Silent Push allows users to obtain a graphical representation of WHOIS record changes for any given domain, within a set time period.
Security teams are able to use the WHOIS History query to vizualise a domain's movement across the IP space, and track it's association with malicious infrastructure.
-
Navigate to
Explore DNS Data > WHOIS History
-
Specify a
Domain
-
Use the
Collected Before
andCollected After
fields to establish a timeline -
Click
Search
Working with WHOIS results
Once you've generated a set of results, the following fields are used to give a general overview:
WHOIS Record First Created
Latest SOA Record
Nameserver Reputation
scores for each nameserver
The graph displayed shows a visual timeline of WHOIS record changes, within the specified Collected Before
and Collected After
dates.
Hovering over a change gives the precise reason for the change:
A tabulated version of results are displayed below the graph, corresponding to the specified timeline, with any changes tagged on the relevant date:
You can expand each row to obtain the fill WHOIS record for that date, with any changes highlighted in red (the old value) and green (the new value).