sk Skill · mukul975
tracking-threat-actor-infrastructure
Discovers and maps adversary-controlled infrastructure (C2 servers, phishing domains, exploit-kit hosts, bulletproof hosting) by pivoting across passive DNS, certificate transparency logs, Shodan/Censys scans, WHOIS records, and network fingerprints (JARM/JA3S). Use when tracking threat actor infrastructure, expanding a known IOC into related assets, or producing STIX-based threat intelligence during a CTI…
Open on skills.sh ↗read 2026-09-17
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 2
- Connections
- 0
pythonpassive-dnscensysstixinfrastructure-trackingmitre-attackPythonshodaniocctithreat-intelligence
- Host repository
- mukul975/Anthropic-Cybersecurity-Skills
- Version
- 1.0
- Licence
- Apache-2.0
- Host stars
- 33k
- Host language
- Python