Indicator investigation workbench for security analysts

Paste a suspicious IP, hostname, or certificate and get one profile page with Censys detail, VirusTotal reputation, history, and one-click Jira escalation.

App
CensysVirusTotalJiraEngineeringOperationsResearch & Monitoring
PromptCreate

I want an indicator investigation workbench that my security analysts open whenever an alert hands them something to chase. The app is anchored on one indicator at a time. At the top there is an input where I paste an IP address, a hostname and port, or a certificate SHA-256 fingerprint. The app detects which kind of indicator it is and loads a single profile page for it, so nobody has to flip between six browser tabs.

Profile tab. This is the default view and it combines infrastructure detail with reputation. For an IP address, load the host record with the Censys Get a Host operation and layer on Censys Get Host Enrichment, then show the VirusTotal Get an IP Address Report result beside it. For a hostname and port, use Censys Get a Web Property, and pair it with the VirusTotal Get a Domain Report for the hostname part. For a certificate fingerprint, use Censys Get a Certificate. Surface the things an analyst reads first: open services and ports, network owner and ASN, hosting location, certificate subject and issuer and validity dates, and the VirusTotal detection counts with the engines that flagged it. Note the identifier formats, because they are not obvious: a Censys host ID is the IP address itself, a web property ID is hostname:port, and a certificate ID is the SHA-256 fingerprint.

Timeline tab. This exists to answer when this service actually appeared and which names resolved to it. Use Censys Get Host Event History for the host timeline, Censys Get Service History for a Host to show the time ranges each service was observed on the host, and Censys Get DNS Resolution Records for a Name (Bounds) to show the observed DNS records for a name. Render it chronologically with clear first-seen and last-seen markers so an analyst can tell new infrastructure from long-standing infrastructure at a glance.

Pivot panel. This is the heart of the app. Run CenQL queries through the Censys Run a Search Query operation to surface related infrastructure that shares the same certificate fingerprint, the same ASN, or the same service banner as the current indicator. Offer those three as one-click pivot buttons so the analyst does not have to write query syntax by hand, and let them edit the query if they want. Every result row is clickable, and clicking it re-anchors the entire investigation on that new indicator, reloading the profile and timeline tabs around it. Keep a visible breadcrumb trail of the pivot path so the analyst can see how they got to the current indicator and can walk back.

Escalation. When something is worth escalating, one button files a Jira issue using the Jira Create Issue operation, prefilled with the indicator as the summary and a description assembled from the evidence gathered so far: the key profile facts, the VirusTotal verdict, notable timeline events, and the pivot path that led here. Let the analyst pick the project and issue type and edit the prefilled text before submitting. After the issue is created, show the issue key and a link to it, and record on the investigation that it was escalated.

Per-user history. Keep a history of recent investigations and pivots for each user so an analyst can resume where they left off. Show it as a sidebar list of recent indicators with timestamps and the indicator type, and clicking one reopens that investigation. This history is scoped per user and is not shared across the team.

Degrade gracefully for free-tier accounts. Censys requires an Organization ID for host enrichment, service history, and DNS resolution. If the connected Censys account does not have one, the app must still work: keep the host, web property, certificate, and search panels plus all VirusTotal reputation working, and show a clear inline note on the affected panels explaining that they need an Organization ID, rather than erroring out or showing a blank screen. Censys and VirusTotal are read-only here, so nothing in this app writes back to them. The Jira issue is the only thing the app ever creates.

What does this prompt do?

  • Paste an IP address, a hostname and port, or a certificate fingerprint and get a single profile page for it, instead of flipping between six browser tabs.
  • Shows what the thing is next to whether it is already known to be bad, combining infrastructure detail from Censys with reputation scores from VirusTotal on one screen.
  • A timeline view answers the questions that actually matter during triage: when did this service first appear, and which names have resolved to it.
  • A pivot panel surfaces related infrastructure sharing the same certificate, network owner, or service fingerprint, and every result is clickable to re-anchor the investigation on that new lead.

What do I need to use this?

  • A Censys account with a personal access token
  • A VirusTotal account (a free key works, with lower daily limits)
  • A Jira project where escalations should be filed
  • Optional but recommended: your Censys Organization ID, which unlocks the enrichment and timeline views

How can I customize it?

  • Choose which Jira project and issue type escalations land in, and what the prefilled summary and description include
  • Reorder the pivot panel to lead with certificate matches, network owner, or service fingerprint depending on how your team investigates
  • Set how many recent investigations each analyst keeps in their history sidebar

FAQs

What can I paste into the search bar?
Three kinds of indicator: an IP address, a hostname with its port, or a certificate fingerprint. The app works out which one you gave it and loads the right profile automatically.
Do I need a paid Censys plan?
No, but some panels need more than a free account. Censys requires an Organization ID for the enrichment and timeline views, so if your account does not have one the app still shows the host, certificate, web property, search, and reputation panels, and simply notes which panels are unavailable rather than failing.
Does this work with a free VirusTotal key?
Yes. The free tier allows a limited number of lookups per minute and per day, which is usually fine for one analyst working through alerts. Busy teams tend to upgrade for higher limits.
Will this change anything in Censys or VirusTotal?
No. Both are used purely for lookups and nothing is written back to them. The only thing the app creates anywhere is the Jira issue you file when you decide something is worth escalating.
Can several analysts use it at the same time?
Yes. Each analyst gets their own private history of recent investigations and pivots, so you can pick up exactly where you left off without seeing or disturbing anyone else's work.

Related templates

Work your whole Terraform approval queue from one board

Every Terraform run that needs a human, across every workspace, on one board with approve, discard, and plain English plan summaries.

HCP Terraform (Terraform Cloud)
Jira
App
Internet scanning campaign explorer for security teams

Browse the mass-scanning campaigns running on the internet right now and see instantly whether any of them target software you actually run.

GreyNoise
Google Sheets
Jira
App
Bulk IP triage queue that clears your SIEM alert backlog

Paste a few hundred alert IPs, split them into scanner noise, safe business services, and real suspects, then suppress or escalate in one pass.

GreyNoise
Jira
App
Patch prioritization board built on live exploitation data

See which vulnerabilities attackers are actively exploiting, which already have tickets, and which dangerous gaps nobody on your team has logged yet.

GreyNoise
Jira
App
See every open Confluence action item on one board

Pull every unfinished task out of your meeting notes and project pages into one screen, sorted oldest first, and tick them off without leaving the board.

Confluence
Jira
Slack
App
Datadog alert noise cleanup board for monthly monitor review

Open one board each month to rank every monitor by how often it alerted, spot the noisy and unowned ones, and clean them up in place.

Datadog
Jira
App

Stop chasing one indicator across six browser tabs.

Give your analysts one screen that profiles an indicator, shows its history, finds related infrastructure, and escalates in a click.