Content
Here are a few ways to dig deeper:
-
Check the subnet: Investigate domains that are within the same subnet as the suspicious IP. Some (or most) of these will display similar behaviours.
-
Watch for reuse: Abusers recycle their resources e.g. the same web server often hosts several phishing domains, not just one. Passive DNS intelligence lets you acquire the information before, or immediately after, they change their domain or IP address.
-
Map the full range: In larger more complex operations, an abuser may control the full /24 subnet. Passive DNS intelligence can reveal all the domains that are pointing to an IP address in the subnet, giving you the full picture instead of a single data point.
-
Audit your own zones: Use passive DNS intelligence to find invalid or unauthorised records in the zones you control. This is a sign of unauthorised access or cache poisoning/spoofing, where corrupt DNS data is introduced into a resolver’s cache, causing the name server to return false results.
SEE THE FULL PICTURE WITH DETEQTIVE
A single suspicious IP rarely tells the whole story. Deteqtive's pattern matching and broader DNS coverage surface the entire cluster of related domains and infrastructure behind it, so you're not left guessing whether you've found one bad actor or missed the rest of their operation.
Want to know more? Deteqtive is currently in early access, you can find more information here or get in touch if you have any questions.