Obtain historic domain WHOIS information

Historic WHOIS data can provide valuable information about the ownership and registration of domains and IP addresses associated with potential threats. For example, information such as the name and contact information of the domain owner can be used to verify the legitimacy of a website or to identify potential sources of phishing or malware distribution.

WHOIS data can be used to identify patterns and connections between different domains and IP addresses, as well as between different threat actors.

By monitoring WHOIS data, security teams can detect and respond to changes that may indicate potential threats, such as the creation of new subdomains or changes to the IP addresses associated with a domain.

Silent Push allows you to scan for previously collected WHOIS information for visible domains, including (but not limited to):

  1. Nameserver information
  2. Address
  3. Registered emails
  1. Navigate to Advanced Query Builder > Domain Queries > whois information

  2. Specify a domain

  3. Click Search

Saving queries

Organizational users are able to save individual queries ran from Advanced Query Builder, and store them in the Private Queries menu for future analysis, or to share with their organization.

  1. Specify the query parameters

  2. Click Save Query

  3. Give your query a Name

  4. Specify a Description to add more context

  5. Click Save