Beyond IOCs: Enriching Threat Investigations with Global Network Telemetry


Wednesday, August 12, 2026 10AM PT | 1PM ET

Zoom Event


Modern threat and infrastructure analysis isn’t a guessing game - it’s pattern recognition at planetary scale.

Every investigation starts fragmented: a hostname here, an IP there, a slice of infrastructure behavior, a whisper of adversary tradecraft. The real challenge is stitching those fragments into something coherent before the trail goes cold.

In this webinar, we use Synapse alongside global network telemetry from Team Cymru to show what happens when infrastructure stops being static and starts becoming a living graph of behavior, exposure, and intent.

You’ll see how investigators move beyond simple IOC chasing and into structured infrastructure analysis - enriching known artifacts, operationalizing adversary TTPs, and using real-world telemetry to pressure-test assumptions. From there, the analysis expands: previously unknown infrastructure surfaces, campaigns extend through correlation and fingerprinting, and “known bad” becomes a gateway into broader actor infrastructure.

Across several practical investigations, we’ll walk through how behavioral signals, infrastructure relationships, and exposure data converge to accelerate decision-making. Whether starting from known tradecraft, exposed systems, or published indicators, the outcome is the same: faster convergence on truth, and fewer blind spots in the data.

Who Should Attend?

This session is built for analysts, threat hunters, and incident responders who know IOC-based workflows are not enough and are ready to operate at the level where infrastructure itself becomes the intelligence surface.

Presenters


Ryann Hallback
The Vertex Project


Eli Woodward
Team Cymru