Domain Intelligence Cards®

Domain Intelligence Cards® provide an on-demand summary of essential information related to a specific Domain or DNS Names, and are updated in real time as Recorded Future collects new information. You can use Domain Cards as a starting point when assessing whether observation of a given Domain in a specific context is an Indicator of Compromise, and further can be used in security control rules to block or detect incidents. Domain Cards are also pivot points during investigations that start with another indicator, a malware tool, a vulnerability, or a threat actor.

Domain Intelligence Cards include the following tabs: 

  • Overview
  • Risk Rules
  • Insikt Group
  • Technical Links
  • Screenshot
  • DNS Resources
  • TLS
  • WHOIS
  • Extensions

  Training Available

Use in app-guidance to view the workflow inside of Recorded Future.

Overview

The Intelligence Card Overview includes a Summary of relevant information about this domain as well as modals for Screenshots of the domain, Sandbox Analysis, Recorded Future AI Insights, triggered Risk Rules, and any Analyst Notes written by users in your organization. 

domain.PNG

Risk Rules

Clicking on the Risk Rules tab displays Risk History for this domain as well as information on all currently triggered risk rules. Use the drop-down menu in the top right to change the time period for the Risk History view: Last Month, Last 3 Months, and Last Year. Learn more about Domain Risk Rules.

Domain_risk Rules.PNG

Insikt Group

View any Insikt Group Notes or Research Links related to the domain.

Technical Links

View any Technical Links related to the domain. These events generally report indicators and technical data observations. You can filter by time to focus only on the most recent events or an extended time frame, and filter by category. 

Screenshot

Recorded Future’s Domain Abuse use case now includes a screenshot of the domain, allowing you to quickly examine the content of a newly registered domain of interest and assess the risk it presents to their company.

The most recent domain screenshot can be found in the Overview of the Domain Intelligence Card as well as in the Screenshot tab, as shown below.

domain_screenshot.PNG

DNS Records

View subdomains, DNS Records, and DNS History for the domain.

domain_DNS.PNG

TLS

View TLS certificates of the company’s domain. Information also includes the issuer, created date and expiration date. 

domain_TLS.PNG

WHOIS

View WHOIS Record Data for the domain. Both current and historical WHOIS records from the organisation’s domain are displayed; click on the timeline to see more details for a specific date.

domain_WHOIS.PNG

Extensions

View data from available Intelligence Card Extensions, integrations that enhance Domain Intelligence Cards with content from our Intelligence Partners.

domain_extensions.PNG

This content is confidential. Do not distribute or download content in a manner that violates your Recorded Future license agreement. Sharing this content outside of licensed Recorded Future users constitutes a breach of the terms and/or agreement and shall be considered a breach by your organization.
Was this article helpful?
4 out of 4 found this helpful

Articles in this section