The 4 Step Guide to Exploring Attacker Infrastructure with Web Assets
ID: 84ed99d3-6e7f-5864-b51f-455b46a9a3df
STIX ID: report--84ed99d3-6e7f-5864-b51f-455b46a9a3df
Feed Name: DomainTools
This article explains a technique for enumerating attacker infrastructure by fingerprinting web assets (JavaScript/CSS/image paths) embedded in HTML. The author demonstrates pivoting from a malicious site using a unique asset path, leveraging Iris/DomainTools to surface related domains (for example, linking domains via shared SOA email), and advises building allowlists and examining code-level artifacts to improve confidence and reduce false positives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
