Release 6.1 brings major advancements in visibility, automation, and user experience. Domain Impersonation detection is more powerful and intuitive, making it easier than ever to explore and act on your data.
Domain Impersonation Detection
We’ve completely rebuilt Domain Impersonation. It now uses advanced data science models to detect brand abuse and impersonation attempts more accurately and with more actionable signals. This helps security and brand protection teams spot sophisticated impersonation campaigns earlier and with greater confidence.
Domain Impersonation now works primarily with asset lists, supports scheduled background processing, and offers a simpler, more powerful experience.
Defend
My Assets
We’ve introduced My Assets to give you a strong foundation for attack surface visibility. It includes data ingestion and on-demand bulk enrichment so you can quickly build an accurate picture of your organization’s digital footprint.
You can now automatically track how your assets appear across the internet, making it easier to spot emerging risks early.
Domains and IP addresses are automatically discovered, aggregated, and continuously monitored with integrated threat intelligence. You’ll also benefit from improved brand spoofing detection and intelligent task queues that highlight the most important actions, helping your team respond faster.
Assets Impersonation
Assets Impersonation searches for domains that look like or target the assets you already track. You do not start from a blank query. You start from a domain or IP folder in My Assets. The feature then hunts for lookalikes of everything in that list.
Multi-Language Support
Spanish and Korean are available, with more languages coming, making the platform more accessible to global teams.
Total View Improvements
We’ve improved Total View to help you work faster and more clearly. This includes better handling of domains, URLs, IPv4, IPv6, and ASN data; improved Whois information; clearer threat feed presentation; and helpful additions such as copy buttons, Country Code support, and refined subdomain filtering.
PADNS Timeline Chart
A new timeline chart in PADNS shows a clear visual history of infrastructure changes. Quickly see when records first and last appeared, spot overlaps, and track how your digital footprint has evolved.
Improved Threat Feeds Tab
The Threat Feeds tab has an improved historical timeline with better colors, adaptive scaling, and clearer legends. We’ve also refined the layout and default ordering, and added direct PDF export so you can easily share insights.
Better Defaults and Clearer Views in Infrastructure Variance
We’ve updated the ASN and IP Diversity tabs in Total View’s Infrastructure Variance section to show recent changes more clearly and require less manual adjustment.
New 90-day default – Both the ASN and IP Diversity tabs now load with a 90-day lookback (instead of 30 days). All existing time range options (30 / 60 / 90 / 180 / 360 days) remain available.
Improved IP Diversity chart styling – Bar colors and styling are cleaner and easier to read, while still clearly distinguishing between different ASN groups. The design matches the PADNS Timeline view.
Clearer labeling – The bar chart column is now labeled “Observed Date Range”.
Updated hover tooltips – Tooltip colors match the new visual design.
These changes reduce the need to adjust the date range and make infrastructure variance data easier to read at a glance.
Redesigned WHOIS Experience in Total View
We’ve given the WHOIS tab a major upgrade focused on clarity, consistency, and faster analysis of historical changes.
Cleaner SOA Record Display
The Latest SOA Record section has been redesigned to match Total View’s look and feel. It now sits directly above the WHOIS Changes chart with consistent colors, cleaner typography, and a tighter layout.
New SPQL-Enabled WHOIS Changes Table
The WHOIS Changes table has been replaced with a full SPQL-enabled table. It keeps the same columns, compare feature, and “show only changes” default, now running on WHOIS data.
Redesigned WHOIS Changes Chart
The chart now visualizes the history of every major WHOIS field in a clear timeline format:
Each field gets its own row, always shown in this fixed order: Name, Organization, Email, Address, City, State, Zip Code, Country, Registrar, Expires, Name Servers, and WHOIS Server.
Horizontal bars show how long each value was active.
Adjacent value periods use alternating shades of blue for easy distinction.
Gaps appear where no data exists.
Hover a bar to see the exact value.
Bars for currently active values extend to the chart's right edge.
The chart’s date range automatically matches the current page of the Changes table and updates when you paginate.
Time-axis tick marks adjust intelligently (from hourly up to yearly), just like the PADNS Timeline chart.
These updates make it easier to see when WHOIS data changed and how long each value lasted, without leaving Total View.
New Certificates Tab in IPv4 Total View
We’ve added a dedicated Certificates tab to Total View for IPv4 addresses, making it faster to investigate SSL/TLS certificates associated with an IP address.
Key Capabilities
Tab location – Appears immediately to the right of the WHOIS tab.
Due to Expire cards – Two summary cards show certificates expiring in the next 24 hours and the next 30 days. Counts are specific to the selected IP; clicking a card filters the table.
Certificate Issuers chart – Shows the issuers of all certificates linked to the IP, using the same design and interactions as the domain Certificates experience.
Certificate Details table – Added a Domain column on the far right
Row expansion – Expanding a row reveals Web Search results for the selected IP, consistent with the domain Certificates behavior.
Large result handling – Loads up to 100 rows at a time with incremental pagination for smooth performance, even with many certificates.
Because a single IP can host multiple sites, the tab fully supports multiple certificates and multiple domains per certificate, giving you a complete view of the certificate landscape for any IPv4 address.
Polished Details Across Total View
Added a Timeline (Chart) view alongside the classic table view. Switch instantly using the Table / Chart icons in the top-right of any supported tab.
Chart icons are disabled when a tab has no data.
Improved the Certificates tab with a Domain Wide View toggle and clearer labeling.
Enhanced Infrastructure Variance views with better default time ranges and more readable charts.
Search and Navigation
Unified Search
We’ve replaced the previous header search with a more powerful and consistent unified Insight Search. It features a wider input field, helpful dropdown options, and fewer steps, making every search faster and more productive.
Advanced Pivot Control
The Advanced Pivot Control consolidates views into clean tabs (Total View, Insight, Defend, Reconnaissance, and more), preserves your context as you move between them, and makes it seamless to explore connections in your data.
TLP Amber + Strict Reports
Access highly sensitive Amber and Strict TLP reports with proper controls in place. This ensures the right people get the right information while maintaining strict security and compliance.