Domain & IP Threat Reconnaissance: Whois, DNS History and Infrastructure Mapping
How to map threat actor infrastructure using passive DNS, reverse Whois, ASN analysis, and SSL certificate transparency logs.
Infrastructure reconnaissance allows security analysts to map threat actor servers and identify lateral assets without alerting defensive telemetry.
Reconnaissance Sequence
- Enumerate DNS records and correlate historical passive DNS resolutions.
- Query Certificate Transparency logs for undocumented subdomains.
- Inspect autonomous system numbers (ASNs) and IP geolocation markers.
Frequently Asked Questions
What is Passive DNS?
Historical record of domain-to-IP resolution telemetry used to map infrastructure shifts over time.
How does Certificate Transparency aid reconnaissance?
Public CT logs uncover unindexed subdomains and internal development endpoints.
What does ASN intelligence reveal?
The network routing entity, hosting provider, and IP neighborhood of targeted servers.