Indicator investigation workbench for security analysts

By General Input

Paste a suspicious IP, hostname, or certificate and get one profile page with Censys detail, VirusTotal reputation, history, and one-click Jira escalation.

Integrations

  • Censys
  • VirusTotal
  • Jira

Type

App

Categories

  • Engineering
  • Operations

I want an indicator investigation workbench that my security analysts open whenever an alert hands them something to chase. The app is anchored on one indicator at a time. At the top there is an input where I paste an IP address, a hostname and port, or a certificate SHA-256 fingerprint. The app detects which kind of indicator it is and loads a single profile page for it, so nobody has to flip between six browser tabs.

Profile tab. This is the default view and it combines infrastructure detail with reputation. For an IP address, load the host record with the Censys Get a Host operation and layer on Censys Get Host Enrichment, then show the VirusTotal Get an IP Address Report result beside it. For a hostname and port, use Censys Get a Web Property, and pair it with the VirusTotal Get a Domain Report for the hostname part. For a certificate fingerprint, use Censys Get a Certificate. Surface the things an analyst reads first: open services and ports, network owner and ASN, hosting location, certificate subject and issuer and validity dates, and the VirusTotal detection counts with the engines that flagged it. Note the identifier formats, because they are not obvious: a Censys host ID is the IP address itself, a web property ID is hostname:port, and a certificate ID is the SHA-256 fingerprint.

Timeline tab. This exists to answer when this service actually appeared and which names resolved to it. Use Censys Get Host Event History for the host timeline, Censys Get Service History for a Host to show the time ranges each service was observed on the host, and Censys Get DNS Resolution Records for a Name (Bounds) to show the observed DNS records for a name. Render it chronologically with clear first-seen and last-seen markers so an analyst can tell new infrastructure from long-standing infrastructure at a glance.

Pivot panel. This is the heart of the app. Run CenQL queries through the Censys Run a Search Query operation to surface related infrastructure that shares the same certificate fingerprint, the same ASN, or the same service banner as the current indicator. Offer those three as one-click pivot buttons so the analyst does not have to write query syntax by hand, and let them edit the query if they want. Every result row is clickable, and clicking it re-anchors the entire investigation on that new indicator, reloading the profile and timeline tabs around it. Keep a visible breadcrumb trail of the pivot path so the analyst can see how they got to the current indicator and can walk back.

Escalation. When something is worth escalating, one button files a Jira issue using the Jira Create Issue operation, prefilled with the indicator as the summary and a description assembled from the evidence gathered so far: the key profile facts, the VirusTotal verdict, notable timeline events, and the pivot path that led here. Let the analyst pick the project and issue type and edit the prefilled text before submitting. After the issue is created, show the issue key and a link to it, and record on the investigation that it was escalated.

Per-user history. Keep a history of recent investigations and pivots for each user so an analyst can resume where they left off. Show it as a sidebar list of recent indicators with timestamps and the indicator type, and clicking one reopens that investigation. This history is scoped per user and is not shared across the team.

Degrade gracefully for free-tier accounts. Censys requires an Organization ID for host enrichment, service history, and DNS resolution. If the connected Censys account does not have one, the app must still work: keep the host, web property, certificate, and search panels plus all VirusTotal reputation working, and show a clear inline note on the affected panels explaining that they need an Organization ID, rather than erroring out or showing a blank screen. Censys and VirusTotal are read-only here, so nothing in this app writes back to them. The Jira issue is the only thing the app ever creates.

Related prompts

Explore more prompts
One triage console for every Jira service desk queueWork your whole Terraform approval queue from one boardInternet scanning campaign explorer for security teamsBulk IP triage queue that clears your SIEM alert backlogPatch prioritization board built on live exploitation dataSee every open Confluence action item on one boardDatadog alert noise cleanup board for monthly monitor reviewAttack surface inventory board your team triages each morningVendor security review board built on your vendor sheetSee which sprint tickets actually have code behind them