Hack.lu 2026

Bob van der Kamp

Bob is a senior (as in old and working for an eternity) CTI-Specialist of the NCSC-NL.


Session

10-22
16:30
30min
A Generalized Fingerprinting Framework for Deriving Searchable Features to Identify Publicly Exposed Infrastructure
Bilal, Bob van der Kamp

Scanning of internet-exposed infrastructure has become a core methodology in
network security research, vulnerability assessment, and threat intelligence.
Threat intelligence analysts and researchers routinely scan the public internet to identify
exposed services, characterize device types, and infer software versions in
order to assess security posture and systemic risk. When a new vulnerability is disclosed,
national security teams face the task of identifying the hosts that run the vulnerable version.
Here, time and reliability are key, because vulnerable infrastructure has to be found before
attackers find it. Under NIS2, which significantly expands the number and
diversity of organizations under supervision, this task has become even more
important.

Therefore, this talk presents parts of the results of a master thesis performed at the request
of and in close collaboration with the National Cyber Security Centre (NCSC-NL).
It gives insights into a proposed methodology that guides threat intelligence
analysts to a fast and reliable search engine query, in this case Censys, in
order to identify vulnerable infrastructure. We present part of the methodology,
which is modeled as a decision tree whose leaves result either in an effective query
or in the conclusion that no suitable query can be derived. Alongside it, we present
the comprehensive feature table, in which features across domains were aggregated to
depict the most promising fingerprinting features. Certificates, exposed HTML code,
and even TTL values of OT devices can all be used as fingerprinting features to identify a specific
vulnerable product. Finally, we present parts of the prototype: a CLI-based
tool that allows researchers and experts to automatically identify suitable
features and the resulting query.

topic: hack.lu
Europe