The new scouting tool for threat hunting and malicious infrastructure analysis promises to level up users’ security operation centers.

By

Regional Editor for Australia and New Zealand,

CSO |




shutterstock 175644863 scattered clutter of nuts bolts wrenches tools in black and white

TrifonenkoIvan / Shutterstock

Team Cymru has launched Pure Signal Scout, an external threat-hunting and malicious infrastructure analysis tool to “level up” security operations centers (SOCs). Under the promise of being the “fastest” tool available for threat insights, Pure Signal Scout is expected to save analysts’ time by providing fast answers to complex queries.

“We are now achieving in one working day what used to take several,” Josh Picolet, team leader of Team Cymru’s S2 Threat Research, said in a statement. This includes determining if an IP is important to a threat investigation. Another point factoring in the speed of response is that Scout is cloud-based and designed to eliminate the need to deploy multiple data services and solutions. It also eliminates the need to create custom scripts to combine disparate threat feeds and data sources.

Other benefits of the threat-hunting tool

Scout was designed to enable analysts of all experience levels to see previously unseen activities, helping companies with insights to identify and counteract threats.

Team Cymru said that prior to Scout only experienced analysts from Fortune 50 organizations had access to products using external threat telemetry that includes NetFlow, PDNS, and many other datasets that enable threat hunters and security analysts’ visibility beyond their own networks.

Those using Scout have access to Team Cymru’s Pure Signal threat intelligence and enable visibility of cyber adversary infrastructure and network activity before, during, and after a cyberattack. It provides an intuitive interface and API integrations, which allows for many use cases. Furthermore, analysts can merge results across internal logs, SIEM solutions, and data tools to gain a broader picture and more precise intelligence.

Organizations can create their own threat intelligence

“Using Scout’s API, tools like analyst notebook Maltego, or even SIEM tools like QRadar and Splunk, can support automation through integration. This enables organizations to create their own threat intelligence, and then build workflows that better support their security objectives,” a spokesperson tells CSO.

Scout also offers 24/7 helpdesk support to customers. Pure Signal Scout is available now, globally, with user-based pricing on a subscription model.

With years of experience covering technology and business across the IT channel, Samira Sarraf managed the enterprise IT content at and wrote for the CIO.com, CSO Online, and Computerworld editions in Australia and New Zealand. She is now an editor with CSO Online global.

Copyright © 2023 IDG Communications, Inc.