Request demo

Incident Investigation and Response

Investigate Incidents With the Data Underneath.

Some incident questions can only be answered from outside your network: what a domain resolved to last month, who registered it, what else they registered, and whether anyone is selling what left. The index behind the Deepinfo Platform answers them.

domain login-acme.example

  1. DNS history GET /analyze/dns-history?type=A
    • 203.0.113.24 · seen 2026-09-18, 2026-09-05 (the next pivot starts here)
    • 198.51.100.77 · seen 2026-08-16
  2. Reverse IP · /24 reverse-ip?ip=203.0.113.24&mask=24
    • neighbor domains on 203.0.113.0/24
  3. from login-acme.example Same-time · 10 minutes sametime-domain-finder?interval=10
    • siblings registered with it

From One Domain to Its Neighbors.

Three requests, run in order, each answer feeding the next.

Request

1 · DNS history
# What has the suspicious domain resolved to?
curl "https://api.deepinfo.com/v1/analyze/dns-history?domain=login-acme.example&type=A" \
  -H "apikey: YOUR_API_KEY"

Response

200 OK · application/json
{
  "fqdn": "login-acme.example",
  "dn": "login-acme.example",
  "subdomain": null,
  "records": [
    {
      "type": "a",
      "values": [
        { "value": "203.0.113.24",
          "time": ["2026-09-18T05:41:26Z", "2026-09-05T21:26:18Z"] },
        { "value": "198.51.100.77",
          "time": ["2026-08-16T16:37:59Z"] }
      ]
    }
  ]
}
# Which other domains resolve into the same /24?
curl "https://api.deepinfo.com/v1/discovery/reverse-ip?ip=203.0.113.24&mask=24&page_size=25" \
  -H "apikey: YOUR_API_KEY"

Profiles Inform Attribution Without Deciding It.

If the CVE exploited in your incident appears on a Threat Actor Intelligence profile that also targets your sector, the list of candidates gets short.

Attribution stays your team’s call. The profiles tell you where to look and what to ask next.

IdentityName, aliases, first and last seen
OriginCountries the actor operates from
ActivityLeak sites, forums and markets
TargetsRegions, countries, industries, organizations
CapabilitiesCVEs and tools used

Keep Watching After It Closes.

Verify

Confirm the Fix

An on-demand scan of an affected asset confirms the change without waiting for the next scheduled run.

Reopen

Watch for a Return

If a resolved issue’s signal comes back, it reopens as reappeared, and a notification rule tells the team.

Accounts

Work the Exposed Logins

Credentials tied to the incident move through recorded states until your team closes each one.

Report

Write It Up

Export the records behind each finding as CSV or JSON for the incident report.

Questions About Incident Investigation and Response

Is this a digital forensics service?

No. The platform supplies the external evidence: what infrastructure looked like, what connects to it and what is said about it. Forensics inside your network stays with your responders or your retained incident response firm.

Can we look up infrastructure that isn’t ours?

Yes. Lookups, history and finders work for any domain or IP address an incident turns up. Port Scan is the exception: it only targets hosts you own or are authorized to test.

Are lookups live or historical?

Both are available. WHOIS, DNS, IP WHOIS and SSL lookups query the target or its registry at request time and stamp the answer with check_date, and DNS History and WHOIS History return what the index observed before.

Does history go back before we became a customer?

DNS and WHOIS history come from the index, so they cover whatever the index observed for a domain, independent of your subscription. Per-asset history in your monitoring starts when an asset is added.

Can the pivots be scripted into our playbooks?

Yes. Every lookup and finder is a REST endpoint behind one apikey header, with rate limits set by plan. See the Lookup and Discovery references.

Run Your Next Investigation on the Index.

Bring an indicator from a closed incident to a demo and follow the pivots, histories and actor context with our team.