Good read about APT Infrastructure tracking by @censysio - https://censys.io/advanced-persistent-infrastructure-tracking/
Also combine this with JARM and the Threat Hunting game is on - https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a
π