Certificate Tab for IPv4

Prev Next

When you investigate an IPv4 address in Total View, a dedicated Certificates tab is now available. It appears immediately to the right of the WHOIS tab and gives you fast visibility into the SSL/TLS certificates associated with that IP.

Because a single IP can host multiple websites, the tab is designed to handle multiple certificates and multiple domains per certificate — providing a complete picture of the certificate landscape for any IPv4 address.

Key Capabilities

Due to Expire Cards

At the top of the tab, you will find two summary cards:

  • Certificates expiring in the next 24 hours

  • Certificates expiring in the next 30 days

Counts are specific to the selected IPv4 address. Clicking either card filters the Certificate Details table to show only the matching certificates.

Certificate Issuers Chart

A visual chart displays the issuers of all certificates linked to the IP. It uses the same design language and interaction patterns as the Certificates experience for domains, making it easy to see which certificate authorities are most prevalent.

Certificate Details Table

The main table has been updated for IPv4 investigations:

  • The title is now “Certificate Details”

  • The previous “IPs Scanned On” column has been removed

  • A new sortable Domains Count column shows how many unique domains observed on this IP are using each certificate

  • A domain column has been added on the far right

Row Expansion

Expanding any row in the Certificate Details table reveals Web Search results for the selected IPv4 address, matching the behavior of the domain Certificates experience. This lets you quickly pivot into additional context without leaving the tab.

Handling Large Result Sets

The table loads a maximum of 100 rows per request. Additional results load incrementally using the existing pagination controls, so performance remains smooth even when an IP has a large number of certificates.

Note

This tab is available only when viewing an IPv4 address in Total View. It does not appear for domain lookups (domains continue to use the existing Certificates experience).  

How to Use It

  1. Search for an IPv4 address and open it in Total View.

  2. Click the Certificates tab (located immediately to the right of WHOIS).

  3. Review the Due to Expire cards for quick prioritization.

  4. Examine the Certificate Issuers chart to understand the distribution of authorities.

  5. Use the Certificate Details table to explore individual certificates, domain counts, and related domains.

  6. Expand any row to view associated Web Search results.

Tip

Because one IP can serve many sites, pay special attention to the Domains Count column. A high count may indicate shared hosting, a CDN, or potential infrastructure reuse by threat actors.  

The new Certificates tab brings the same depth of certificate intelligence previously available for domains into the IPv4 investigation workflow, helping you move faster from IP to actionable context.