The move, confirmed by internal communications, is part of a broader wave of reductions and restructuring within the agency.
According to Nextgov/FCW, on April 16 notificationwas sent to over 500 CISA cyber threat hunters. The division stopped using Censys, a service for mapping exposed devices and services, in late March, and will retire the use of Google-owned VirusTotal, a widely used malware analysis platform, effective April 20, 2025.
“We understand the importance of these tools in our operations and are actively exploring alternative tools to ensure minimal disruption,” the agency stated in its internal email, emphasizing efforts to find suitable replacements soon.
The decision follows significant staff reductions, including contractors from Nightwing and Peraton, raising concerns about CISA’s operational capacity to proactively defend federal networks and critical infrastructure.
The retirement of VirusTotal and Censys marks a significant operational challenge for CISA’s threat hunters.
VirusTotal has long enabled analysts to scan suspicious files and URLs using multiple antivirus engines and sandbox tools, while Censys provided continuous internet-wide scanning to identify exposed assets and vulnerabilities.
The loss of these platforms could slow detection and response times, potentially creating temporary blind spots as staff adjust to new workflows and tools.
CISA has assured staff that it is evaluating alternative platforms to fill the gap. Potential substitutes include:
However, integrating these alternatives will require development work, workflow adjustments, and retraining for analysts.
The agency faces the challenge of maintaining robust threat-hunting operations while managing reduced resources and political scrutiny over its mission and scope.
| Functionality | Retired Tool | Potential Alternatives |
|---|---|---|
| Malware Analysis | VirusTotal | Hybrid Analysis, Joe Sandbox |
| Internet Asset Discovery | Censys | Shodan, Zoomeye |
| Threat Intelligence Feeds | VirusTotal | Recorded Future, Anomali |
As CISA navigates this transition, its ability to quickly deploy effective replacements and maintain its threat-hunting edge will be crucial for safeguarding federal networks against increasingly sophisticated cyber threats.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates
The post CISA Halts Use of Censys and VirusTotal for Threat Hunting Operations appeared first on Cyber Security News.
Some of the Invincible VS DLC roster appears to have leaked online, pointing to the…
HARRISBURG, Pa. (AP) — Building trades unions — long fashioned as the voice of the…
Reggie Fils-Aimé has opened up about the time an Amazon executive gave him a phone…
Reggie Fils-Aimé has opened up about the time an Amazon executive gave him a phone…
Star Wars Day is upon us, and that means there's a slew of Star Wars…
A new weekend has arrived, and today, you can save big on Dragon Quest VII…
This website uses cookies.