Censys has enhanced its Internet Map by integrating real-time Domain Name System (DNS) data, allowing security teams to connect domain names directly to the underlying internet infrastructure. This development aims to streamline security workflows by consolidating information previously scattered across multiple datasets and interfaces into a single platform.
The expanded Censys Internet Map now presents a unified view that links domains, DNS records, IP addresses, hosts, services, and digital certificates. This integration enables security analysts to understand the names associated with internet infrastructure and to move fluidly between name-based and IP-based perspectives. The platform also provides historical context, showing how infrastructure has evolved over time.
According to Censys, this unified approach supports various stages of the security operations workflow. During triage, analysts can quickly validate suspicious domains by examining the associated internet infrastructure, aiding in decisions about escalating threats. For investigations, the ability to pivot between domains, IPs, hosts, services, certificates, and historical relationships helps in understanding the full scope of an incident. Threat hunting is enhanced by the capacity to start with a single indicator and uncover the broader adversary infrastructure, effectively mapping an attacker's footprint. For defense, the feature allows for the identification of campaign infrastructure behind threats, enabling proactive strengthening of defenses.
Censys customers are reportedly using these new DNS capabilities to identify and disrupt phishing campaigns at the infrastructure level. One example cited involved the investigation of a phishing campaign impersonating the United States Postal Service (USPS). By analyzing a single malicious domain, security teams were able to uncover hundreds of related phishing domains and the broader campaign infrastructure. This included historical DNS relationships that are no longer visible through live DNS queries, allowing defenders to understand and counter the entire campaign rather than individual threats.
Raj Sivasankar, Senior Director of Product Management at Censys, stated that security teams often rely on fragmented external intelligence from various tools. He explained that by incorporating DNS data into the Censys Internet Map, the company is providing a unified platform for understanding the internet infrastructure behind threats. This, he added, equips defenders with the intelligence necessary to make more informed security decisions and to uncover larger adversary campaigns, especially as attacks become more automated.






