With 89% of ransomware attacks now exfiltrating data, BlackFog is pioneering technology to prevent data exfiltration and ransomware. Using Spamhaus’ data, BlackFog validates its rich data, providing context to its users, reinforcing its anti data exfiltration (ADX) services. Read on to find out how.

Getting to know BlackFog

BlackFog is a global cybersecurity company specializing in on-device anti data exfiltration technology. The pioneering software protects SMEs through to enterprises from security threats such as ransomware, malware, phishing, unauthorized data collection and profiling. Yet, what really sets BlackFog apart is its preventative approach to cyber security, using behavioural analysis to pre-emptively identify and neutralize attacks before they occur.

With most solutions on the market being cloud-based, they rely on a centralized cloud console or a SIEM solution to identify anomalies remotely before raising an alert. BlackFog is different. The behavioural analysis occurs on the device in real time, allowing the threat to be stopped immediately.

To achieve this BlackFog requires rich data with an accurate ruleset that is constantly updated, validated and refined.

Getting to know the solution

BlackFog’s anti data exfiltration technology crowdsources dozens of different datasets, ranging from IP and domain reputation to ransomware feeds and real-time dark web scans.

BlackFog’s behavioural based technology not only blocks threats immediately, but also determines intent based on over 20 different parameters, including process injection, anomalies in communication patterns, baseline data volume, etc.

This behavioural analysis operates at the endpoint, rather than being sent to the cloud. By gathering as much context and information as possible, the technology is trained against potential threats and continuously developed to devise new rule sets and behavioural techniques.

The outcome? Not one customer has been breached by ransomware since installing the software, highlighting the effectiveness of the proactive data-driven approach.

How does BlackFog use Spamhaus data?

Two words: validation and context. The IP and domain data available via the Spamhaus Intelligence API (SIA) enriches the BlackFog data pool providing additional insight and signal. When an anomaly is highlighted at the endpoint, the information is returned to the cloud console, and the decision is then validated against the Spamhaus data.

SIA also adds value in providing new context BlackFog didn’t previously have, particularly valuable for the virtual CISO service. Aimed at smaller companies that cannot afford full-time IT professionals, the service analyses a company’s security environment, providing a detailed report. SIA provides context and insight to help interpret the data, identifying those potential threats or weaknesses in the company’s security posture. As Dr. Darren Williams, Founder and CEO of BlackFog explained “Our Virtual CISO customers have really appreciated the extra insights and details relating to why we’re blocking a specific resource or activity.”

Unique data

As we’re all aware, when it comes to data, quality is king. The diverse datasets collected internally and via API provide multiple points of validation, building accuracy and context.

Nonetheless, there are valuable data points that BlackFog is unable to obtain or that require a significant investment to create, therefore it’s a sensible commercial decision to partner with a third party. This is where Spamhaus comes in.

Having known about Spamhaus as a reputable vendor for years, BlackFog was on the hunt for feeds to give additional context and validation to their rich data. Fortunately, SIA was launched, offering something different to the rest of the market – unique sets of reputation data relating to IPs and domains, including domain authority scoring and the time a domain was registered.

For BlackFog, the availability of such data was a huge win, because let’s face it, creating this dataset would have been a huge undertaking. So, who better to buy it from, than the leaders in IP and domain reputation.

And the benefits for BlackFog?

Easy to use, plenty of time saved and even more data!

As SIA uses the latest standards – RESTful API – BlackFog hooked up and started consuming the data within the hour. In their own words, “implementation was easy and trivial”. But the true value is in the data itself.

By effortlessly adding an extra layer of validation and context, BlackFog’s analysis is reinforced in quality and reliability. This both empowers virtual CISOs with more detail and results in fewer unnecessary queries regarding blocked potential threats. Ergo, time is saved internally, and a clear picture of potential threats is provided, ultimately leading to better decision-making!

Great work BlackFog – we’re proud to be on this journey with you!

You can learn more about the Spamhaus Intelligence API and start a free 30-day trial here.

Spamhaus Intelligence API (SIA)

Spamhaus Intelligence API (SIA) contains context-rich metadata relating to IP and domain reputation. Integrate this data with your applications to enhance existing data feeds, or consume as an independent data source.

In this easy-to-consume format, SIA can be used for threat detection and investigation, risk scoring, customer vetting, validation and much more.

  • Save valuable time investigating and reporting
  • Simple and quick to access
  • Data you can trust in

Postmastery enhances email deliverability services with Spamhaus Intelligence API

5 September 2023

Case Study

Using Spamhaus’ data, Postmastery has enhanced its email deliverability optimization services by giving customers additional reputational context. We spoke with Willem Stam and Yves-Marie Le Pors-Chauvel of Postmastery to find out what this means for their customers.

Enrich, protect, and inform with Domain Reputation Data via API

7 June 2023

News

Today, Spamhaus Technology’s Domain Reputation Data via Spamhaus Intelligence API (SIA) goes into production. This rich domain dataset provides valuable signals relating to every single domain Spamhaus researchers observe.

Mailkit and Omnivery keep email services secure with Spamhaus Intelligence API

5 June 2023

Case Study

Email security is integral to Mailkit's operations. To ensure they continue to be “the ones who know how to deliver” they’re using rich domain reputation data via the Spamhaus Intelligence API to vet potential customers.