Documentation Index

Fetch the complete documentation index at: https://help.silentpush.com/llms.txt

Use this file to discover all available pages before exploring further.

Farsight Tab

Prev Next

A domain resolves to dozens of IPs over months or years. Which are stable hosting addresses, and which are short-lived, fast-flux, or load-balancer entries? Manually querying Farsight DNSDB for every domain is impractical.

The Farsight tab aggregates historical A-record data from Farsight Security’s DNSDB—the world’s largest passive DNS database. It displays the number of times each domain-to-IP mapping has been observed globally, along with first and Last Seen dates, giving you a clear picture of infrastructure longevity and change.

Available for Domains. It works alongside Zetalytics (granular query-level detail), PADNS (current live resolutions), and Infrastructure Variance (ASN Diversity and IP churn).

How It Works

Farsight passively collects DNS responses worldwide. Silent Push surfaces the aggregated RRset counts and time windows. Per the latest updates, the table is streamlined: the Type column has been removed (all entries are A records for this view), the Domain Wide View toggle is gone, and risk-score/ASN columns are not displayed.

Generate a Set of Results

  1. Open Total View for any domain.

  2. Switch to the Farsight tab.

  3. The table loads with Count, Domain, IP, First Seen, and Last Seen columns.

  4. Adjust result size or apply date filters as needed.

Example

For silentpush.com, the top rows show:

  • Count 2344 for IP 8.6.112.0 (First Seen 2025-09-04, Last Seen 2026-04-02)

  • Similar high-count entries for 8.47.69.0 and older infrastructure from 2020.

High counts with recent Last Seen indicate primary, long-term hosting IPs.

Fields

  • Count: Number of global observations of this exact domain-to-IP A record.

  • Domain: The domain name.

  • IP: The IPv4 address the domain resolved to.

  • First Seen: Earliest date this resolution was recorded in Farsight DNSDB.

  • Last Seen: Most recent date the resolution appeared.

Use Case

Defenders quickly identify stable infrastructure (high Count + long First/Last Seen span) versus ephemeral IPs used in malicious campaigns. Correlating Farsight data with Whois changes or Threat Feeds helps attribute hosting providers and detect evasion tactics.

Work with Farsight Results

  • Pivot on Domain or IP directly into other tools.

  • Export CSV for reports or SIEM enrichment.

  • Save high-count IPs to monitoring lists for continued tracking.

Tips

  • Focus on rows with the highest Count for core Infrastructure mapping.

  • Compare First Seen vs. Last Seen spans to spot infrastructure migration events.

  • Combine with Zetalytics for subdomain-level granularity and PADNS for current status.