What it does. Discovers and maps adversary-controlled infrastructure (C2 servers, Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill tracking-threat-actor-infrastructure, or copy the skill folder into ~/.claude/skills/tracking-threat-actor-infrastructure/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/tracking-threat-actor-infrastructure/SKILL.md
SKILL.md (verbatim)
name: tracking-threat-actor-infrastructure
description: Discovers and maps adversary-controlled infrastructure (C2 servers,
phishing domains, exploit-kit hosts, bulletproof hosting) by pivoting across passive
DNS, certificate transparency logs, Shodan/Censys scans, WHOIS records, and network
fingerprints (JARM/JA3S). Use when tracking threat actor infrastructure, expanding
a known IOC into related assets, or producing STIX-based threat intelligence during
a CTI investigation.
domain: cybersecurity
subdomain: threat-intelligence
tags:
- threat-intelligence
- cti
- ioc
- mitre-attack
- stix
- infrastructure-tracking
- shodan
- censys
- passive-dns
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- ID.RA-01
- ID.RA-05
- DE.CM-01
- DE.AE-02
mitre_attack:
- T1591
- T1592
- T1593
- T1589
- T1566
mitre_f3:
version: '1.1'
tactics:
- reconnaissance
- resource-development
techniques:
- id: T1593
name: Search Open Websites/Domains
tactic: reconnaissance
source: attack
- id: T1583.001
name: 'Acquire Infrastructure: Domains'
tactic: resource-development
source: attack
- id: T1583.008
name: 'Acquire Infrastructure: Malvertising'
tactic: resource-development
source: attack
- id: T1583.003
name: 'Acquire Infrastructure: Virtual Private Network or Server'
tactic: resource-development
source: attack
- id: F1020.002
name: 'Create Fake Materials: Fake Website'
tactic: resource-development
source: f3
- id: T1608.006
name: 'Stage Capabilities: SEO Poisoning'
tactic: resource-development
source: attack
Tracking Threat Actor Infrastructure
Overview
Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, and staging servers. This skill covers using passive DNS, certificate transparency logs, Shodan/Censys scanning, WHOIS analysis, and network fingerprinting to discover, track, and pivot across threat actor infrastructure over time.
When to Use
- When managing security operations that require tracking threat actor infrastructure
- When improving security program maturity and operational processes
- When establishing standardized procedures for security team workflows
- When integrating threat intelligence or vulnerability data into operations
Prerequisites
- Python 3.9+ with
shodan, censys, requests, stix2 libraries
- API keys: Shodan, Censys, VirusTotal, SecurityTrails, PassiveTotal
- Understanding of DNS, TLS/SSL certificates, IP allocation, ASN structure
- Familiarity with passive DNS and certificate transparency concepts
- Access to domain registration (WHOIS) lookup services
Key Concepts
Infrastructure Pivoting
Pivoting is the technique of using one known indicator to discover related infrastructure. Starting from a known C2 IP address, analysts can pivot via: passive DNS (find domains), reverse WHOIS (find related registrations), SSL certificates (find shared certs), SSH key fingerprints, HTTP response fingerprints, JARM/JA3S hashes, and WHOIS registrant data.
Passive DNS
Passive DNS databases record DNS query/response data observed at recursive resolvers. This allows analysts to find historical domain-to-IP mappings, discover domains hosted on a known C2 IP, and identify fast-flux or domain generation algorithm (DGA) behavior.
Certificate Transparency
Certificate Transparency (CT) logs publicly record all SSL/TLS certificates issued by CAs. Monitoring CT logs reveals new certificates registered for suspicious domains, helping identify phishing sites and C2 infrastructure before they become active.
Network Fingerprinting
- JARM: Active TLS server fingerprint (hash of TLS handshake responses)
- JA3S: Passive TLS server fingerprint (hash of Server Hello)
- HTTP Headers: Server banners, custom headers, response patterns
- Favicon Hash: Hash of HTTP favicon for server identification
Workflow
Step 1: Shodan Infrastructure Discovery
import shodan
api = shodan.Shodan("YOUR_SHODAN_API_KEY")
def discover_infrastructure(ip_address):
"""Discover services and metadata for a target IP."""
try:
host = api.host(ip_address)
return {
"ip": host["ip_str"],
"org": host.get("org", ""),
"asn": host.get("asn", ""),
"isp": host.get("isp", ""),
"country": host.get("country_name", ""),
"city": host.get("city", ""),
"os": host.get("os"),
"ports": host.get("ports", []),
"vulns": host.get("vulns", []),
"hostnames": host.get("hostnames", []),
"domains": host.get("domains", []),
"tags": host.get("tags", []),
"services": [
{
"port": svc.get("port"),
"transport": svc.get("transport"),
"product": svc.get("product", ""),
"version": svc.get("version", ""),
"ssl_cert": svc.get("ssl", {}).get("cert", {}).get("subject", {}),
"jarm": svc.get("ssl", {}).get("jarm", ""),
}
for svc in host.get("data", [])
],
}
except shodan.APIError as e:
print(f"[-] Shodan error: {e}")
return None
def search_c2_framework(framework_name):
"""Search Shodan for known C2 framework signatures."""
c2_queries = {
"cobalt-strike": 'product:"Cobalt Strike Beacon"',
"metasploit": 'product:"Metasploit"',
"covenant": 'http.html:"Covenant" http.title:"Covenant"',
"sliver": 'ssl.cert.subject.cn:"multiplayer" ssl.cert.issuer.cn:"operators"',
"havoc": 'http.html_hash:-1472705893',
}
query = c2_queries.get(framework_name.lower(), framework_name)
results = api.search(query, limit=100)
hosts = []
for match in results.get("matches", []):
hosts.append({
"ip": match["ip_str"],
"port": match["port"],
"org": match.get("org", ""),
"country": match.get("location", {}).get("country_name", ""),
"asn": match.get("asn", ""),
"timestamp": match.get("timestamp", ""),
})
return hosts
Step 2: Passive DNS Pivoting
import requests
def passive_dns_lookup(indicator, api_key, indicator_type="ip"):
"""Query SecurityTrails for passive DNS records."""
base_url = "https://api.securitytrails.com/v1"
headers = {"APIKEY": api_key, "Accept": "application/json"}
if indicator_type == "ip":
url = f"{base_url}/search/list"
payload = {
"filter": {"ipv4": indicator}
}
resp = requests.post(url, json=payload, headers=headers, timeout=30)
else:
url = f"{base_url}/domain/{indicator}/subdomains"
resp = requests.get(url, headers=headers, timeout=30)
if resp.status_code == 200:
return resp.json()
return None
def query_passive_total(indicator, user, api_key):
"""Query PassiveTotal for passive DNS and WHOIS data."""
base_url = "https://api.passivetotal.org/v2"
auth = (user, api_key)
# Passive DNS
pdns_resp = requests.get(
f"{base_url}/dns/passive",
params={"query": indicator},
auth=auth,
timeout=30,
)
# WHOIS
whois_resp = requests.get(
f"{base_url}/whois",
params={"query": indicator},
auth=auth,
timeout=30,
)
results = {}
if pdns_resp.status_code == 200:
results["passive_dns"] = pdns_resp.json().get("results", [])
if whois_resp.status_code == 200:
results["whois"] = whois_resp.json()
return results
Step 3: Certificate Transparency Monitoring
import requests
def search_ct_logs(domain):
"""Search Certificate Transparency logs via crt.sh."""
resp = requests.get(
f"https://crt.sh/?q=%.{domain}&output=json",
timeout=30,
)
if resp.status_code == 200:
certs = resp.json()
unique_domains = set()
cert_info = []
for cert in certs:
name_value = cert.get("name_value", "")
for name in name_value.split("\n"):
unique_domains.add(name.strip())
cert_info.append({
"id": cert.get("id"),
"issuer": cert.get("issuer_name", ""),
"common_name": cert.get("common_name", ""),
"name_value": name_value,
"not_before": cert.get("not_before", ""),
"not_after": cert.get("not_after", ""),
"serial_number": cert.get("serial_number", ""),
})
return {
"domain": domain,
"total_certificates": len(certs),
"unique_domains": sorted(unique_domains),
"certificates": cert_info[:50],
}
return None
def monitor_new_certs(domains, interval_hours=1):
"""Monitor for newly issued certificates for a list of domains."""
from datetime import datetime, timedelta
cutoff = (datetime.utcnow() - timedelta(hours=interval_hours)).isoformat()
new_certs = []
for domain in domains:
result = search_ct_logs(domain)
if result:
for cert in result.get("certificates", []):
if cert.get("not_before", "") > cutoff:
new_certs.append({
"domain": domain,
"cert": cert,
})
return new_certs
Step 4: Infrastructure Correlation and Timeline
from datetime import datetime
def build_infrastructure_timeline(indicators):
"""Build a timeline of infrastructure changes."""
timeline = []
for ind in indicators:
if "passive_dns" in ind:
for record in ind["passive_dns"]:
timeline.append({
"timestamp": record.get("firstSeen", ""),
"event": "dns_resolution",
"source": record.get("resolve", ""),
"target": record.get("value", ""),
"record_type": record.get("recordType", ""),
})
if "certificates" in ind:
for cert in ind["certificates"]:
timeline.append({
"timestamp": cert.get("not_before", ""),
"event": "certificate_issued",
"domain": cert.get("common_name", ""),
"issuer": cert.get("issuer", ""),
})
timeline.sort(key=lambda x: x.get("timestamp", ""))
return timeline
Validation Criteria
- Shodan/Censys queries return infrastructure details for target IPs
- Passive DNS reveals historical domain-IP mappings
- Certificate transparency search finds associated domains
- Infrastructure pivoting discovers new related indicators
- Timeline shows infrastructure evolution over time
- Results are exportable as STIX 2.1 Infrastructure objects
References
Other files in this skill
assets/template.md (verbatim)
Threat Actor Infrastructure Tracking Report
| Field |
Value |
| Report ID |
INFRA-YYYY-NNNN |
| Date |
YYYY-MM-DD |
| Classification |
TLP:AMBER |
| Analyst |
[Name] |
Infrastructure Summary
| Metric |
Count |
| C2 Servers Identified |
|
| Domains Tracked |
|
| SSL Certificates Found |
|
| ASNs Involved |
|
| Countries |
|
C2 Servers
| IP Address |
Ports |
Framework |
ASN |
Country |
First Seen |
Last Seen |
|
|
|
|
|
|
|
Associated Domains
| Domain |
Resolved IP |
First Seen |
Last Seen |
Source |
|
|
|
|
pDNS/CT/WHOIS |
SSL Certificates
| Common Name |
Issuer |
Not Before |
Not After |
SANs |
|
|
|
|
|
Pivot Map
[Seed IP] --> [Domain A] --> [IP B] --> [Domain C]
| |
v v
[CT: Domain D] [WHOIS: Domain E]
Recommendations
- Block identified C2 IPs and domains at network perimeter
- Deploy JARM/JA3S signatures for C2 framework detection
- Monitor CT logs for new certificates matching tracked domains
- Set up passive DNS alerts for domain resolution changes
references/api-reference.md (verbatim)
API Reference: Tracking Threat Actor Infrastructure
Pivoting Techniques
| Technique |
Source |
Discovers |
| Passive DNS |
DNS resolvers |
Domains on same IP, historical mappings |
| Reverse WHOIS |
Registrar data |
Domains by same registrant |
| SSL Certificate |
CT logs, direct |
Shared certs, SANs, issuers |
| Shodan/Censys |
Internet scanning |
Open ports, services, banners |
| HTTP fingerprint |
Server responses |
Body hash, headers, favicon |
| JARM/JA3S |
TLS handshake |
C2 framework identification |
API Endpoints
| Service |
Endpoint |
Auth |
| Shodan Host |
GET /shodan/host/{ip}?key= |
API key |
| VirusTotal IP |
GET /api/v3/ip-addresses/{ip} |
x-apikey header |
| VirusTotal Domain |
GET /api/v3/domains/{domain} |
x-apikey header |
| SecurityTrails |
GET /v1/domain/{d}/subdomains |
APIKEY header |
| RDAP WHOIS |
GET https://rdap.org/domain/{d} |
None |
Network Fingerprinting
| Method |
Tool |
Description |
| JARM |
jarm.py |
Active TLS server fingerprint |
| JA3S |
Zeek/Wireshark |
Passive TLS Server Hello hash |
| Favicon hash |
Shodan http.favicon.hash |
mmh3 hash of favicon.ico |
| HTTP body hash |
SHA-256 |
Response body fingerprint |
| Server banner |
HTTP Server header |
Software identification |
Python Libraries
| Library |
Version |
Purpose |
requests |
>=2.28 |
API queries to Shodan/VT |
ssl |
stdlib |
TLS certificate retrieval |
socket |
stdlib |
DNS resolution, connections |
hashlib |
stdlib |
Certificate/content fingerprinting |
References
references/standards.md (verbatim)
Standards and Frameworks Reference
STIX 2.1 Infrastructure Object
{
"type": "infrastructure",
"name": "C2 Server",
"infrastructure_types": ["command-and-control"],
"description": "Cobalt Strike TeamServer at 198.51.100.1",
"first_seen": "2025-01-01T00:00:00Z",
"last_seen": "2025-06-01T00:00:00Z"
}
Diamond Model of Intrusion Analysis
- Adversary: Threat actor or group
- Capability: Tools, techniques, and malware
- Infrastructure: C2 servers, domains, hosting
- Victim: Targeted organization or individual
Infrastructure Types (STIX vocabulary)
- command-and-control, botnet, exfiltration, hosting-malware
- hosting-target-lists, phishing, staging, undefined
Network Fingerprinting Methods
| Method |
Type |
Description |
| JARM |
Active |
TLS server fingerprint from 10 TLS handshakes |
| JA3S |
Passive |
Server Hello hash from TLS negotiation |
| JA3 |
Passive |
Client Hello hash for client fingerprinting |
| Favicon Hash |
Active |
HTTP favicon file hash |
| HTTP Headers |
Active/Passive |
Server banner and header fingerprinting |
| SSH Key |
Active |
SSH host key fingerprint |
Passive DNS Record Types
- A/AAAA: Domain to IP mapping
- CNAME: Domain alias
- MX: Mail server records
- NS: Nameserver records
- TXT: Text records (SPF, DKIM, verification)
References
references/workflows.md (verbatim)
Infrastructure Tracking Workflows
Workflow 1: IP-Centric Pivoting
[Known C2 IP] --> [Shodan/Censys] --> [Service Fingerprints]
| |
v v
[Passive DNS] --> [Associated Domains] --> [WHOIS Analysis] --> [Registrant Pivot]
| |
v v
[SSL Certs] --> [Subject Alt Names] --> [New Domains] --> [Additional IPs]
Workflow 2: Domain-Centric Pivoting
[Known C2 Domain] --> [DNS History] --> [Historical IPs] --> [Co-hosted Domains]
| |
v v
[CT Logs] --> [Subdomains] --> [Infrastructure Map] --> [Shared Hosting Analysis]
|
v
[WHOIS] --> [Registrant/Email] --> [Other Registered Domains]
Workflow 3: C2 Framework Hunting
[C2 Signature] --> [Shodan Search] --> [Candidate Servers] --> [Validation]
|
v
[JARM Fingerprint]
|
v
[Confirm C2 Type]
|
v
[Track Over Time]
Workflow 4: Continuous Monitoring
[Watchlist IPs/Domains] --> [Scheduled Scans] --> [Change Detection] --> [Alerts]
|
+--------+--------+
| | |
v v v
[New Port] [DNS Change] [New Cert]
| | |
v v v
[Investigate] [Update TI] [Share]
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.