IOC enrichment and investigation
Pull the history behind an IP or domain
See where an indicator has been and what FullHunt observed there.
The question
Did this indicator always belong to the same infrastructure?
A DNS lookup tells you where the indicator resolves today. FullHunt adds earlier resolutions and the services and organizations observed around them. Mapped CVEs help the analyst test the alert.
How it works
01
Query the indicator
Submit an IP or domain in the console, REST API, or Model Context Protocol (MCP) server.
02
Read the current host
Check the services, TLS certificates, hosting provider, and attributed organization.
03
Look back
Use passive DNS and historical observations to find earlier infrastructure relationships.
04
Attach the evidence
Return the FullHunt records to the case in your SIEM, SOAR, threat platform, or agent.
The records behind the answer
Observed host
Open ports, detected services, technologies, and TLS certificates.
Ownership
Organization attribution, ASN, hosting provider, and related infrastructure.
Passive DNS
Earlier links between the indicator, domains, and IP addresses.
Security findings
Mapped CVEs, EPSS, CISA KEV status, exploit records, and observed Tor nodes.
Put the source records in the case.
The same fields are available in the FullHunt Console, API, and MCP server.
What you get
- Current host, domain, IP, and organization records
- Prior DNS and infrastructure relationships
- Vulnerability and exploit records for observed services
- Structured JSON for the investigation that requested it
Investigate an IP or domain.
Start with one indicator and inspect the FullHunt records behind it.