Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
Get detailed context on an IP address, including its user’s geolocation, time zone, connected domains, connection type, IP range, ASN, and other network ownership details.
Get access to a web-based enterprise-grade solution to search and monitor domain registrations and ownership details for branded terms, fuzzy matches, registrants of interest, and more.
Enjoy priority data access with our premium API services topped with extra perks including dedicated team support, enterprise-grade infrastructure, and SLAs for full scalability and high performance.
Carry a complete threat intelligence analysis for a given domain or IP address and get access to a report covering 120+ parameters including IP resolutions, website analysis, SSL vulnerabilities, malware detection, domain ownership, mail servers, name servers, and more.
We offer comprehensive services for the integration of our data – from consultations to the precise definition of the basic needs of the business to increase the work efficiency.
Set up and manage public WHOIS servers for your business. Our WHOIS parsing system is a utility that collects extensive information about any given domain by sending series of DNS and WHOIS queries. The report is generated in raw as well as in parsed format.
Regardless of whether you are a startup, a small business or a global one, our team is always ready to help you. Enterprises operating on a scale can also choose special premium support management with high priority 24/7 email and telephone responses and other professional services.
We detected noteworthy domain registration and Domain Name System (DNS) activity connected to some of the current events in May 2022, along with age-old targets of cybercriminal activities. We provided an overview for three of these items below. You may download relevant threat reports where available.
While the world is facing major crises of the century, cybercriminals are taking advantage of the situation and are rapidly setting digital traps in numerous creative ways. Cyberattacks affect not only individuals but also organizations and governments, begging for top-notch tools to help combat the threats.
The Cybernews team has invited Jonathan Zhang, the CEO of WhoisXML API, an Internet and security data aggregator, to discuss the importance of data and the current situation in the cybersecurity field.
We detected significant domain and DNS activity relevant to some of the top current events seen in April 2022. Check out the overview below, and feel free to download the dedicated threat reports where available.
Here are some of the top events in March 2022 for which we detected significant connected domain and DNS activity. See below for an overview, and feel free to download the dedicated threat reports where available.
Secure shell (ssh) is the typical tool for getting secure command-line access to Linux (and other Unix flavor) systems. Notably, most Linux-based servers are administered remotely via ssh access. Hence the security of the ssh service is of paramount importance, especially since it is often a very attractive part of the attack surface of an organization.
The present blog provides a discussion on setting up efficient firewall rules for the ssh service, and extending the whitelist easily with the help of WhoisXML API's IP Netblocks API. The method also works for other services using inbound tcp connections. We discuss a typical iptables firewall on a Linux system. Basic expertise in Linux tools and firewalls is assumed. The recipe works as it is, or with minor modifications also on other systems.
As an aggregator of WHOIS, DNS, and IP data, WhoisXML API can help back up journalistic investigations with verifiable online facts about domains and websites. Researchers and media professionals can use our 9-in-1 hosted Domain Research Suite (DRS) platform to investigate suspicious domains, detect domain registration trends, keep track of the government’s or private sector’s actions towards errant websites, and more.
WhoisXML API’s Newly Registered & Just Expired Domains Database (NRD Database) has a new and improved version. NRD 2.0 features the following changes from NRD 1.0:
Outputs now come in JSON and CSV.
A file dedicated to statistics can be downloaded along with the data.
NRD 2.0 has more data sources and covers more TLDs, giving you daily access to over 1+ million records.
New subscription plans are available to meet diverse data needs.
Users enjoy a concise and consistent file and directory structure across different subscription plans.
Learn more about NRD 2.0 in this comprehensive guide.
While the cybersecurity landscape constantly evolves, the targets remain consistent. Among the hardest hit by cyber attacks is the financial services industry. In Verizon’s 2021 Data Breach Investigations Report (DBIR), for instance, 65% of security incidents in the industry resulted in confirmed data disclosure.
Mitigating this problem begins by determining where the threat actors are attacking from—inside or outside? Identifying attack vectors is also pertinent.
Threat actors in the financial sector vary. Some are institution insiders and partners, while 56% are external parties. The top attack vectors are phishing and other social engineering campaigns.
One of the keys to a digitally safer financial industry is properly managing as many external attack vectors as possible. External Attack Surface Management (EASM) Solutions that uncovers and addresses vulnerable and dangerous Internet-facing assets, can help achieve this feat.
WhoisXML API uses cookies to provide you with the best user experience on our website. They also help us understand how our site is being used. Find out more here. By continuing to use our site you consent to the use of cookies.