Fuente:
Noticias ICEX
Lugar:
Threat Intelligence
Threat IntelligencePivot from an IP IoC to live host data in CensysCheck whether the host is still live, what it's running, and which other hosts share its certificatesDave Johnsonon Sep 17, 2026BLUFFeedly flags an IP in a threat report. Censys tells you about the host record, when the IP was last scanned, which ports and services answered, who owns the netblock, and which other hosts share its certificates. You can now pivot from one to the other in one click.Explore Feedly Threat IntelligenceThe gap: Open web reporting can lack valuable IP IoC contextFeedly consolidates open web reporting around a particular IoC in IoC Insights Cards: who reported it, what it's been linked to, which threat actors and malware families it connects to. But when you need context on a particular host, external analysis from Censys can describe the infrastructure right now.Open Censys straight from the IoC Insights CardsNow you can click Open in Censys directly from any IoC Insights Card and see where the host is, what services it's running, and other details that the open web reporting might have left out. You don’t need a Censys account to view the host lookup page.Opening Censys from Feedly's IoC Insights CardsAlso accessible via Threat Actor and Malware Insights CardsYou can also open Censys from the IoC table on Threat Actor and Malware Insights Cards, so you can pivot from a list of IoCs without opening each card.The IoC table in a Threat Actor Insights CardQuestions you can answer once in CensysIs the host still up?Censys rescans known services daily. If the infrastructure has been torn down, you know before you block it. If the IP has been reassigned to an unrelated tenant, you know before you generate false positives against someone innocent.What kind of host is it?View open ports, running services, TLS certificates, ASN, and hosting provider. A dedicated VPS running an exposed panel is a different decision from a shared cloud host where a block could cause collateral damage.Which other hosts share its certificates?Adversaries build infrastructure in batches, reusing certificates, service combinations, and fingerprints. Pivot on any of those and you get the rest of the set, not just the host in the report.Who owns it, and where does it sit?The Network and Routing panel gives Autonomous System, Organization, Routing Prefix and WHOIS Network, with the geolocation map beside it.What is it running, and is anything exposed?The Summary panel's service chips give you the shape immediately, then the Services tab has the detail and the CVEs tab carries a count badge. Censys shares software "including name, version, and vendor, often in the Common Platform Enumeration (CPE) format," with CVSS scores and KEV catalog membership where CVEs are present.See how else Feedly can help CTI teamsFeedly Threat Intelligence is the fastest way for CTI teams to track threats, contextualize what matters, and delivered tailored briefings in minutes.Explore Feedly Threat Intelligence