Introducing Censys IOC Investigator: Run Every Lead Like You’ve Got Hours Censys launched Censys IOC Investigator in open beta, an AI-powered threat investigation feature that automates pivoting, infrastructure mapping, and host profiling across its internet-wide intelligence. The tool, built on Censys' Internet Map, parses raw input, clusters and pivots, and returns ranked, evidence-backed findings with confidence scores. It originated from Censys ARC's internal research processes, and uses large language models for orchestration while keeping verdicts deterministic. Today we’re launching Censys IOC Investigator in open beta: an AI-powered threat investigation feature that automates pivoting, infrastructure mapping, and host profiling. Give it a network observable single, bulk list, or intel report , and it runs the investigation in parallel across Censys’ internet-wide intelligence, then returns ranked, evidence-backed findings. The key here: it operates on top of Censys’ Internet Map https://censys.com/internet-map/ . Much like a member of Censys ARC https://censys.com/censys-arc/ , our research arm. And no surprise: this didn’t start as a product It started as the way ARC parallelizes and scales investigations across the vast Internet. Our researchers have spent years turning adversary tracking, threat hunting, fingerprinting, and detection engineering into repeatable, parallelized processes. Expanding threat definitions, mapping infrastructure, and writing rules that survive after the hostnames rotate. IOC Investigator brings this process to our users . In this blog, we’ll detail Give it an indicator, a list, or an intel report, and it runs the pivots, history checks, and host profiling a seasoned analyst would — in parallel — and hands back ranked findings with the evidence attached. From Humble Beginnings None of this began on a roadmap. It began with ARC researchers running their own tooling on their own hardware to find the things no feed had labeled yet. Principal Security Researcher Andrew Northern, for example, would analyze initial-access operators and dynamic web-delivered malware – and build a technique-based approach to hunting that pivots on how a campaign behaves rather than the indicators it burns. In one investigation https://censys.com/blog/technique-based-approach-hunting-web-delivered-malware/ , that method narrowed the entire web down to 42 actionable results on a live ClickFix campaign delivering XWorm through the PhantomVAI loader. Then he’d build that reasoning and those skills into our internal predecessor of this tool. Techniques like this are exactly what powers it today. See Censys IOC Investigator in Action Feed IOC Investigator a single indicator, a bulk list, or a raw intel report. It decides what needs checking, then works history, related infrastructure, and host profiling in parallel instead of one pivot at a time. It correlates the results, ranks what matters, and returns a short list of findings — each one carrying its source, the query that produced it, and a confidence score. Let’s see it in action, with a report from Jumpsec on a DPRK BlueNoroff ClickFix Kit. https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/ This kit uses a fake Zoom invite, but the only thing on the other line is malware Step 1 – It parses raw input, our massive copy-pasted IOC list. Step 2 – Cluster, pivot, provide an intel report with evidence and queries. Step 3 – Visualization of clustering evidence within said report. Step 4 – Behavioral analysis and confidence breakdown. Fin. The pipeline stays deterministic wherever possible. Large language models handle orchestration and decomposition, not the verdict, because in security trust is earned through determinism, not fluency. What you get back is a full package: an investigation log, a saved query ready to become a collection, links to the platform, and a written report with a relationship diagram and explicit notes on where the evidence is thin. Hours of manual pivoting collapse into minutes, with the paper trail already built . Recall: this operates on top of Censys’ Internet Map . Unprecedented in speed and scope. Spanning hundreds of protocols. Years of history. Active DNS resolution https://docs.censys.com/docs/platform-active-dns in the millions per second. The biggest cert database on earth. Raw scan and finished threat intel alike. AI-based workflows excel only when fed context that is expansive, correct, and current. What Censys ARC Has Already Found With It The proof is in what ARC has already surfaced this way. Recent investigation: USPS package smishing You’ve probably received one of these USPS smishing texts https://censys.com/blog/following-a-usps-smishing-kit-through-censys-dns-data/ . Starting from one lure hostname, Censys DNS history turned a single host into the whole operation: a domain factory running hundreds of disposable lookalikes. 682 unique hostnames across the confirmed cluster, fronting a real-time skimming kit that serves USPS’s genuine production pages as its own bait, down to firing USPS’s own analytics tag . Pivoting on the kit’s HTTP banner hash then jumped the investigation onto a sibling UPS campaign run by the same operator on a different backend. The hostnames and IPs rotate weekly; the structural signals — asset paths, the operator’s own cookie theme name, the banner hash, and the DNS history — do not. This is the durable, evidence-backed conclusion IOC Investigator is built to reach. Recent investigation: AsyncRAT forks into dozens of variants Or Take AsyncRAT, the open-source Windows remote access trojan forked repeatedly into a messy family tree https://censys.com/blog/asyncrat-family-threat-overview/ . ARC mapped roughly 40 named variants and confirmed live command-and-control for 13 of them, and identified the family’s central weakness: forks inherit their parent’s TLS certificate structure and rarely change it. A single certificate pattern carried down from DCRAT identifies the malware across the entire tree, regardless of which variant is deployed. A lineage-wide signature, the perfect pivot. Correlation like that, across a sprawling family tree, is precisely the parallel, evidence-first work the product automates. The Bottom Line Every vendor will have an AI investigator this year. The difference is what it runs on, and whether you can trust what it hands back. IOC Investigator pairs Censys’s first-party Internet intelligence with a deterministic pipeline and ARC-backed intuition, so the output is an evidence package an analyst can act on. It opens in open beta on August 10 following Black Hat USA 2026 . Any organization on the Adversary Investigation plan can enable it from org admin, no credits charged during the beta, three concurrent investigations per user, with GA targeted for September 30 . If you’re at Black Hat, come watch it run against a live indicator at the booth. If you want to take it for a spin, contact us https://censys.com/request-a-demo/ and check out what else Censys Platform can do https://censys.com/product/adversary-investigation/ .