THREATMOSAIC: collection, curation and enrichment of indicators of compromise (IOCs)

Authors

  • Sergio Mauricio Martínez Monterrubio School of Engineering, Universidad Internacional de La Rioja (UNIR), 26006 Logroño, Spain
  • Juan Frausto Solis Tecnologico Nacional de México/IT Cd Madero
  • Juan Antonio Recio García Group of Artificial Intelligence Applications, Department of Software Engineering and Artificial Intelligence, Faculty of Computer Science, Universidad Complutense de Madrid, Ciudad Universitaria, 28040 Madrid, Spain

DOI:

https://doi.org/10.61467/2007.1558.2025.v16i3.848

Keywords:

threat indicators of compromise, cyber intelligence, threat information sharing IOC

Abstract

 In this research an experimental software is developed for the classification, analysis and enrichment of indicators of compromise (IOCs), codenamed THREATMOSAIC. This software can import IOCs in bulk, classifying them according to whether they are IPv4, IPv6, URLs, MACs, e-mails, DNS domains or MD5, SHA1 and SHA256 hashes, sorting and sanitizing them in an effective and efficient way. All this is combined with the STIX2.1 standard, generating a directional graph enriched with information obtained from analysis through third-party REST APIs. Mainly information collected through services such as Virus Total, Abuse IPDB, IP Stack or Whois. Finally, the software allows sharing threat information in STIX2.1 format through the TAXII protocol via a server to which requests can be made from threat exchange platforms.

Downloads

Published

2025-07-14

How to Cite

Martínez Monterrubio, S. M., Frausto Solis, J., & Recio García, J. A. (2025). THREATMOSAIC: collection, curation and enrichment of indicators of compromise (IOCs) . International Journal of Combinatorial Optimization Problems and Informatics, 16(3), 441–457. https://doi.org/10.61467/2007.1558.2025.v16i3.848

Issue

Section

Recent Advances on Soft Computing

Most read articles by the same author(s)