Use Advanced Pivot Control to investigate an indicator without leaving your current page. Click an indicator to open the panel, review context, run a search, or save the indicator to a feed. The panel stays consistent with the rest of the platform so you can keep working in the same pattern you already use.
Open Pivot Control
Left-click a supported indicator anywhere in the platform. Pivot Control opens for that value.
The header shows the indicator, its type, and a Copy button.
The label next to Copy matches the column you clicked, including spelling and capitalization. If you clicked
origin_hostname, the header showsorigin_hostname.Pivot Control uses the same field the platform already uses for that indicator. It does not change existing field mapping.
Close and pin the panel
Click X in the top right to close Pivot Control. You can also click outside the panel to close it, unless you pin it. Closing the panel does not save anything.
Use Pin, to the left of X, when you want the panel to stay available.
Pin to keep this open across clicks and screens
Unpin to close this on clicks and screen changes
One Pivot Control open
Unpinned: the panel closes when you click X, click outside it, or leave the current page or tab.
Pinned: clicks outside the panel do not close it, and it stays open if you move to another page. Close it with X, or unpin it and then click outside.
Which tabs appear
Pivot Control shows only the tabs you can use for the current indicator and your access level. Tabs appear in this order when they apply:
Total View
Insight
Defend
Reconnaissance
Advanced Attribution
HTML Similarity Search
Tab | Available for |
|---|---|
Total View | Domain and IPv4. ASN support is coming later. |
Insight | Domain, IPv4, IPv6, ASN, and HTML Title. Email and phone number support is coming later. Live Scan is also available for IPs, domains, and URLs. |
Defend | Indicators that can be searched in Feeds. |
Reconnaissance | Indicators that can be searched in Web, Dark Web, Full WHOIS, Web Resource, Open Directory, Banner, WHOIS, PADNS, Domain Search, or Dynamic DNS. |
Advanced Attribution | IPv4 and IPv6. |
HTML Similarity Search |
|
Most searches open in a new browser tab and close Pivot Control on the original page.
Total View
Use this tab for a quick read of the indicator. Click Total View at the top to open the full Total View page in a new tab. Pivot Control then closes on the original page.
This tab shows:
Risk Score
The same flags you see in full Total View, such as Expired Cert or Part of Threat Feed
WHOIS for domains: registrar name and created date. WHOIS is not shown for IPv4.
PADNS record counts
Domain: A, AAAA, CNAME, NS, MX, SOA, and TXT
IPv4: A and PTR
A is selected by default
Infrastructure
Domain: ASN Diversity, IP Diversity, and NS Changes
IPv4: ASN, Subnet, AS Name, and AS Organization Name
Web Search highlights for Domain and IPv4: last scan date, response, header server, and HTML title
This tab does not include the pie chart, screenshot, Run Live Scan, or Traffic Origin. Use Insight for Live Scan and Advanced Attribution for Traffic Origin.
Fields that you can pivot from in full Total View can also be pivoted from this tab, including nshash, mxhash, txthash, and soahash.
Threat Feeds
If the indicator is on one or more feeds, Threat Feeds appears as a carousel. Move through feeds with the arrows or pagination dots. Each card shows the feed name, vendor, date added, feed tags, and indicator tags. Historical feeds are included when they apply.
Date added is the earliest date the indicator was added to that feed, matching full Total View.
If the indicator is not on a feed, you see: This [indicator type] is not part of any feed.
Insight
There is no search bar on this tab. Pivot Control uses the indicator you clicked.
The options match Search for Insights on the homepage for that indicator type, including the same order and descriptions. IPv4 and IPv6 each have their own list.
For IPs, domains, and URLs, Live Scan appears last in the list and follows the same layout as the other options.
Click an option to open that page in a new tab, already loaded for the indicator. Pivot Control then closes on the original page.
Defend
The Defend tab is for Feed Search.
Search feeds
Choose an operator from the dropdown. The list includes operators that apply to the pivoted indicator.
Search stays unavailable until you choose an operator. Choosing an operator does not start the search by itself.
Click Search to open Feed Search with the indicator and operator already applied.
Save Indicator to Feed
You can save the pivoted indicator to a feed when the indicator is a domain or IP. Feed Search operators remain available for every supported indicator type.
Save to an existing feed
Open the Existing Feed list. The list includes the feeds you can use and scrolls if there are many.
If you have no feeds, the list shows No feeds available and stays disabled.
Select a feed. Save becomes available.
Click Save.
If the save succeeds, you see Indicator saved to [Feed Name]. Pivot Control stays open. Save stays unavailable until you choose a different feed.
If the save fails, you see Failed to save indicator. Please try again. Pivot Control stays open so you can retry.
Save to a new feed
Click Add to New Feed. The new-feed flow opens over Pivot Control.
Create the feed and save.
If the save succeeds, the new-feed window closes and you see Indicator saved to new feed [Feed Name]. Pivot Control stays open.
If the save fails, the new-feed window stays open and you see Failed to save indicator. Please try again.
Click cancel to close the new-feed window without saving. Pivot Control stays as it was.
Open in New Search
This option appears only when you open Pivot Control from Context Graph Search.
Selected: the new condition starts a new Context Graph Search in a new tab.
Cleared: the new condition is added to the search you already have open.
Reconnaissance
The Reconnaissance tab is for Context Graph Search.
Choose data sources
Only sources that apply to the pivoted field are shown, in this order:
Web
Dark Web
Full WHOIS
Web Resource
Open Directory
Banner
WHOIS
PADNS
Domain Search
Dynamic DNS
Web is selected when the tab opens. You can select Web and Dark Web together. Selecting any other source clears the current selection and keeps only that source. At least one source stays selected.
Hover a source to see what it returns.
Run a search
Choose an operator for the selected source or sources. Web and Dark Web use the same operators, so selecting both does not change the list.
Choosing an operator opens Context Graph Search in a new tab with results already loaded, then closes Pivot Control. The search uses the field you are most likely to expect for that indicator. See Pivot Control Field Mapping for the defaults used in the query.
PADNS
PADNS uses lookup types instead of the operator dropdown. When PADNS is selected, choose a forward or reverse lookup to apply to the data, then click Lookup PADNS. Use Clear Selection to clear the lookup type.
Domain
Query: A, AAAA, CNAME, MX, NS, TXT, SOA
Answer (Reverse): PTR4, PTR6, CNAME, MX, NS
IPv4
Query: PTR4
Answer (Reverse): A
Open in New Search
This option appears only when you open Pivot Control from Context Graph Search.
Selected: the new condition starts a new Context Graph Search in a new tab.
Cleared: the new condition is added to the search you already have open.
Advanced Attribution
The Advanced Attribution tab is for Traffic Origin Search. It appears for IPv4 and IPv6.
Set a start and end date and time. The picker is empty until you choose values. If the end is before the start, you see an error in the picker.
Search stays unavailable until both times are valid.
Click Search to open Traffic Origin Search in a new tab for the indicator and time range. Pivot Control then closes on the original page.
HTML Similarity Search
This tab appears only when you pivot on html_body-ssdeep. Use it to find other pages with similar HTML.
Set Minimum Match. The range is 50 to 100. The default is 50.
Click Search to open HTML Content Similarity Search in a new tab with the hash and match value applied. Pivot Control then closes on the original page.