---
title: "Farsight Tab"
slug: "farsight-tab"
updated: 2026-06-24T14:19:53Z
published: 2026-06-24T14:19:53Z
canonical: "help.silentpush.com/farsight-tab"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.silentpush.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Farsight Tab

A domain resolves to dozens of IPs over months or years. Which are stable hosting addresses, and which are short-lived, fast-flux, or load-balancer entries? Manually querying Farsight DNSDB for every domain is impractical.

The **Farsight** tab aggregates historical A-record data from Farsight Security’s DNSDB—the world’s largest passive DNS database. It displays the number of times each domain-to-IP mapping has been observed globally, along with first and Last Seen dates, giving you a clear picture of infrastructure longevity and change.

Available for Domains. It works alongside **Zetalytics** (granular query-level detail), **PADNS** (current live resolutions), and **Infrastructure Variance** (ASN Diversity and IP churn).

## How It Works

Farsight passively collects DNS responses worldwide. Silent Push surfaces the aggregated RRset counts and time windows. Per the latest updates, the table is streamlined: the Type column has been removed (all entries are A records for this view), the Domain Wide View toggle is gone, and risk-score/ASN columns are not displayed.

## Generate a Set of Results

1. Open Total View for any domain.
2. Switch to the **Farsight** tab.
3. The table loads with Count, Domain, IP, First Seen, and Last Seen columns.
4. Adjust result size or apply date filters as needed.

## Example

For **silentpush.com**, the top rows show:

- Count **2344** for IP `8.6.112.0` (First Seen 2025-09-04, Last Seen 2026-04-02)
- Similar high-count entries for `8.47.69.0` and older infrastructure from 2020.

High counts with recent Last Seen indicate primary, long-term hosting IPs.

## Fields

- **Count**: Number of global observations of this exact domain-to-IP A record.
- **Domain**: The domain name.
- **IP**: The IPv4 address the domain resolved to.
- **First Seen**: Earliest date this resolution was recorded in Farsight DNSDB.
- **Last Seen**: Most recent date the resolution appeared.

## Use Case

Defenders quickly identify stable infrastructure (high Count + long First/Last Seen span) versus ephemeral IPs used in malicious campaigns. Correlating Farsight data with Whois changes or Threat Feeds helps attribute hosting providers and detect evasion tactics.

## Work with Farsight Results

- Pivot on Domain or IP directly into other tools.
- Export CSV for reports or SIEM enrichment.
- Save high-count IPs to monitoring lists for continued tracking.

> [!NOTE]
> Tips
> 
> - Focus on rows with the highest Count for core Infrastructure mapping.
> - Compare First Seen vs. Last Seen spans to spot infrastructure migration events.
> - Combine with Zetalytics for subdomain-level granularity and PADNS for current status.

## 

The most recent date a domain appeared in zone files, indicating its ongoing presence or activity in DNS records.

A metric indicating how frequently the IP addresses hosting a domain switch between different Autonomous System Numbers (ASNs) over the past 30 days, often used to detect suspicious domain behavior.

Autonomous System Number, a unique numeric identifier assigned to an Autonomous System (AS) for managing IP address routing within and between networks on the internet

The date when a domain was first observed in DNS zone files, providing insight into its age and potential trustworthiness in threat intelligence analysis.

Publicly available data collected during domain registration or DNS updates, used to analyze domain ownership and history.

An Indicator of Compromise (IoC) with potential to cause harm, such as a malicious IP, domain, or file hash.

A technique that visualizes and analyzes relationships between malicious IPs, domains, and other infrastructure to uncover threat actor networks.
