with domains that spoof a specific organization, or certificates that mimic their services. In either case, the behavioral patterns identified by the Silent Push Context Graph remain consistent.

Why Standard Threat Intelligence Arrives Late

SIEMs, EDR platforms, blocklists, and standard threat intelligence feeds share a common dependency: something has to have happened before they can act. A blocklist entry requires an indicator that has already been used maliciously. An EDR alert requires observable endpoint behavior. A SIEM correlation rule requires log data from an event that has already occurred. Threat intelligence feeds document what has been observed, meaning campaigns that have run, infrastructure that has been weaponized, and victims who have already been hit.

The data collection cycle works like this: an incident occurs, it generates data, which is processed into indicators, and those indicators eventually reach your stack. By the time that cycle completes, the preparation phase for the follow-on campaign may already be done. Traditional security tools are processing accurately and at pace, but they’re focused on activity that has already happened.

Where Defenders Have the Most Leverage

During the preparation phase, staged infrastructure can still be blocked before any breach occurs, and campaigns that have not yet launched can be disrupted without incident. Once a campaign goes operational, defensive options narrow significantly because the attacker is already inside the timeline.

Silent Push Preemptive Cyber Defense was built to operate during the preparation phase. The platform continuously maps internet infrastructure across DNS, WHOIS, certificate data, and host configurations, analyzing both known-bad assets and the behavioral patterns that appear when infrastructure is being built and managed in ways consistent with adversarial Tactics, Techniques, and Procedures (TTPs). When those patterns match the operational signatures of how campaigns are staged, our proactive technology generates Indicators of Future Attack® (IOFA): verified signals of staging environments that exist before they have been used against anyone.

The average early-detection lead time from that process is 104 days ahead of a traditional SIEM alert. For Advanced Persistent Threat (APT) campaigns, the lead time has exceeded 300 days.

What This Looks Like for Each Team

  • SOC managers working from IOC-based feeds are responding to activity that is already running. The infrastructure has been live for weeks, the campaign is operational, and alert volume is climbing. Integrating IOFA from the Context Graph into your existing stack gives your team lead time to push verified indicators into blocklists and validate staging infrastructure before that volume spike happens. Your analysts are working from current adversary data rather than reacting to events already in motion.
  • IR leads arriving at an active breach begin with a single known indicator. What that indicator rarely provides is a complete picture of what the attacker has staged and is ready to use. Adversaries build infrastructure with redundancy, so if your remediation only covers the assets identified during the active investigation, there is a real chance the attacker has left themselves a route back in. Silent Push tracks infrastructure relationships, DNS history, and WHOIS lineage so that a single starting indicator can be expanded into the full cluster of adversary-controlled assets, including fallback infrastructure the attacker intended to rely on if their primary domains or IPs were discovered.
  • CTI analysts delivering post-breach briefs are documenting what has already happened, which limits what a SOC can do with the output. Delivering IOFA for infrastructure that is now being staged, before it becomes an IOC anywhere, changes the operational value of that brief considerably. The Context Graph pre-correlates across 200+ behavioral parameters so that when you run queries in SPQL, the clustering is already complete, and the pivot work starts from a much earlier position.

See the Preparation Phase Before It Becomes an Incident

Silent Push IOFA are built on pre-breach infrastructure data. Our platform gives security teams visibility into adversary staging environments before weaponization and before alerts begin.

  • Block staging grounds before campaigns deploy. Silent Push pushes IOFA into your existing blocklists and SIEM, so your team can act on current adversary infrastructure rather than last month’s IOC feed.
  • Ingest earlier, more accurate indicators via automated feed exports. IOFA feeds are updated continuously with the latest research from our analyst team.
  • Track APT campaigns from the infrastructure up. Pre-built IOFA feeds give your team visibility into the staging patterns of APTs, an average of 104 days before those indicators appear elsewhere.

Getting Started

Request a demo to see how Silent Push surfaces the preparation phase in your environment.

NIS2's 24-Hour Early Warning Requirement: How to Actually Meet It

The 24-hour early warning obligation in NIS2 is the requirement most security teams are least prepared to meet. Many have read the directive, however few have pressure-tested their detection capability against it.

Under Article 23 of EU Directive 2022/2555, organizations in scope have 24 hours from the moment they become “aware” of a significant incident to file an early warning with their national competent authority. They have 72 hours to submit a full incident notification. And within one month, a final report is due.

That first 24-hour window is where most organizations are going to run into trouble. Filing a credible early warning requires infrastructure context that traditional threat intelligence was never designed to provide.

NIS2 covers more than you think

NIS2 applies to a significantly wider range of sectors than its predecessor. Energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, and space are all in scope. If you operate critical infrastructure or essential services anywhere in the EU, the directive applies to you.

The “significant incident” threshold is defined broadly. An incident qualifies if it has caused or is capable of causing severe operational disruption, financial loss, or material or immaterial damage to other entities. That is a low bar. Most organizations will cross it before they realize they have.

The phrase “becoming aware” is doing a lot of work in that 24-hour obligation. In practice, security teams become aware of an incident when an alert fires in their SIEM. By that point, the attacker has already been operational for some time.

The personal liability piece is worth flagging separately. Under NIS2, management bodies can be held personally liable for infringements. Senior executives are required to approve cybersecurity risk management measures and can face sanctions if their organization fails to comply. For most security leaders, that changes the conversation with the board significantly.


Assess your readiness across all three NIS2 windows

The NIS2 Incident Reporting Readiness Checklist covers detection capability, the 24-hour early warning, the 72-hour full notification, and the 30-day final report. Use it to find the gaps before an incident opens the clock.


The problem with reactive detection

Most security teams are running on IOCs: fragmented, point-in-time indicators that document what an attacker used, pulled from third-party feeds, and often stale by the time they arrive. A domain hash from a breach last month. An IP address that has since rotated. A file signature from a campaign that has already moved on.

IOCs tell you what happened. They rarely tell you who built the infrastructure, when they built it, what else they registered at the same time, or what is sitting dormant waiting to be activated. For day-to-day detection that gap is manageable. For NIS2 incident reporting, it creates a real problem.

Regulators expect your early warning to contain meaningful initial information: the nature of the incident, the systems affected, and a preliminary assessment of scope. That requires you to understand the full infrastructure picture, not just the indicator that fired the alert. Third-party IOC feeds were built for a different job.

What the NIS2 24-hour window actually requires from your detection capability

In practice, filing a complete early warning within 24 hours requires your team to already have infrastructure context assembled before the investigation begins. Most incident investigations start from a single indicator and expand outward from there, which takes time the regulation does not give you.

To file accurately, your team needs to answer three questions quickly.

  • What infrastructure is involved? The attacker’s staging environment is a cluster of assets: domains registered in the same batch, IPs sharing hosting patterns, certificates rotating on the same schedule. A single IOC shows you one node. NIS2 requires you to account for the cluster.
  • How long has this been active? Regulators will want to know when the incident began, not just when you detected it. If you cannot reconstruct the timeline from your own data, your notification will be incomplete.
  • What else is connected? Campaign infrastructure is built with redundancy. If you report on what you found and miss the rest, you risk having to revise or resubmit as more surfaces, which carries its own regulatory exposure.

How preemptive detection changes the compliance picture

The Silent Push Context Graph aggregates DNS, WHOIS, certificate data, host scans, traffic sensor data and behavioral fingerprints across the full IPv4 and IPv6 range, every day. It maps the relationships between internet assets continuously, so when an incident indicator surfaces, the infrastructure connected to it is already correlated.

Your analyst is not starting from a single stale IOC and manually pivoting across fragmented tools trying to reconstruct a picture under a 24-hour deadline. The related infrastructure cluster is already mapped. DNS history and WHOIS records show when it was first stood up. Dormant assets connected to the same campaign are visible.

At T+24, your notification goes in with an infrastructure map and a preliminary timeline attached. At T+72, the full footprint is documented with an accurate start date confirmed. At 30 days, the report reflects what actually happened, with TTPs logged and management sign-off recorded.

The average detection lead time across Silent Push customers is 104 days. For NIS2 purposes, that means the infrastructure behind a significant incident is often visible and already correlated long before an alert fires.

Context Graph Silent Push

NIS2, agentic workflows, and the data quality problem

A lot of teams are now looking at automating parts of incident response, and the 24-hour window is an obvious candidate. The problem is that automation is only as good as the data it runs on. An AI agent triaging an incident or drafting an early warning needs infrastructure context it can act on with real confidence. Feed it fragmented, stale IOC data and you get unreliable outputs at exactly the moment reliability matters most.

The Context Graph was built to be machine-consumable from day one: 250+ API endpoints, deterministic attribution, and clear confidence signals that give automated workflows something solid to act on. For teams building agentic pipelines, that matters a lot.

The EU AI Act (Regulation 2024/1689) adds a separate obligation for organizations deploying AI-assisted security systems. High-quality, verifiable inference data is an explicit requirement. Silent Push infrastructure data carries full provenance, which directly supports that for teams building automated detection and response into their stack.

What good looks like

When an incident is confirmed, your team should be able to pull up a correlated infrastructure map, establish when the staging environment was first built, identify connected assets including dormant ones, and have a credible draft early warning ready well within the 24-hour window. The investigation is not starting from scratch. It is starting from a picture that has been building continuously in the background.

At the 72-hour mark, the full cluster is documented, the timeline is accurate, and containment covers everything the attacker built, not just the subset that surfaced during the active incident. At 30 days, the final report has no gaps that require explanation.

Security teams that get there consistently have one thing in common: the underlying infrastructure data is correlated, current, and complete before the incident ever surfaces. Talk with our team to learn more.


What sectors does NIS2 apply to?

NIS2 applies to essential and important entities across energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. It also covers a wider range of digital service providers than NIS1, including managed service providers and cloud platforms.

What counts as a “significant incident” under NIS2?

An incident is significant if it has caused or is capable of causing severe operational disruption to the provision of services, financial loss to the entity, or material or immaterial damage to other natural or legal persons. Organizations should assess whether the threshold is met as early as possible, rather than waiting for confirmed damage.

How does Silent Push help meet the 24-hour early warning obligation?

The Silent Push Context Graph pre-correlates attacker infrastructure data across DNS, WHOIS, certificate records, and host scan data continuously. When an incident indicator surfaces, the related infrastructure cluster is already mapped. Investigation that would otherwise take hours of manual pivoting across tools completes in minutes, giving teams the context they need to file a credible early warning within the required window.

Does Silent Push cover third-party ICT risk monitoring for NIS2?

Yes. The Discover Shadow IT query surfaces unmanaged third-party services connected to your domain. Active tracking monitors providers like Mailchimp, SendGrid, and similar platforms for signs of weaponization. Brand impersonation detection identifies lookalike domains and fake login pages at registration. These capabilities directly support the supply chain risk monitoring obligations under NIS2.