---
title: "Total View"
slug: "total-view"
status: "update"
updated: 2025-10-06T19:33:08Z
published: 2025-10-06T19:33:08Z
canonical: "help.silentpush.com/total-view"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.silentpush.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Total View

Total View consolidates comprehensive Domain and IP intelligence into a single screen, empowering security teams to detect, analyze, and mitigate threats proactively. This guide explains what **Total View** is, why it’s essential for modern cybersecurity, and how its Highlights section delivers actionable insights.

Total View is our centralized platform for analyzing domains and IPv4 addresses, integrating over 100 pivotable data points, including DNS records, web content, and Threat intelligence, into a single interface. Available in the free Community Edition and paid subscriptions, it eliminates the need for multiple queries, saving time for security operations centers (SOCs) and researchers.

### Total View

#### Total View provides:

- **Proactive Defense**: Utilizes Silent Push’s Indicators of Future Attack (IOFA™) to identify malicious observables before full deployment.
- **Comprehensive Insights**: Provides real-time and historical data, including subdomains and certificates, to identify and uncover threat patterns.
- **Efficiency**: Streamlines analysis with a unified view, reducing manual effort.
- **Brand Protection:** Detects impersonation attempts like Typosquatting or fake certificates.

Access all domain-related information in one place by navigating to the Total View screen. This screen is divided into three key sections: **Highlights**, **Expanded**, and **Domain-Wide** View.

## Highlights

Use the **Highlights** section to quickly review general domain details. Refer to the table below for an overview of each highlight.

![](https://cdn.document360.io/8e5460b3-9d96-4b01-8bb3-6591a4af3a8c/Images/Documentation/image(23).png)

Use the following table to understand the highlights of Total View:

|  | Highlight Section | Domain description | IP description | Why it matters | Access |
| --- | --- | --- | --- | --- | --- |
| 1 | **Domain** | Name of the domain. | IPV4 address | Identifies the Observable | All users |
| 2 | [**Risk Score**](https://help.silentpush.com/docs/risk-scores) | Proprietary score based on threat feed presence (for paid users) and secondary metrics. | Same as the domain | Quantifies malicious potential. | All users |
| 3 | [**Flags**](/v1/docs/understand-and-present-flags) | Flags that indicate if the domain is: - **IOFA Feed**: Currently active on an IOFA Feed |  |  |  |
| 3 | **Scores** | Age, Score, NS Reputation Score, NS Entropy Score. | IP Reputation, ASN Reputation, Subnet Reputation | Assess infrastructure trustworthiness | All users |
| 4 | **PADNS Infrastructure** | Counts of A, AAAA, CNAME, NS, MX, SOA, TXT records | Same as the domain | Flags DNS anomalies | All users |
| 5 | **Infrastructure Variance** | ASN Diversity, IP Diversity, NS Changes. | ASN, Subnet data | Detects suspicious infrastructure shifts. | All users |
| 6 | **Whois Information** | Registrar name, Created date. | Not applicable | Verifies domain legitimacy | All users |
| 7 | [**Web Search**](/v1/docs/web-search) **Highlights** | Response code, Scan Date, Header Server, favicon, HTML Title. | Same as the domain | Identifies phishing site traits. | All users |
| 8 | [**Flags**](/v1/docs/understand-and-present-flags) | Indicates IOFA feed presence (paid users) or other classifiers. | Same as the domain | Flags high-risk observables. | All users |

> **Note**: Some advanced metrics (e.g., Threat Feeds data in Risk Score and Flags) are unavailable for Community Users, but enhance analysis for paid subscribers by linking to real-time threat intelligence.

## Access Total View

- From the Silent Push homepage, enter a domain (e.g., example.com) or IPv4 address in the search bar.
- Click on an indicator, and you will be presented with the [Standard Pivot Control](/v1/docs/pivot-point-control); then, select Total View.
- Use the Quick Search bar (located at the top right), enter a domain.

## 

The human-readable name (e.g., example.com) associated with an indicator of compromise (IoC) or network resource, used to identify and access websites or services in threat intelligence analysis.

An Indicator of Compromise (IoC) with potential to cause harm, such as a malicious IP, domain, or file hash.

A tool or method to detect domains mimicking legitimate company or supply chain domains, used to identify phishing or fraudulent activity

A distinct data point, such as an IP address, domain, or file hash, used in threat intelligence to identify, track, or predict potential cyber threats.

A measure of an Autonomous System’s trustworthiness, calculated as the ratio of blacklisted IP addresses to the total active IPs within the ASN over the past 30 days, indicating potential risk levels.

The network segment associated with an IP address, used to contextualize and analyze related infrastructure.

A metric indicating how frequently the IP addresses hosting a domain switch between different Autonomous System Numbers (ASNs) over the past 30 days, often used to detect suspicious domain behavior.

Autonomous System Number, a unique numeric identifier assigned to an Autonomous System (AS) for managing IP address routing within and between networks on the internet

Publicly available data collected during domain registration or DNS updates, used to analyze domain ownership and history.

A small icon or image associated with a website, typically displayed in browser tabs or bookmarks, used in threat intelligence to identify potential spoofing or phishing by analyzing its unique characteristics or hash
