logo

Playing Defense By Locating Pre-Attacks

ID: cae58834-85d7-561e-9446-850fffac2413

STIX ID: report--cae58834-85d7-561e-9446-850fffac2413

Feed Name: Censys Blog

Threat Score
25/100

Date Published: 2019-02-06

Date Updated: 2026-04-27

...
...

This advisory explains how defenders can proactively detect and disrupt phishing/BEC campaigns by discovering adversary pre-attack infrastructure—primarily typo-squatted domains and fake TLS certificates—using tools like DNS Twist to generate domain permutations and Censys to search certificate transparency logs; it includes examples (Anthem, Binance) and recommends takedowns and blocking to prevent attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.