Skip to content
P
非影
top
latest
vulnerabilities
research
tools
Topics
sources
search
search
🌓
中文
Curated security research, vulnerabilities, advisories and tools for practitioners.
Let's go Hunting
hunt.io
| blog |
#threat-hunting
|
#c2
|
#launch
|
#product
|
#open-directories
Summary
The launch of Hunt.io: a threat-hunting platform with feeds of active C2 servers across 125+ malware families, open-directory counterintelligence and malicious-infrastructure data.
Published
2023-08-01 00:00
Collected
2026-08-10 10:25
original ↗
← Previous
Transparency of Attacker Tooling
Next →
CVE-2026-24294: Windows SMB local NTLM reflection privilege-escalation PoC
Related coverage
blog
·
hunt.io
Introducing the Hunt.io C2 Feed
Hunt announces its C2 Feed, covering how the team identifies and tracks malicious command-and-control servers and packages this intelligence to help defenders block adversary infrastructure.
blog
·
hunt.io
Transparency of Attacker Tooling
How open directories aid threat hunting and incident response: exposed C2 executables, configs, bash history and RAT logs can reveal victims; Hunt automates finding and pivoting on them.
blog
·
hunt.io
Legacy Threat: PlugX Builder/Controller Discovered in Open Directory
Hunt discovered an exposed Czech server hosting an outdated PlugX builder and controller, with victim logs and a VBA script abusing a Nepalese government domain; Nepal's CERT was notified.
blog
·
hunt.io
In Plain Sight: Uncovering SuperShell & Cobalt Strike from an Open Directory
While hunting IOX copies, Hunt found an open directory holding two SuperShell/GOREVERSE payloads and a Linux ELF Cobalt Strike beacon, and shows how /supershell/login panels can be tracked.
blog
·
hunt.io
How We Identify Malicious Infrastructure At Hunt.io
Hunt explains how it identifies, tracks and 'burns' malicious C2 servers using TLS certificates, HTTP headers, SSH keys, JARM/JA4x hashes and TCP banners, seen in Gh0st and ShadowPad cases.
blog
·
netlas.io
How we hunt C2 infrastructure at RST Cloud using Netlas
How RST Cloud hunts C2 infrastructure with Netlas: a seven-step loop from goals and samples to fingerprints (JARM, certificates, HTTP headers), scheduled searches and multi-criteria validation.
back