Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
Success Stories
Malfors & WhoisXML API: Powering Cyber Investigations with Domain, DNS, and IP Intelligence

About
Highlights
- Without reliable domain ownership and DNS data built within their workflows, Malfors users would need to break away from their investigations to obtain additional context elsewhere.
- Malfors integrated several WhoisXML API products as enrichment sources built directly into the platform.
- The integration helped analysts pivot faster and strengthen attribution, and WhoisXML API is now one of the most popular integrations on the Malfors platform.
Mapping Malicious Infrastructure in One Investigation Workflow
Threat intelligence analysts, threat hunters, and incident response teams rely on Malfors to investigate threat actors and map the infrastructure behind their campaigns. A central part of that work is pivoting, which entails taking a domain, IP address, or WHOIS record and discovering related domains and infrastructure connected to it. Doing this well requires reliable domain ownership and DNS data, historical WHOIS records to trace changes over time, and the ability to search across records rather than look them up one at a time. Without that data built into the platform, analysts would need to step away from their investigation to run lookups elsewhere, slowing down attribution and infrastructure discovery.Domain Registration, DNS, and Reverse Lookup Intelligence Built Into the Graph
Malfors integrated a broad set of WhoisXML API products directly into its platform as additional enrichment sources. Analysts were able to enrich domains in their investigation with current or historical WHOIS records, or start from a string, email address, or registrant name and run a Reverse WHOIS search to identify domains associated with the same WHOIS details. The same pivoting extended to IP addresses, name servers, and mail servers, allowing investigators to move from a single indicator to a mapped network of related infrastructure without leaving their graph.“We’ve used WhoisXML API’s data in our own investigations, and it is one of the most popular integrations among Malfors users. It is the best source we’ve found for WHOIS data, including WHOIS history and Reverse WHOIS. Analysts can pivot on DNS records or WHOIS text to uncover more infrastructure and support threat actor attribution. Our users, from SOC teams to incident responders, can access that data in just a few clicks.”
Faster Pivoting and More Complete Investigations
WhoisXML API has become one of the most popular integrations on the Malfors platform, giving users direct access to domain ownership and DNS intelligence within their existing workflow. The integration paved the way for:- In-workflow pivoting: WhoisXML API data enabled analysts to map the related infrastructure for a domain or IP address without switching tools.
- Deeper context: Investigators were able to access current and historical domain ownership details in one place, helping to strengthen threat actor attribution.
- Broader coverage: Additional context, such as subdomains and geolocation, enabled analysts to map out a more complete attacker footprint.
Learn how WhoisXML API intelligence can help you achieve success
Try our WhoisXML API for free
Get startedHave questions?
We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.