Incident Investigation and Response
Investigate Incidents With the Data Underneath.
Some incident questions can only be answered from outside your network: what a domain resolved to last month, who registered it, what else they registered, and whether anyone is selling what left. The index behind the Deepinfo Platform answers them.
domain login-acme.example
- DNS history GET /analyze/dns-history?type=A
- 203.0.113.24 · seen 2026-09-18, 2026-09-05 (the next pivot starts here)
- 198.51.100.77 · seen 2026-08-16
- Reverse IP · /24 reverse-ip?ip=203.0.113.24&mask=24
- neighbor domains on 203.0.113.0/24
- from login-acme.example Same-time · 10 minutes sametime-domain-finder?interval=10
- siblings registered with it
Each Question Has a Source That Answers It.
Scope, pivot, timeline, context: investigations come back to these questions. Each row links to the capability that holds the answer.
What Did Our Host Look Like Last Week?
Per-asset snapshots of DNS, HTTP, IP DNS (PTR), IP WHOIS, port scans, SSL, web data and WHOIS.
What Did This Domain Resolve To?
Passive DNS history: every value, with the times it was observed.
Who Registered It, and When Did That Change?
WHOIS history: every distinct registration record, with its dates.
What Else Is Connected?
Reverse lookups, same-time registrations and associated domains.
Is It Being Discussed or Sold?
Dark web search by email domain, IP, crypto address, card number, CVE and more.
Whose Credentials Are Exposed?
Breaches that include your addresses, with dates and the data types each one exposed.
Which Devices Leaked Them?
Infostealer-infected devices linked to your employees, with password, cookie and token counts.
Who Uses This CVE?
The CVEs and tools listed on each threat actor profile.
From One Domain to Its Neighbors.
Three requests, run in order, each answer feeding the next.
Request
# What has the suspicious domain resolved to?
curl "https://api.deepinfo.com/v1/analyze/dns-history?domain=login-acme.example&type=A" \
-H "apikey: YOUR_API_KEY"
Response
{
"fqdn": "login-acme.example",
"dn": "login-acme.example",
"subdomain": null,
"records": [
{
"type": "a",
"values": [
{ "value": "203.0.113.24",
"time": ["2026-09-18T05:41:26Z", "2026-09-05T21:26:18Z"] },
{ "value": "198.51.100.77",
"time": ["2026-08-16T16:37:59Z"] }
]
}
]
}
# Which other domains resolve into the same /24?
curl "https://api.deepinfo.com/v1/discovery/reverse-ip?ip=203.0.113.24&mask=24&page_size=25" \
-H "apikey: YOUR_API_KEY"# What did the same registrant register within 10 minutes?
curl "https://api.deepinfo.com/v1/discovery/sametime-domain-finder?domain=login-acme.example&interval=10" \
-H "apikey: YOUR_API_KEY"
Profiles Inform Attribution Without Deciding It.
If the CVE exploited in your incident appears on a Threat Actor Intelligence profile that also targets your sector, the list of candidates gets short.
Attribution stays your team’s call. The profiles tell you where to look and what to ask next.
| Identity | Name, aliases, first and last seen |
|---|---|
| Origin | Countries the actor operates from |
| Activity | Leak sites, forums and markets |
| Targets | Regions, countries, industries, organizations |
| Capabilities | CVEs and tools used |
Keep Watching After It Closes.
Verify
Confirm the Fix
An on-demand scan of an affected asset confirms the change without waiting for the next scheduled run.
Reopen
Watch for a Return
If a resolved issue’s signal comes back, it reopens as reappeared, and a notification rule tells the team.
Accounts
Work the Exposed Logins
Credentials tied to the incident move through recorded states until your team closes each one.
Report
Write It Up
Export the records behind each finding as CSV or JSON for the incident report.
Use This Data in Your Tools
Analysts can pivot through these records from their own tools: what else sits on an IP address, what a domain resolved to before, and who registered it.
Questions About Incident Investigation and Response
Is this a digital forensics service?
No. The platform supplies the external evidence: what infrastructure looked like, what connects to it and what is said about it. Forensics inside your network stays with your responders or your retained incident response firm.
Can we look up infrastructure that isn’t ours?
Yes. Lookups, history and finders work for any domain or IP address an incident turns up. Port Scan is the exception: it only targets hosts you own or are authorized to test.
Are lookups live or historical?
Both are available. WHOIS, DNS, IP WHOIS and SSL lookups query the target or its registry at request time and stamp the answer with check_, and DNS History and WHOIS History return what the index observed before.
Does history go back before we became a customer?
DNS and WHOIS history come from the index, so they cover whatever the index observed for a domain, independent of your subscription. Per-asset history in your monitoring starts when an asset is added.
Run Your Next Investigation on the Index.
Bring an indicator from a closed incident to a demo and follow the pivots, histories and actor context with our team.