Turn an indicator into a better investigation.

Start with a suspicious link, an IP from an alert, or an email from a report. Inspect the available records, follow the useful leads, and keep your team’s assessment together.

Investigate the infrastructure

Look up a reported domain, then inspect DNS, HTTP, certificates, registration, and available archives. Pivot to an IP for network context.

Check the other identifiers

Search an email or username from a report. Review returned public profiles and selected breach sources without treating a match as proof.

Make it repeatable

Send supported identifiers through the Search API, follow progress, and receive signed completion webhooks in your own workflow.

Follow the indicator, not a hunch.

Three different starting points. Open only the records that answer the question, then keep the source details with your assessment.

A reported login link needs triage.

Search the domain from the alert. Compare its DNS records, HTTP redirect, and certificate hostnames before deciding whether the link needs escalation.

Example domain; no live result is implied.

Reported domain

login.example.com

DNS

Addresses & records

HTTPS

Response & redirect

Certificate

Issuer & hostnames

Link triage

Sources & analyst notes

The inherited domains need a first pass.

After an acquisition, start with the domains you were given. Request subdomain, certificate, DNS, and passive service sections to map what is visible from outside. Keep the snapshot so the next review has a point of comparison.

An observed port or associated CVE is a lead for authorized verification, not a finding of current exposure.

Acquired domain list

Supplied by the security team

01

DNS & subdomains

Which hosts resolve?

02

Certificates

Which hostnames are covered?

03

Passive services

What was observed before?

04

Saved snapshots

What changed at the next review?

Request only the sections needed for this pass.

Give every indicator a first pass.

Your alert feed brings in a domain, an IP, and a sender address. Start a separate Search API request for each. Follow their progress and receive a signed webhook as each search finishes.

For a focused infrastructure check, choose the sections you need with Domain or IP Intelligence.

Talk to sales

Keep the reasoning with the alert.

Save the reported URL, the source sections you checked, and what still needs verification in one organization project. The next analyst can reopen the searches and follow your reasoning.

Set up an organization
Investigation project

Reported login link

Input
login.example.com
Sources opened
DNS · HTTP · certificate

Analyst note

Compare the redirect destination with the certificate hostnames. Confirm the current behavior before escalating.

Resources for your next investigation.

Questions from
security teams.

The Search API accepts usernames, emails, domains, IP addresses, and cryptocurrency addresses. Domain and IP Intelligence provide dedicated infrastructure checks. Available records depend on the source and the sections you request.

Put the right context
in your team’s hands.

Tell us which indicators you check, your daily volume, and where your analysts need the results.