Obtain domain infratag

Prev Next

An infratag is a custom text string generated by Silent Push that contains the following information on a domain (in order, on one line, with values separated by a colon):

  1. MX - The domain portion of the domain's first MX record

  2. NS - The domain portion of the top last-seen nameserver

  3. AS - The AS name of the assigned IP address of the A record

  4. Reg - The registrar mentioned in the available WHOIS data

For example, the infratag for silentpush.com resolves to outlook.com:cloudflare.com:cloudflare.net:enom

Domain infratags enable organizations to search threat feeds and DNS records for similar tags, helping security teams identify malicious infrastructure before it becomes weaponized and familiarize themselves with broad attack surfaces without the need for complex queries.

Obtain domain infratag

  1. Navigate to Advanced Query Builder > Domain Queries > Infratag.

  2. Specify a domain.

  3. Under mode, choose live for current data or padns for passive data.

  4. Click Search.

Save queries

Organizational users can save queries for future use or sharing.

  1. Specify query parameters.

  2. Click Save Query.

  3. Provide a Name and Description for context.

  4. Click Save. The query appears in Private Queries.

This identifies malicious infrastructure before weaponization.