Our cybersecurity experts and advanced threat technology identify and eliminate threats fast.
What is Black Lotus Labs?
The Threat Research and Operations arm of Lumen, Black Lotus Labs® leverages unmatched network visibility to help protect your business and keep the internet clean. By powering Lumen® Rapid Threat Defense, Black Lotus Labs automates protection and proactively neutralizes threats—using global network data flows combined with machine learning algorithms to detect, classify and validate malicious actors. Learn more on the Black Lotus Labs X/Twitter feed and blog archive.
The Threat Research and Operations arm of Lumen, Black Lotus Labs® leverages unmatched network visibility to help protect your business and keep the internet clean. By powering Lumen® Rapid Threat Defense, Black Lotus Labs automates protection and proactively neutralizes threats—using global network data flows combined with machine learning algorithms to detect, classify and validate malicious actors. Learn more on the Black Lotus Labs X/Twitter feed and blog archive.
See how Black Lotus Labs helps protect your business (1:52)
Crimeware analysis and disruption
Daily monitoring of ~46,000 C2s and ~200B+ NetFlow sessions to stay on top of emerging threats.
Crimeware analysis and disruption
Daily monitoring of ~46,000 C2s and ~200B+ NetFlow sessions to stay on top of emerging threats.
Advanced actor tracking
High network visibility and owned infrastructure allows for unprecedented tracking and proactive defense.
Advanced actor tracking
High network visibility and owned infrastructure allows for unprecedented tracking and proactive defense.
Automated threat repulsion
Proactive defense through automated threat blocking helps eliminate threats before they cause harm.
Automated threat repulsion
Proactive defense through automated threat blocking helps eliminate threats before they cause harm.
Products supported with Rapid Threat Defense
DDoS Mitigation
Activate powerful protection against single and multi‑vector attacks with minimized downtime.
Streamline security with a cloud‑based platform to simplify threat management for hybrid security environments.
Maximize efficiency with automated defense and proactively protect your critical assets against harmful cyberthreats. Learn more about how you can put Rapid Threat Defense to work for your business in our report.
Maximize efficiency with automated defense and proactively protect your critical assets against harmful cyberthreats. Learn more about how you can put Rapid Threat Defense to work for your business in our report.
Learning Center
Featured Blog
The Darkside Of TheMoon
Learn how Black Lotus Labs identified a long‑running campaign targeting outdated routers with “TheMoon” malware, commonly used as the foundation of a notorious, cybercriminal‑focused proxy service known as Faceless.
Learn how Black Lotus Labs identified a long‑running campaign targeting outdated routers with “TheMoon” malware, commonly used as the foundation of a notorious, cybercriminal‑focused proxy service known as Faceless.
What people are saying
“We have that global internet backbone where we collect 200B netflow sessions per day, which allows us to parse through this data and look for who exactly is being infected.”
– Danny Adamitis, Lumen Black Lotus Labs
“We have that global internet backbone where we collect 200B netflow sessions per day, which allows us to parse through this data and look for who exactly is being infected.”
– Danny Adamitis, Lumen Black Lotus Labs
“Lumen’s research team said the purpose of AVrecon appears to be stealing bandwidth—without impacting end‑users—in order to create a residential proxy service to help launder malicious activity…”
– KrebsonSecurity
“Lumen’s research team said the purpose of AVrecon appears to be stealing bandwidth—without impacting end‑users—in order to create a residential proxy service to help launder malicious activity…”
– KrebsonSecurity
“Our data illustrates the winding down of operations leading up to QakBot’s seasonal ‘lull’ in operations, which appears in part to have been accelerated by good work from Lumen’s Black Lotus Labs.”
– Team Cymru
“Our data illustrates the winding down of operations leading up to QakBot’s seasonal ‘lull’ in operations, which appears in part to have been accelerated by good work from Lumen’s Black Lotus Labs.”
– Team Cymru
Resources
REPORT
Rapid Threat Defense helps proactively protect your critical assets and more
Please complete the form below and one of our specialists will contact you within one business day.
Thank you!
One of our expert sales specialists will review your request and contact you within one business day.
If you have any immediate questions, please contact us at 800-871-9244.