Blog
Fix the TLS 1.3 Hostname Visibility Gap with IP Categorization
For years, security vendors made a quiet assumption: when a device on your network opens a TLS connection, the Server Name Indication (SNI) field in the ClientHello will tell you exactly where it's going. That hostname became the foundation of every DNS filter, every...
DNS Blocklist Feeds: How to Evaluate What You’re Actually Getting
If you're evaluating DNS blocklist feeds, you already know what they do. This post skips the explainer and gets to the part that actually matters: how to tell whether the feed you're running—or considering—is actually any good. Most teams set up a DNS blocklist once...
SIEM Threat Enrichment Is Too Late — Fix It with Tenzir + alphaMountain
Today we're announcing an integration with Tenzir that moves URL enrichment out of the SIEM and into the security data pipeline — where it can actually change outcomes. Most SIEM threat enrichment strategies share the same flaw: they start after data has already...
alphaMountain Now Classifies 92 Web Filtering Categories
Your DNS filter sees every query your network generates. But seeing a query and understanding it are two different things. Most URL classification systems were built around a specific assumption: the host being queried is a website, and the website has content worth...
How to Use an IP Reputation Score API: What the Data Means and How to Act on It
🔍 Want to look up an IP reputation score right now? Enter any IP address into threatYeti and get a full reputation score, threat breakdown, and infrastructure context — no account required. Free, instant, no rate limit for manual lookups. Every security product that...
The Ultimate Web Classification Guide (2026)
**Updated for 2026 to include new categories: DNS Over HTTPS, Local/Non-Routable, Network Access/Captive Portal. If you manage a firewall rule-set, write secure-web-gateway policies, wrangle CASB shadow-IT reports, or simply lose sleep over which URLs your workforce...






