Documentation Index

Fetch the complete documentation index at: https://help.silentpush.com/llms.txt

Use this file to discover all available pages before exploring further.

Monitor Nameserver Changes

Prev Next

Silent Push helps track changes to nameservers to detect malicious domain hopping or inadequate security practices. This query combines scans and searches for comprehensive monitoring.

  • Scan for Nameserver Changes: Identifies all changes to a domain’s nameservers, offering summarized results or detailed views.

  • Search for Nameserver Changes: Targets specific changes within a time window, including registrar and WHOIS filters.

Scan and search for Nameserver Changes

  1. From the left navigation menu, select Advanced Query Builder > Domain Queries > Nameserver Changes.

  2. Specify a domain.

    • (Optional) Click Summary to return summarized results.

    • (Optional) Click Explore Table View to visualize results and look up passive DNS data.

    • (Optional) For a targeted search, select Search Nameserver Changes.

  3. Specify nameservers in the from_ns and to_ns fields.

    • (Optional) Specify a date in change_date_before or change_date_after (defaults to the last 30 days).

    • (Optional) Check ns_changes_only to focus on nameserver data.

    • (Optional) Specify whois_date_before, whois_date_after, registrar, or email for WHOIS filters.

    • (Optional) Adjust the sorting order or set a limit and skip to control results.

  4. Click Search.

Save Query

  1. Specify query parameters.

  2. Click Save Query.

  3. Provide a Name and Description for context.

  4. Click Save. The query appears in Private Queries.

This pinpoints shifts in threat actor infrastructure, reducing attack windows.