🔗 Domain Intelligence (DOMINT)
Domains, DNS, and Registration Intelligence
Cyber & Threat
Sources
0
0 no-auth
Mission domains
0
reach
Data points
0
covered
Related INT
0
disciplines
🔍 Lookup
📊 Pre-built Queries · Domain Intelligence
📜 Playbook — Domain Intelligence collection
- Direction — frame the requirement for Domain Intelligence: what decision does this support, by when?
- Collection — collect from the 0 mapped sources (0 free) — filter the catalog by DOMINT; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
✨ Enrichment pathways
🎯 Mission
Domain Intelligence analyzes domain registration, DNS, and hosting metadata to detect typosquats, phishing, and adversary infrastructure and to cluster related domains by shared attributes. It answers who registered lookalike domains, what infrastructure shares a registrant or nameserver, and how an actor's DNS footprint changes over time.
📡 Collection methods
- WHOIS/RDAP enrichment and registrant pivoting to cluster domains by common ownership
- Passive DNS analysis to map historical and current domain-to-IP relationships
- Newly-registered-domain monitoring against brand and keyword watchlists
- Typosquat and homoglyph permutation generation with live-resolution and MX checks
- DNS record enumeration (A/AAAA/MX/TXT/NS/CNAME) to characterize hosting and mail posture
- Nameserver and hosting clustering to expand from one malicious domain to a campaign
📚 Key sources & datasets
🎫 Data points produced
🔧 Tools & frameworks
- dnstwist
- Amass
- dnsx
- Sublist3r
- urlscan.io
- SecurityTrails
- Maltego
- massdns
📜 Domain Intelligence Tradecraft
- Generate typosquat permutations and ingest newly-registered-domain feeds filtered to brand and product keywords
- Resolve candidates and enrich each with WHOIS/RDAP, DNS records, hosting IP, and CT history
- Analyze which lookalikes are live, weaponized (MX set, login page cloned), or dormant, and prioritize accordingly
- Attribute domains to a common actor by pivoting on registrant email, nameserver, hosting IP, and registration timing
- Disseminate a prioritized watchlist of active phishing and impersonation domains to brand-protection and email defense
- Initiate registrar/registry takedowns and blocklisting, then track passive DNS for the actor re-hosting the campaign
📊 Dashboard KPIs
New lookalike domainsActive phishing domainsRegistrant clustersDNS record changesDomains taken down
🔍 Pre-built queries
🔗 Cross-discipline pivots
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron