Skip to content
FullHunt

IOC enrichment and investigation

Pull the history behind an IP or domain

See where an indicator has been and what FullHunt observed there.

IP and domain records Passive DNS Ownership Vulnerabilities

The question

Did this indicator always belong to the same infrastructure?

A DNS lookup tells you where the indicator resolves today. FullHunt adds earlier resolutions and the services and organizations observed around them. Mapped CVEs help the analyst test the alert.

How it works

01

Query the indicator

Submit an IP or domain in the console, REST API, or Model Context Protocol (MCP) server.

02

Read the current host

Check the services, TLS certificates, hosting provider, and attributed organization.

03

Look back

Use passive DNS and historical observations to find earlier infrastructure relationships.

04

Attach the evidence

Return the FullHunt records to the case in your SIEM, SOAR, threat platform, or agent.

The records behind the answer

Observed host

Open ports, detected services, technologies, and TLS certificates.

Ownership

Organization attribution, ASN, hosting provider, and related infrastructure.

Passive DNS

Earlier links between the indicator, domains, and IP addresses.

Security findings

Mapped CVEs, EPSS, CISA KEV status, exploit records, and observed Tor nodes.

Put the source records in the case.

The same fields are available in the FullHunt Console, API, and MCP server.

What you get

  • Current host, domain, IP, and organization records
  • Prior DNS and infrastructure relationships
  • Vulnerability and exploit records for observed services
  • Structured JSON for the investigation that requested it

Investigate an IP or domain.

Start with one indicator and inspect the FullHunt records behind it.