logo

Advanced Persistent Infrastructure Tracking

ID: c5be80a6-2e3d-5d46-a9d8-03d04a441550

STIX ID: report--c5be80a6-2e3d-5d46-a9d8-03d04a441550

Feed Name: Censys Blog

Threat Score
55/100

Date Published: 2020-12-07

Date Updated: 2026-04-27

...
...

This article describes methods for tracking malicious infrastructure using OSINT services such as Censys, focusing on clustering hosts by HTTP response headers, response content, and TLS certificate data; it gives practical examples (Cobalt Strike C2 header fingerprints and APT29/WellMess certificate DNs), sample queries, an example Python-based workflow, and beginner tips for combining data sources and storing query results.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.