Bishop Fox published research showing that website favicons can be used as a practical reconnaissance signal to identify internet-exposed software, infrastructure, and decoys at scale. The work describes an AI-assisted workflow that hashes favicons with MurmurHash3, correlates results with Shodan data, and enriches findings through human review to map products, vendors, honeypots, and parking pages. The research says favicons are often stable, distinctive, and sometimes reachable even when applications are otherwise shielded by WAF or SSO controls, making them useful for passive pivoting and attack-surface intelligence.
Using a dataset of more than three million favicon entries, the researchers reported several notable findings, including signs that apparent cPanel exposure may be inflated by honeypots, attribution of infrastructure linked to Shadowserver Foundation and Thinkst Canary, and exposed Firefox noVNC sessions uncovered during enrichment. The report also notes that favicon handling is grounded in standard browser behavior defined by the HTML specification, but warns that favicon hashes are indicators rather than definitive proof of product identity, and presents the released repository as a starting point for further attack-surface mapping and validation.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
Bishop Fox published research describing an AI-assisted methodology for fingerprinting internet-exposed software using favicon hashing, Shodan data, and human-reviewed enrichment. The post also notes release of a repository and highlights findings including honeypot attribution and exposed Firefox noVNC sessions discovered during enrichment.
The HTML Standard reference describes how user agents process icon-related link types such as `icon`, providing standards context for browser favicon handling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.