---
title: "Web Search Tab"
slug: "web-search-tab-1"
status: "new"
updated: 2026-01-26T19:50:48Z
published: 2026-01-26T19:50:48Z
canonical: "help.silentpush.com/web-search-tab-1"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.silentpush.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Web Search Tab

A domain surfaces in your alerts, `example.com` linked to a Phishing kit. Is it a one-off scan hit, or part of a broader campaign with evolving web assets? Sifting through real-time snapshots misses the historical trail of content shifts and infra moves.

The **Web Search** view aggregates Scan Data in **Total View**, providing a searchable interface and results table for a domain's online presence. Below the Domain Wide View toggle, it reveals historical web content, response codes, and timestamps—ideal for tracking threat evolution without separate queries.

Available for Domains and IPv4, **Web Search** draws from Silent Push’s scan database, contrasting Live Scan's real-time focus by delivering a full historical dataset from all scan points. It complements the detailed guides under **Web Data >** [**Web Search**](/v1/docs/web-search), covering advanced query construction, data sources, and use cases, for instance, correlating an IP change in results with an Infrastructure Variance shift.

Web content analysis reveals attacker tactics, ranging from phishing pages to exposed directories; however, isolated scans lack context. It enables risk assessment and property verification by surfacing historical scans, helping teams identify trends such as repeated favicon hashes that signal kit reuse.

Security analysts use it to validate anomalies (e.g., outdated response codes indicating dormant threats), while defenders monitor subdomains for exposures. Customize queries for targeted views, export for reports, or save to feeds—streamlining workflows from Total View to escalation.

## How It Works

The web scanning engine collects and indexes data in-house, creating searchable historical datasets that rely on no third-party sources. **Web Search** queries this database, returning results such as HTML hashes, headers, and scan dates for the domain and its subdomains.

Unlike Live Scan's on-demand snapshot, **Web Search** provides directional intel: Track infra movements (e.g., server header changes) or TTPs over time. Domain Wide View extends to subdomains; Basic Raw Data mode delivers unprocessed details (e.g., full HTTP responses) for verification. It ties to other views: an IP in results might align with PADNS resolutions, enabling unified analysis.

[Web Scanner.mov](https://cdn.document360.io/8e5460b3-9d96-4b01-8bb3-6591a4af3a8c/Images/Documentation/Web%20Scanner.mov)

## Generate a Set of Results

Enter a domain (e.g., `example.com`) in the search bar to open **Total View**, and click **Web Search**. The search interface appears below the [Domain Wide View](/v1/docs/domain-wide-view) toggle; input parameters (e.g., hostname or data source) are used to populate the results table. Filter by scan date or response code, and toggle Basic Raw Data for unfiltered views.

## Example

- **Query**`example.com` **in Web Search**: Results show scans from 2025-09-01, with a 200 response for `www.example.com` (HTML hash: abc123, server: Apache/2.4.41), and a 404 for api.example.com (timestamp: 2025-08-31).
- **Domain Wide View includes subdomains**: a favicon MD5 match (d41d8cd98f00b204e9800998ecf8427e) across `blog.example.com`, flagging potential kit sharing. Outdated scans (e.g., 301 redirect on 2025-07-15) suggest infra drift.

> [!NOTE]
> Tip
> 
> Copy results to the clipboard, customize columns (e.g., add favicon path), or download as CSV for reporting. Save findings to a Feed or Draft Feed to monitor trends, such as recurring open directories.
> 
> - **Customize queries**: Use the ‘**Edit the query' option in the Web Search** tooltip to adjust the data source or hostname, focusing on specific subdomains.
> - **Analyze results**: Check response codes and scan_dates to identify outdated or failed scans.
> - **Export data:** Use **Download** or **Copy** for reporting, and **Basic Raw Data** for unfiltered details.
> - **Save findings**: **Save to a** **Feed** or **Draft Feed** to monitor trends or escalate issues.
> 
> For anomalies, pivot:
> 
> - A suspicious header? Chain-to-Infrastructure Variance for ASN ties.
> - Standalone **Web Data > Web Search** offers SPQL syntax and Dark Web scans. Use Query Constructor for complex filters or Query Multiple Data Sources for broader hunts.

### 

The identification of pre-packaged tools or scripts used by attackers to create phishing websites, analyzed to disrupt fraudulent campaigns.

Host scanning data retrieved through enrichment queries, including details like certificates, open directories, or favicons, used to validate and analyze potential threats.

A real-time analysis tool that scans a specific URL to capture current data, such as screenshots, HTML titles, favicons, redirect chains, and SSL details, for immediate threat validation.

A suite of tools in a threat intelligence platform for scanning and analyzing web-based content, including clearnet, dark web, and non-web services, to identify threats and vulnerabilities.

Unprocessed query results in JSON format, containing detailed threat intelligence data for further analysis or integration.

A curated stream of threat intelligence data containing indicators of compromise (IoCs), such as malicious IPs or domains, used to monitor and mitigate cyber threats.

Autonomous System Number, a unique numeric identifier assigned to an Autonomous System (AS) for managing IP address routing within and between networks on the internet

The query language used to construct precise searches across threat intelligence data sources, enabling advanced analysis via API or CLI.

A hidden part of the internet, accessible only through special software, where illicit activities, such as the sale of stolen data or malware, often occur, monitored by threat intelligence teams.
