












Feedly flags an IP in a threat report. Censys tells you about the host record, when the IP was last scanned, which ports and services answered, who owns the netblock, and which other hosts share its certificates. You can now pivot from one to the other in one click.
Feedly consolidates open web reporting around a particular IoC in IoC Insights Cards: who reported it, what it's been linked to, which threat actors and malware families it connects to. But when you need context on a particular host, external analysis from Censys can describe the infrastructure right now.
Now you can click Open in Censys directly from any IoC Insights Card and see where the host is, what services it's running, and other details that the open web reporting might have left out. You don’t need a Censys account to view the host lookup page.
You can also open Censys from the IoC table on Threat Actor and Malware Insights Cards, so you can pivot from a list of IoCs without opening each card.
Censys rescans known services daily. If the infrastructure has been torn down, you know before you block it. If the IP has been reassigned to an unrelated tenant, you know before you generate false positives against someone innocent.
View open ports, running services, TLS certificates, ASN, and hosting provider. A dedicated VPS running an exposed panel is a different decision from a shared cloud host where a block could cause collateral damage.
Adversaries build infrastructure in batches, reusing certificates, service combinations, and fingerprints. Pivot on any of those and you get the rest of the set, not just the host in the report.
The Network and Routing panel gives Autonomous System, Organization, Routing Prefix and WHOIS Network, with the geolocation map beside it.
The Summary panel's service chips give you the shape immediately, then the Services tab has the detail and the CVEs tab carries a count badge. Censys shares software "including name, version, and vendor, often in the Common Platform Enumeration (CPE) format," with CVSS scores and KEV catalog membership where CVEs are present.
Feedly Threat Intelligence is the fastest way for CTI teams to track threats, contextualize what matters, and delivered tailored briefings in minutes.

此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。