October 20, 2025

Summary

Platform

  • Some threat data for hosts and web properties is now viewable by all users on Enterprise accounts.

    An example search result for a host showing that an AsyncRAT threat is present.

    • The following fields can be seen in the Platform web console and retrieved via API, but may not be searched for or pivoted across unless you also have access to the Threat Hunting module.

      Data fieldDescription
      *.threats.idA unique identifier for the threat.
      *.threats.nameName of the threat, such as Cobalt Strike.
      *.threats.tacticHow the threat behaves and the purpose of the activity, such as COMMAND_AND_CONTROL and PERSISTENCE.
      *.threats.typeThe role of the service, such as PHISHING_SERVER and WEBSHELL.

Rapid Response

The Censys Rapid Response team published information about and queries for the following issue.

New fingerprints

Added the following fingerprint.

TypeNameDescriptionQuery
softwareInteractsh ServerThis is an Interactsh server. Interactsh is an OOB interaction gathering server and client library.Platform query