Botnet C2 servers
—
tracked, last 30 days · — online
Who gets onto the network, how they prove it, and what policy they land in.
A revoked certificate got full access, a certificate with no clientAuth was accepted, and a dead OCSP responder went unnoticed. All measured on ISE 3.5 with openssl, eapol_test and radclient, and no network hardware at all.
We built an 802.1X and MAB policy on ISE 3.5 API-first and measured where the API stops. More of it is reachable than we expected, and the gaps are not where the documentation suggests.
Live from BlueCore's lab threat-intel service. Indicators are defanged.
—
tracked, last 30 days · — online
—
reported, last 24 h
—
currently listed
Exit nodes are not malicious by themselves; they are context for access decisions.
| IP | Family | Country | First seen |
|---|