A domain under investigation shows erratic resolutions — example.com hopping IPs or nameservers in logs. Is it benign scaling, or fast-flux evasion? Piecing together historical ASNs, IP sprawls, and NS changes across tools disrupts focus.
The Infrastructure Variance view delivers a unified timeline of these evolutions directly inside Total View, with dedicated sub-tabs for ASN, IP Diversity, and Name Server Changes. It flags anomalies such as sudden diversity spikes by tying raw data to risk context for rapid triage.
Infrastructure Variance draws from Silent Push’s passive DNS and infrastructure datasets. It complements PADNS (for detailed resolutions) and WHOIS (for registrant context), and supports pivots into IOFA feeds for actor attribution.
What’s New
Recent updates make Infrastructure Variance more useful out of the box:
New 90-day default lookback — Both the ASN and IP Diversity tabs now load with a 90-day time range instead of the previous 30-day default. All existing options (30 / 60 / 90 / 180 / 360 days) remain available in the dropdown.
Improved IP Diversity chart styling — Bar colors and overall styling have been refined to reduce visual intensity while maintaining clear contrast. Colors are grouped by ASN and follow the same design standards as the PADNS Timeline view for easier scanning.
Clearer labeling — The bar chart column is now labeled “Observed Date Range”.
Updated hover tooltips — Tooltip colors have been refreshed to match the new visual design while preserving existing hover behavior.
These changes reduce the need for analysts to constantly widen the time window and make infrastructure variance data easier to interpret at a glance.
Why It Matters
Infrastructure shifts can signal threats: fast-flux for evasion, high-density nameservers for compromise, or ASN hops to bulletproof hosting. Manual tracking across queries often misses connections. This view consolidates historical and recent data so you can assess stability and risk in one place.
Security teams use it to detect unusual patterns (for example, 15 IPs in 30 days on outlier ASNs). Brand defenders map exposures. Pair it with PADNS for the underlying A/AAAA records or with WHOIS for ownership changes to fully explain the variance. A common workflow is correlating an ASN switch (e.g., from AS15169 to AS207713) with IOFA hits that point to known adversary infrastructure.
How It Works
Silent Push’s in-house aggregation engine compiles passive DNS and routing data into clear timelines. Three sub-tabs break the data down:
ASN — Network providers and their reputation
IP Diversity — Address sprawl over time
Name Server Changes — DNS management shifts
Raw details such as ASN takedown scores (0–100), IP counts with timestamps, and NS density populate filterable tables. You can enrich any row with one-click pivots to subnets, feeds, or related views. An NS shift here might align with PADNS anomalies and prompt a WHOIS check for possible takeovers.
Generating Results
Enter a domain (for example,
example.com) in the search bar and open Total View.Switch to the Infrastructure Variance tab.
The sub-tabs load automatically.
Use the time-period dropdown (now defaults to 90 days) to adjust the window.
Toggle Domain Wide View when you want to include subdomains.
Filter by date or metric as needed.
Example
Querying example.com in Infrastructure Variance might show:
ASN sub-tab — A hop from AS15169 (high takedown score) to AS207713 (lower score) on a specific date, flagging potential flux.
IP Diversity — A visual timeline of 15 IPs over the selected period, with a concentration on the newer ASN that triggers an outlier signal. The chart column is labeled “Observed Date Range.”