Passive DNS Pivots
ZETAlytics Global pDNS with 800 Billion records. Unearth nefarious domains within minutes of creation.
With the Passive DNS Pivots plugin, you can easily search through 800 billion global passive DNS records. Whether you're looking for suspicious domains or investigating host naming patterns, this plugin has got you covered. Search by IP, CIDR, domain name, or strings to uncover nefarious activities in just minutes. Plus, you can even use poly-dimensional search terms for more in-depth insights. Stay one step ahead of potential threats with this powerful and comprehensive plugin.
How to
Comments (0)
Try it
API docs
Learn how to use Passive DNS Pivots effectively! Here are a few example prompts, tips, and the documentation of available commands.
Example prompts
-
Prompt 1: "Search for host naming patterns in recent passive DNS."
-
Prompt 2: "Can you fetch the count of IP addresses associated with a domain over time?"
-
Prompt 3: "Give me a sample of dates when IP address resolutions were observed in passive DNS."
-
Prompt 4: "Fetch the count of hostnames that resolve to an IP address range."
-
Prompt 5: "What are the IP addresses associated with a specific domain?"
Features and commands
Feature/Command | Description |
---|---|
getQnames | This command allows you to search host naming patterns in recent passive DNS. You can specify strings that must be contained in the queried names, strings that should be contained, and the minimum number of should values that must match. You can also filter the search by a specific day. |
getDomainIPs | This command fetches the count of IP addresses associated with a domain over time. It also displays a sample of dates when the IP address resolutions were observed in passive DNS. You need to provide the domain name query. Optionally, you can specify a date range filter and select which date the range applies to. |
getDomainsForIP | This command fetches the count of hostnames observed resolving to an IP address range. It also displays a sample of dates when the resolutions were observed in passive DNS. You need to provide a CIDR range or a single IP address. Optionally, you can specify a date range filter and select which date the range applies to. |