惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
小众软件
小众软件
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园_首页
博客园 - 司徒正美
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
C
Check Point Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Hugging Face - Blog
Hugging Face - Blog
B
Blog RSS Feed
阮一峰的网络日志
阮一峰的网络日志
D
DataBreaches.Net
The GitHub Blog
The GitHub Blog
G
Google Developers Blog
L
LangChain Blog
T
The Blog of Author Tim Ferriss
博客园 - 【当耐特】
Engineering at Meta
Engineering at Meta
Google DeepMind News
Google DeepMind News
雷峰网
雷峰网
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
I
InfoQ

New in Feedly

Automatically collect Splunk Hunting Queries that match your requirements | Feedly Continuously collect Suricata rules matching your requirements | Feedly Enrich and triage Atlassian security releases in the Vulnerability Intel Agent | Feedly Enrich and triage Apple security releases in the Vulnerability Intel Agent | Feedly Feedly completes SOC 2 Type 2 examination | Feedly VirusTotal Integration: Triage IOCs Faster in Feedly | Feedly Connect Feedly to OpenCTI: Real-Time Threat Intel, Automated | Feedly Feedly Best Practices for CTI Teams | Feedly GreyNoise + Feedly Threat Intelligence: Enriching IoCs | Feedly 7 AI Prompts for Cyberattack Pattern Analysis | Feedly Navigate Feedly Faster with Go To | Feedly Navigate Feedly Faster with Go To Introducing Feedly ThreatBeats: Your daily intel jingles | Feedly Introducing Feedly ThreatBeats: Your daily intel jingles 6 Ways to Automate Threat Intelligence with the Feedly API | Feedly Get threat intelligence to your team fast, in the tools they already use | Feedly Tracking the cyber consequences of geopolitical events | Feedly Analyze your closed-source intelligence in Feedly | Feedly Cyberattack Insights Cards: A dynamic 360° attack view | Feedly Cyberattack Insights Cards: A dynamic 360° attack view 7 ways to prioritize CVEs by how they're exploited | Feedly Ask AI on Threat Actor Insights Cards: Accelerate adversary research with custom queries | Feedly Research IoCs with rich context in seconds, not hours | Feedly Surface top threats in CTI newsletters | Feedly The Scanner: Exploring Potential Futures | Feedly The Radar: Detecting emerging signals | Feedly Prompt Engineering: Newsletter template for real-time phishing trends | Feedly The Monitor: Tracking the known present | Feedly Startup Innovation Radar: A real-time startup database | Feedly The InsightOS architecture | Feedly
Pivot from an IP IoC to live host data in Censys | Feedly
Dave Johnson · 2026-09-18 · via New in Feedly

BLUF

Feedly flags an IP in a threat report. Censys tells you about the host record, when the IP was last scanned, which ports and services answered, who owns the netblock, and which other hosts share its certificates. You can now pivot from one to the other in one click.

The gap: Open web reporting can lack valuable IP IoC context

Feedly consolidates open web reporting around a particular IoC in IoC Insights Cards: who reported it, what it's been linked to, which threat actors and malware families it connects to. But when you need context on a particular host, external analysis from Censys can describe the infrastructure right now.

Open Censys straight from the IoC Insights Cards

Now you can click Open in Censys directly from any IoC Insights Card and see where the host is, what services it's running, and other details that the open web reporting might have left out. You don’t need a Censys account to view the host lookup page.

Also accessible via Threat Actor and Malware Insights Cards

You can also open Censys from the IoC table on Threat Actor and Malware Insights Cards, so you can pivot from a list of IoCs without opening each card.

Questions you can answer once in Censys

Is the host still up?

Censys rescans known services daily. If the infrastructure has been torn down, you know before you block it. If the IP has been reassigned to an unrelated tenant, you know before you generate false positives against someone innocent.

What kind of host is it?

View open ports, running services, TLS certificates, ASN, and hosting provider. A dedicated VPS running an exposed panel is a different decision from a shared cloud host where a block could cause collateral damage.

Which other hosts share its certificates?

Adversaries build infrastructure in batches, reusing certificates, service combinations, and fingerprints. Pivot on any of those and you get the rest of the set, not just the host in the report.

Who owns it, and where does it sit?

The Network and Routing panel gives Autonomous System, Organization, Routing Prefix and WHOIS Network, with the geolocation map beside it.

What is it running, and is anything exposed?

The Summary panel's service chips give you the shape immediately, then the Services tab has the detail and the CVEs tab carries a count badge. Censys shares software "including name, version, and vendor, often in the Common Platform Enumeration (CPE) format," with CVSS scores and KEV catalog membership where CVEs are present.

See how else Feedly can help CTI teams

Feedly Threat Intelligence is the fastest way for CTI teams to track threats, contextualize what matters, and delivered tailored briefings in minutes.

Explore Feedly Threat Intelligence