Reverse Whois Tracks in Threatconnect® leverage DomainTools, an external data service that interfaces with ThreatConnect to actively detect and issue alerts about new associations discovered in Whois records between Adversary assets and hosts. After the initial execution, when all current Whois records are examined, the Track searches daily for new Whois records to analyze.
Tracks are created through two methods. The first method, outlined in Create, uses the CREATE option on the top navigation bar. This method offers more options to customize a Track via the Contains/Does Not Contain fields. However, with this method, Hosts imported from Track results will not be automatically associated to an Adversary. The second method, detailed in this article, creates a Track based on an Adversary’s assets.
- From the top navigation bar (Figure 1), place the cursor over BROWSE and then over the GROUPS option. Click on the ADVERSARY object to display a results table (Figure 2).
- Click on one of the entries, and the Details flyout for that entry will appear (Figure 3).
- Click the Details icon at the top right corner of the flyout, and the Overview tab of the Details screen will appear (Figure 4). Alternatively, hover over the object's entry in the table in Figure 2 and click on the Details icon that appears on the right side of its Summary cell to go straight to the Overview tab of the Details screen.
- Click the Assets tab, and the Assets screen will appear (Figure 5). Verify that at least one asset is listed. If the tab shows No Assets Found, then follow the steps outlined in Adding Adversary Assets.
- Click the Tracking tab, and a results table of assets will appear (Figure 6).
- Click the gray paw print next to an asset. The paw print will turn orange, and the Results column will show results of the initial Reverse Whois lookup (Figure 7).
- Click on the blue text displaying the results total, and the Overview screen will appear (Figure 8).
NOTE: The Overview screen for a Track can also be accessed by viewing Tracks on the Browse screen, selecting a Track, and clicking the Details icon from its Details flyout or directly from its entry on the Browse screen.
- Click the Follow Item checkbox at the top right to receive push-notification or email updates when changes are made to the Track. See Notifications and Following for more information.
- Click the Results tab to view domains found in the lookup (Figure 9).
- Click on the DNS or Whois link in the Options column for a given domain to view DNS or Whois information, respectively, for that domain.
- To import domains as Host Indicators into one or more Groups of a given type, select the desired domains and click the IMPORT button. The Import window will appear (Figure 10).
- Check the DNS Resolution Active box to activate DNS resolutions for the imported Hosts.
- Check the Whois Active box to activate Whois registration information for the imported Hosts.
- Use the Select Type dropdown menu above the table to select a Group type. The table will display all available Groups of that type. Select the Groups to which the Hosts should be added as associated Indicators. Only one Group type may be selected at a time, but multiple Groups within that type may be selected, even if those Groups are displayed on different pages. Then click the SAVE button.
- To save the Host Indicators without association, click the SAVE button without selecting any Groups.