Hi all,
Is there a logical method for analysing malicious domains/IPs that any of you folks with significant cybersecurity experience have come across?  I work with analysts who have programming backgrounds and this seems to be the best form of learning that they understand.
Sometimes when we have malicious sources at work some coworkers don't seem to be able to dig deeper than simply going to VirusTotal and inputting an IP address.
Analysis of malicious domains/IPs is of course is a significant part of "Incident Response" my primary job at work so thanks in advance for sharing your inputs and comments 
