Disciplines

🔗 Domain Intelligence (DOMINT)

Domains, DNS, and Registration Intelligence
Cyber & Threat

Sources

0
0 no-auth

Mission domains

0
reach

Data points

0
covered

Related INT

0
disciplines

🔍 Lookup

📜 Playbook — Domain Intelligence collection

  1. Direction — frame the requirement for Domain Intelligence: what decision does this support, by when?
  2. Collection — collect from the 0 mapped sources (0 free) — filter the catalog by DOMINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Mission

Domain Intelligence analyzes domain registration, DNS, and hosting metadata to detect typosquats, phishing, and adversary infrastructure and to cluster related domains by shared attributes. It answers who registered lookalike domains, what infrastructure shares a registrant or nameserver, and how an actor's DNS footprint changes over time.

📡 Collection methods

  • WHOIS/RDAP enrichment and registrant pivoting to cluster domains by common ownership
  • Passive DNS analysis to map historical and current domain-to-IP relationships
  • Newly-registered-domain monitoring against brand and keyword watchlists
  • Typosquat and homoglyph permutation generation with live-resolution and MX checks
  • DNS record enumeration (A/AAAA/MX/TXT/NS/CNAME) to characterize hosting and mail posture
  • Nameserver and hosting clustering to expand from one malicious domain to a campaign

🔧 Tools & frameworks

  • dnstwist
  • Amass
  • dnsx
  • Sublist3r
  • urlscan.io
  • SecurityTrails
  • Maltego
  • massdns

📜 Domain Intelligence Tradecraft

  1. Generate typosquat permutations and ingest newly-registered-domain feeds filtered to brand and product keywords
  2. Resolve candidates and enrich each with WHOIS/RDAP, DNS records, hosting IP, and CT history
  3. Analyze which lookalikes are live, weaponized (MX set, login page cloned), or dormant, and prioritize accordingly
  4. Attribute domains to a common actor by pivoting on registrant email, nameserver, hosting IP, and registration timing
  5. Disseminate a prioritized watchlist of active phishing and impersonation domains to brand-protection and email defense
  6. Initiate registrar/registry takedowns and blocklisting, then track passive DNS for the actor re-hosting the campaign

📊 Dashboard KPIs

New lookalike domainsActive phishing domainsRegistrant clustersDNS record changesDomains taken down
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php