Skip to content
Cybersecurity

How Internet Intelligence Helps Investigate Cyber Attacks

/ 10 min read / Malik Tanveer Dhool

Every cyber attack leaves infrastructure clues on the public internet. This guide explains how investigators pivot from one malicious indicator to an entire attacker network — and why attribution must never rest on a single clue.

← Back to Blog
Share X in

WarBrief Live | October 6, 2026 | Cyber Intelligence

When a cyber attack is discovered, the immediate questions are the hardest ones: who did this, how far did they get, and are they still inside the network? The answers often begin outside the victim’s network entirely, on the public internet. Every attack leaves infrastructure clues behind — IP addresses, domain names, digital certificates, hosting servers, and DNS records. Censys cyber attacks investigation work is built on this simple idea: because the internet is constantly scanned and cataloged, investigators can reconstruct what attackers built, how it was connected, and where it led.

Internet intelligence is the use of that public, internet-wide data to support investigations. It turns a single malicious indicator — one suspicious IP or domain — into a map of an attacker’s whole operation. This article explains how incident-response teams use it, what real investigations have looked like, and why attribution is never a job for one clue alone.

Key Takeaways

  • Cyber attacks leave public infrastructure traces — IPs, domains, TLS certificates, hosting patterns, and DNS records — that investigators can query across the entire internet.
  • Pivoting connects one known malicious indicator to related infrastructure, often revealing command-and-control networks before victims know they exist.
  • Real cases, from Citizen Lab’s Candiru spyware exposure to Censys’s botnet research, show how internet data feeds incident response and threat intelligence.
  • Attribution must combine many independent signals; actors reuse tools, plant false flags, and route through third-party infrastructure to mislead analysts.

What clues does a cyber attack leave behind on the public internet?

To run an attack, criminals and spies need infrastructure. Command-and-control servers must be reachable online. Phishing pages need domains and hosting. Malware needs places to check in and send stolen data. All of this infrastructure sits on the public internet, where it can be scanned, cataloged, and studied — even by defenders.

The most useful clues are simple. An IP address tells you where a server lives and who hosts it. A domain name tells you what the server pretends to be. A TLS certificate — the digital ID used for encrypted connections — often contains fingerprints, issuer names, and subject names that are repeated across an attacker’s whole network. DNS records show which domains point to which servers, and hosting metadata shows the provider, the autonomous system number, and sometimes the country.

None of these clues is useful in isolation. A single malicious IP is just one dot. The investigation begins when analysts ask: what else shares this certificate? What else lives on this server? What else was registered the same way? That is where internet intelligence earns its name. For background on the scanning itself, see CensysInspect explained: what the internet scanner is and how it works and CensysInspect Explained: Internet Intelligence Guide.

How does infrastructure pivoting work in practice?

Pivoting is the core technique. An analyst starts with one known indicator — say, a malicious domain found in a victim’s logs — and queries an internet-wide dataset for everything that shares its attributes. The certificate on that domain may also be served by ten other IP addresses. Those IPs may host fifty other domains. Some of those domains may resolve to infrastructure nobody had flagged before. One clue becomes dozens.

The pivots that matter most are well documented. Shared IP addresses link domains and servers into the same operation. Unique strings in web server banners or HTML — a custom server header, an unusual tool name — can be searched across scan databases to find matching infrastructure. TLS certificate fields such as subject common names, serial numbers, and alternative names are especially powerful, because attackers often reuse certificates across their whole network. SSH key fingerprints, open port patterns, and even the same hosting provider combined with the same configuration can all serve as pivot points.

Historical scan data adds a time dimension. Attackers tear down infrastructure when an operation ends, but scan archives remember what the server looked like months or years ago. That lets investigators reconstruct a network after the fact — a critical capability when a breach is discovered long after the intrusion began.

AI-generated illustration

How Censys cyber attacks investigation powers incident response

When a response team finds a compromised machine, their first job is containment: find every attacker foothold, not just the one they tripped over. Internet intelligence accelerates this in three ways.

First, it expands the scope. A single malicious IP from a firewall log can be pivoted into a full infrastructure cluster, letting defenders hunt for related indicators across their whole estate before the attacker moves.

Second, it enriches threat intelligence. Raw indicators are more useful with context — when a domain was registered, what else the server hosts, how long the infrastructure has been active. Enrichment helps teams prioritize: infrastructure tied to a long-running espionage operation gets a different response than a lone compromised server.

Third, it supports hunting. Defenders can proactively search for servers that look like known attacker infrastructure — same certificate quirks, same port patterns, same hosting provider — and flag them before they are used. This proactive side of the work is closely related to tracking how adversary infrastructure evolves; see Tracking Adversary Infrastructure With Censys Data and Cyber Warfare Research: Using Internet Scan Data (2026) for more on research methods and infrastructure tracking.

What does a real investigation look like?

One of the clearest public examples comes from the Citizen Lab at the University of Toronto. In its July 2021 “Hooking Candiru” report, Citizen Lab used internet scanning to map the infrastructure of Candiru, an Israel-based company whose spyware was sold to governments and used against journalists, activists, and dissidents. Researchers identified more than 750 websites linked to Candiru’s spyware infrastructure — domains impersonating advocacy organizations such as Amnesty International and the Black Lives Matter movement, media companies, and country-specific targets.

The method was pure pivoting. The team found a self-signed certificate associated with Candiru’s domain, candirusecurity[.]com (known from a 2015 corporate filing), then queried internet scan data for the IP addresses serving that certificate — iterating back and forth between hosts and certificates until the full impersonation network surfaced. As Citizen Lab senior research fellow Bill Marczak put it in the Censys case study:

“Censys data was a critical part of the investigation because it helped us find the victim and recover the spyware sample.”

The same investigation also surfaced an IP address belonging to a spyware victim in Western Europe, and samples passed to Microsoft’s Threat Intelligence Center led to the discovery of two Windows vulnerabilities, CVE-2021-31979 and CVE-2021-33771 — patched in July 2021 — with Microsoft observing around 100 victims across multiple countries.

A more recent case shows the same technique applied to botnets. In early 2025, Sekoia researchers uncovered PolarEdge, an IoT botnet exploiting a command-injection flaw in Cisco Small Business routers. Investigators then used historical internet scan data to pivot from a single malware-delivery host, examining what services and certificates it had exposed at the time of the attack — a concrete example of how archived scan data lets defenders go back in time.

Researchers have also used certificate pivoting to unmask infrastructure hidden behind content-delivery networks. Group-IB’s October 2025 analysis of a MuddyWater espionage toolkit found a hardcoded command-and-control domain shielded by Cloudflare — but the server’s SSL certificate revealed the real IP address underneath. The vendor also documented cases such as the Vidar stealer, whose hardcoded certificate details led to 22 linked IP addresses, and a Russian ransomware operation using Metasploit and PoshC2, traced across countries with historical scan data (The Hacker News / Censys). Note that if CensysInspect scans are showing up in your own logs, that is a separate matter — see what CensysInspect in your logs means and how to respond.

AI-generated illustration

Why attribution must never rest on a single indicator

Finding infrastructure is only half the job. Naming the attacker — attribution — is where investigations get genuinely difficult, and where the strictest discipline applies.

Attackers actively work to mislead analysts. Malware and tooling are reused, stolen, sold, or deliberately copied from other groups, so a familiar tool does not prove a familiar actor. Operations are routed through compromised devices, rented servers, commercial VPNs, and cloud services in multiple countries, so geography alone reveals only where traffic passed through, not who directed it. Some actors plant false flags on purpose — mimicking another group’s techniques or leaving misleading language artifacts — and proxy actors, from contractors to aligned criminal groups, blur the line between state-directed and merely state-tolerated activity.

That is why serious investigations treat every technical indicator as one piece of evidence, never a conclusion. Forensic analysts describe it plainly: investigations that rely on one or two isolated indicators are the ones that trip up, while thorough, multi-source forensics usually expose the deception.

The discipline shows in practice. In late September 2026, Mandiant’s threat intelligence team reported on the mass exploitation of Citrix NetScaler zero-day vulnerabilities, with dozens of organizations affected across North America and Europe. The tooling was new and the targeting looked deliberate — yet the report attributed the activity only to “suspected state-sponsored” actors, naming no group (SecurityWeek). That restraint is the standard: credible attribution layers independent signals — infrastructure overlaps, tooling, victim targeting, operational habits, geopolitical context — and uses careful language like “suspected” until the evidence supports more.

For analysts, the rule is simple. Internet intelligence can prove that two servers belong to the same operation. It cannot, by itself, prove who operates them. Confidence comes from convergence: multiple independent lines of evidence pointing the same way. A single indicator, no matter how interesting, is never enough — and the analysts who remember that are the ones whose attribution holds up.

Comparing platforms is part of doing this work well: different scanners surface different data, so investigators often cross-check findings. See Censys vs Shodan for Threat Hunting Teams Compared (2026) for how the two leading internet scanners compare for threat hunting, and the Censys internet-wide scan data overview for the dataset behind these techniques.

Frequently asked questions

What is internet intelligence in cyber attack investigations?
Internet intelligence is the use of public, internet-wide scan data — IP addresses, domains, certificates, hosting records, DNS — to investigate attacks. It helps incident-response teams map attacker infrastructure, find related indicators, and understand an operation’s scope beyond the victim’s network.

How does infrastructure pivoting help find attackers?
Pivoting starts from one known malicious indicator and searches for everything sharing its attributes: the same TLS certificate on other servers, other domains on the same IP, matching SSH fingerprints or port patterns. Each pivot can reveal previously unknown attacker infrastructure.

Can internet scan data reveal who hacked an organization?
Only partially. Scan data can show that infrastructure belongs to one operation, but naming the attacker requires many independent signals — tooling, targeting, habits, context. Attribution should never rest on a single technical indicator, because actors reuse tools, plant false flags, and route through third-party infrastructure.

What are real examples of investigations using internet intelligence?
Citizen Lab used certificate pivoting to map over 750 spyware-impersonation websites in its 2021 Candiru investigation; researchers have tracked the Vidar stealer and Russian ransomware C2 networks the same way; and historical scan data helped analyze the PolarEdge botnet in 2025. Censys formalized its research arm, the Advanced Research Collective (ARC), in March 2026.

Conclusion

Internet intelligence has changed how cyber attacks are investigated. A single malicious indicator, fed into an internet-wide dataset, can unfold into a map of an entire operation — its servers, its certificates, its history. Real investigations, from Candiru’s spyware network to modern botnets and espionage toolkits, show the method working in practice: pivot carefully, enrich thoroughly, hunt proactively.

But the same cases carry a warning. The internet remembers infrastructure; it does not name operators. Attribution is a separate discipline, built on converging evidence and disciplined language. For incident-response teams, the lesson is balance: use internet intelligence to find everything the attacker built, and use analytic rigor before saying who built it.

Sources and Further Reading

  • Citizen Lab, “Hooking Candiru: Another Mercenary Spyware Vendor Comes into Focus” (July 2021) — citizenlab.ca
  • Censys case study, “How Censys Helped Citizen Lab Expose Mercenary Spyware Vendor Candiru” — censys.com
  • Censys / The Hacker News, “7 Resources to Inform Your Next Hunt for Malicious Infrastructure” (July 2024) — thehackernews.com
  • SecurityWeek, “Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks” (September 2026) — securityweek.com
  • Cyber Security News, “MuddyWater Using New Malware Toolkit to Deliver Phoenix Backdoor Malware” (October 2025) — cybersecuritynews.com
  • Censys, 2025 State of the Internet Report (PolarEdge botnet spotlight; pivoting on host 119.8.186[.]227 via historical scan data)
  • PR Newswire / Morningstar, “Censys Unveils Censys ARC, Formalizing Its Global Internet Threat Research Team” (March 10, 2026) — morningstar.com

Written by

Malik Tanveer Dhool

Defense and intelligence analysis for WarBrief.live. Covering conflict, technology, and geopolitical strategy.