Advanced Persistent Infrastructure Tracking
ID: c5be80a6-2e3d-5d46-a9d8-03d04a441550
STIX ID: report--c5be80a6-2e3d-5d46-a9d8-03d04a441550
Feed Name: Censys Blog
Threat Score
This article describes methods for tracking malicious infrastructure using OSINT services such as Censys, focusing on clustering hosts by HTTP response headers, response content, and TLS certificate data; it gives practical examples (Cobalt Strike C2 header fingerprints and APT29/WellMess certificate DNs), sample queries, an example Python-based workflow, and beginner tips for combining data sources and storing query results.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
