skip to content

Open-Source Tradecraft

Researching infrastructure an adversary still runs means they can see you looking: one resolved domain, WHOIS lookup or file submission can burn an investigation before containment is ready.

on this pageshow

explore

questions

4

When researching a suspected C2 domain, what is the difference between passive and active collection?

level: juniorimportance: must knowfreq 64%

answer

  1. who ends up seeing your query
  2. records somebody else already collected
  3. passive DNS, CT logs, WHOIS history
  4. resolving the name is already touching it
  5. his access log is your exposure

basics

~20 s

Passive collection reads records third parties already hold - passive DNS, certificate transparency, WHOIS history, stored scan data - so nothing reaches the adversary. Active collection resolves or connects to his host and writes a footprint into logs he controls.

solid answer

~50 s

Passive collection means asking somebody else what they already recorded: a passive DNS provider's historic name-to-address observations, certificate transparency entries for names on his certificates, registrar and WHOIS history, and a scanning service's stored banner records. None of that sends a packet to the adversary, so his logs stay empty. Active collection is anything that touches infrastructure he runs - resolving the name (the query lands on his authoritative nameserver), a TLS handshake, an HTTP request, a port scan, or asking a URL scanner to fetch the link, which makes a third party touch it on your behalf at a moment correlated with your discovery. The operating rule is: exhaust passive first, decide consciously before going active, and go active only from infrastructure that does not identify your organisation - never from the office network.

go deeper

for a junior

Be ready to name three passive sources and three active acts, and to say what each active act writes into the adversary's log. Knowing that resolving a name already counts as touching it is the point being tested.

for a middle

Explain the mechanics: which server actually receives your query in each case, what a passive DNS or certificate transparency record does and does not prove, and how tooling silently converts a passive intent into an active lookup.

for a senior

Show the decision rule. Say what the active step buys, what continued quiet observation is worth, and from what infrastructure you would touch the host at all - then be explicit that going active is a choice someone owns, not a reflex.

for a principal

Own the capability question: whether the team gets a non-attributable research path and a research tenant at all, what it costs, and what you forbid outright while it does not exist.

## The question behind the question When you find a domain or address you believe belongs to an intruder's command-and-control infrastructure, every step you take next either leaves a trace the operator can read or it does not. Tradecraft is the discipline of knowing which is which *before* you click, because the operator's response to being looked at is to rotate infrastructure, go quiet, or accelerate - and all three cost you more than the answer you were about to get. ## Passive: reading what somebody else already collected Passive sources are databases built by third parties from their own vantage points. Querying them reaches the provider, never the adversary. - **Passive DNS.** Sensors and recursive resolvers record the answers they observe and a provider aggregates them. A passive DNS record tells you that *some sensor observed this name resolving to this address at this time*. That is all it tells you. It does not prove the name resolves there now, and coverage is partial - an absence of records is not evidence the name was never used. - **Certificate transparency.** Publicly trusted certificate authorities log the certificates they issue to append-only public logs. A CT entry proves *a certificate containing that name was issued and logged*, not that any host serves it. Names on a shared certificate, an unusual issuance cadence, or a distinctive subject often reveal siblings of the host you started from. A self-signed certificate leaves no CT record at all, so absence proves nothing. - **Registrar and WHOIS history.** Registration and expiry dates, registrar, and nameserver changes over time. Most contact fields are redacted for privacy on many top-level domains, but historic snapshots and nameserver reuse are still strong pivots. - **Stored scan and banner data.** Internet-wide scanning services keep historic records of what a host answered with. Reading a stored record is passive; pressing that same service's *rescan* button is not - it fires a fresh scan at the host on your behalf. ## Active: anything that touches his infrastructure - **Resolving the name.** If the adversary runs the authoritative nameserver for the domain, a recursive lookup delivers a query to *his* server. He sees the resolver that asked, and some resolvers attach an EDNS Client Subnet field carrying a truncated prefix of the client's network. - **Connecting.** A TLS handshake, an HTTP request, a browser visit, a port probe - all of these write a source address, a timestamp and often a distinctive user agent into a log he owns. - **Submitting a URL to a scanner.** You did not touch it, but the service fetches it, and the fetch is timed to your discovery. If the link carried a per-victim token, the fetch also tells him which victim reported it. The trap is that plenty of tooling blurs the line: an intel platform's enrichment button may perform a live lookup, and a browser will helpfully resolve and prefetch a link you only meant to read. ## Why the operator's log is a real threat Corporate address space is attributable. Registry records map a netblock to an autonomous system and an organisation, so a single request from the office egress can tell a watchful operator *which company* is investigating him. A one-analyst team with no separate research egress and no research tenant has, in practice, only one non-attributable option: do not touch it. ## The decision rule 1. Exhaust passive sources and record what you found, including timestamps. 2. Ask what the active step would add that passive cannot give you. 3. Weigh that against the value of continuing to observe the infrastructure quietly. 4. If you still need it, go active from infrastructure that does not identify your organisation, and treat the visit as a decision with a named owner - not as a reflex. Going active is sometimes exactly right: once containment is imminent, or the intel need outweighs further observation, the burn is a price you choose to pay. What is never right is paying it by accident from a workstation.

  • Is a WHOIS lookup passive?
    The WHOIS or RDAP query itself goes to the registry or registrar, not to the adversary, so it is passive. The care needed is with tooling: many WHOIS wrappers also resolve the name, fetch the site, or offer a live-scan button, and any of those turns the same click into an active touch.
  • Does a passive DNS record tell you whether the domain resolves right now?
    No. It tells you that a sensor observed that resolution at some point, and coverage is partial. The record can be months stale, and the absence of a record only means no contributing sensor saw it. To know current state you must resolve it, which is an active step with a footprint.
  • When is going active the right call?
    When passive sources are exhausted, the answer materially changes a decision, and the value of continued quiet observation is already gone - typically because containment is imminent or the adversary knows he is discovered. Even then, do it from infrastructure that does not identify your organisation, and record that someone chose to accept the exposure.

Passive collection is reading the public land registry about a house. Active collection is walking up and trying the door - it answers a different question, and the person inside knows you were there.

saying these in an interview costs you the question

  • Thinks a passive DNS query reaches the adversary's nameserver
  • Calls a browser visit to the C2 host harmless because nothing was downloaded
  • Assumes every adversary TLS host appears in certificate transparency
  • Treats an intel platform's enrichment button as always passive
  • Believes the office VPN makes corporate egress unattributable

context

open as a page

Why can uploading a suspected implant to a public multi-scanner service burn your investigation?

level: middleimportance: must knowfreq 71%

basics

~20 s

An uploaded sample becomes visible to the platform's subscribers, and operators watch for their own tooling appearing there. The upload announces that the implant is discovered, and a targeted file often identifies the victim through embedded names, addresses or per-victim tokens.

open as a page

An analyst browsed a live C2 panel from the office network and the cluster went dark within the hour - what have you lost?

level: seniorimportance: should knowfreq 44%

basics

~20 s

You have likely lost quiet observation of that infrastructure and told the operator which company is investigating him, because corporate address space is attributable. Rotation timed to the visit is strong evidence he noticed, not proof.

open as a page