Member-only story
Monitoring Threat Actors Cobalt Strike C2 Infrastructure with Shodan
3 min readSep 21, 2021
Threat Intel Tips and Shodan queries
ReliableSite, Leaseweb, ITL-Bulgaria, and HostKey Infrastructure are good examples but you can also look for and monitor other ISP’s/orgs.
ReliableSite
org:”ReliableSite.Net LLC” port:”443" HTTP/1.1 404 Not Found Content-Length: 0
examples:


Leaseweb
isp:”Leaseweb” port:”443" HTTP/1.1 404 Not Found Content-Length: 0 org:”Leaseweb USA, Inc.”
examples: