Threat Actor Infrastructure Tracking Report
Report Metadata
| Field |
Value |
| Report ID |
INFRA-YYYY-NNNN |
| Date |
YYYY-MM-DD |
| Classification |
TLP:AMBER |
| Analyst |
[Name] |
Infrastructure Summary
| Metric |
Count |
| C2 Servers Identified |
|
| Domains Tracked |
|
| SSL Certificates Found |
|
| ASNs Involved |
|
| Countries |
|
C2 Servers
| IP Address |
Ports |
Framework |
ASN |
Country |
First Seen |
Last Seen |
|
|
|
|
|
|
|
Associated Domains
| Domain |
Resolved IP |
First Seen |
Last Seen |
Source |
|
|
|
|
pDNS/CT/WHOIS |
SSL Certificates
| Common Name |
Issuer |
Not Before |
Not After |
SANs |
|
|
|
|
|
Pivot Map
Recommendations
- Block identified C2 IPs and domains at network perimeter
- Deploy JARM/JA3S signatures for C2 framework detection
- Monitor CT logs for new certificates matching tracked domains
- Set up passive DNS alerts for domain resolution changes