Open navigation

Farsight DNSDB

Modified on: Tue, 16 May, 2023 at 11:30 AM

Overview

DNSDB is a Passive DNS (pDNS) historical database that provides a unique, fact-based, multifaceted view of the configuration of the global Internet infrastructure DNSDB leverages the richness of Farsight’s Security Information Exchange (SIE) data-sharing platform and is engineered and operated by leading DNS experts.


Farsight collects Passive DNS data from its global sensor array. It then filters and verifies the DNS transactions before inserting them into the DNSDB, along with ICANN-sponsored zone file access download data. The end result is the highest-quality and most comprehensive Passive DNS data service of its kind - with more than 100 billion DNS records since 2010.


Farsight’s DNSDB Transforms threat feeds into actionable, relevant threat intelligence in real time to increase the value of an organization’s existing threat intelligence. Its high-performance, indexed, time-series DNS intelligence data service can ultimately improve visibility for an organization’s security program and protect its infrastructure from current and future threats.


DNSDB makes it easy to find related domain names and IP addresses, assuming you have an initial domain name or IP address as a starting point. DNSDB can answer questions, such as:

  • Where did this domain name point to in the past?
  • What domain names are hosted on a given IP address?
  • What domain names use a given name server?
  • What fully qualified domain names exist below a delegation point?


Farsight Security have created a package of Transforms allowing Maltego to retrieve related information for domains, hostnames, network addresses and ranges, and e-mail addresses. These Transforms use DNSDB to find values that were observed by one of Farsight’s DNS sensors for these Entities, as well as domains resolving to these Entities.


Please take note that the most recent update includes a refresh of all Transform UI names, the functional name for use in Machines stays the same. To line up with Maltego’s naming best practices, the “[DNSDB]” reference has been moved to the end of the Transform name. More information regarding the update, as well as a table with the old and new names can be found here. A flexible search functionality has been provided to enable users to locate Transforms based on both the old and the new Transform names.


The Farsight Security DNSDB Transforms expand the power of Maltego by enabling correlation and contextualization with near real-time and historical DNS intelligence; also known as passive DNS data. Using the DNSDB Transforms users can expose entire networks, gain an outside-in view of their infrastructure and pivot across DNS record types including domains, IPs, NS, MX, AAAA, SOA and many more. Wildcard searches are also available to expose hostnames or Fully Qualified Domain Names (FQDNs) in the left side wildcard, associated domains in the right-side wildcard, and further pivoting across IPs to expose all associated domains, FQDNs, IPs, MX, NS, and other record types.


The DNSDB Transforms for Maltego can be used in any Maltego investigation to:

  • Find hostnames related to network addresses.
  • Illuminate the DNS (and other service) hosting infrastructure of an interesting domain and finding other domains of interest.
  • Finding historical locations of a service identified by a hostname or domain.


Additional Resources


Farsight DNSDB Machines

[DNSDB] Enumerate Domain Machine

Takes a domain Entity, pulls all known hostnames, MX, NS, TXT, grabs IPs for *.domain -> Netblocks -> ASN


InformationValue
Idbenapril.DNSDBEnumerateDomain
Authorsupport@farsightsecurity.com

Farsight DNSDB Transforms

[DNSDB] Records with this value

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Records with this value
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrdataDNSName
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] To DNSNames with this value

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To DNSNames with this value
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Output EntitiesPhrase
Short Description 

Variants

Transform NameInput Entities
dnsdbrdataDomainmaltego.Domain
dnsdbrdataNetblockmaltego.Netblock

[DNSDB] To DNSNames with this IP

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To DNSNames with this IP
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrdataIPv4Address
Input Entitiesmaltego.IPv4Address
Output EntitiesPhrase
Short Description 

[DNSDB] To DNSNames from this IPv6 Address

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To DNSNames from this IPv6 Address
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrdataIPv6Address
Input Entitiesmaltego.Phrase
Output EntitiesPhrase
Short Description 

[DNSDB] Domains using this MX

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Domains using this MX
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrdataMXType
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] Domains using this NS

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Domains using this NS
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrdataNSType
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] To records with this hostname

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To records with this hostname
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Output EntitiesPhrase
Short Description 

Variants

Transform NameInput Entities
dnsdbrrsetDNSNamemaltego.DNSName
dnsdbrrsetDomainmaltego.Domain

[DNSDB] To A Records for this DNSName

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To A Records for this DNSName
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetDNSNameToA
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] To AAAA Records for this DNSName

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To AAAA Records for this DNSName
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetDNSNameToAAAA
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] To MX for this DNSName

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To MX for this DNSName
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetDNSNameToMX
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] To NS for this DNSName

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To NS for this DNSName
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetDNSNameToNS
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] To SOA Records for this DNSName

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To SOA Records for this DNSName
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetDNSNameToSOA
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] To SRV Records for this DNSName

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To SRV Records for this DNSName
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetDNSNameToSRV
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] To TXT Records for this DNSName

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To TXT Records for this DNSName
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetDNSNameToTXT
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup MX for this Domain

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup MX for this Domain
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetDomainMX
Input Entitiesmaltego.Domain
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup NS for this Domain

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup NS for this Domain
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetDomainNS
Input Entitiesmaltego.Domain
Output EntitiesPhrase
Short Description 

[DNSDB] To DNSNames from this email

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To DNSNames from this email
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetEmail
Input Entitiesmaltego.EmailAddress
Output EntitiesPhrase
Short Description 

[DNSDB] MX from E-mail address

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] MX from E-mail address
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetEmailMX
Input Entitiesmaltego.EmailAddress
Output EntitiesPhrase
Short Description 

[DNSDB] To DNSNames from this URL

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] To DNSNames from this URL
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetURL
Input Entitiesmaltego.URL
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup *.$dnsname

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup *.$dnsname
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwclDNSName
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup *.$dnsname/A

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup *.$dnsname/A
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwclDNSNameA
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup *.$dnsname/AAAA

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup *.$dnsname/AAAA
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwclDNSNameAAAA
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup *.$dnsname/CNAME

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup *.$dnsname/CNAME
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwclDNSNameCNAME
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup *.$domain

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup *.$domain
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwclDomain
Input Entitiesmaltego.Domain
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup *.$domain/A

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup *.$domain/A
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwclDomainA
Input Entitiesmaltego.Domain
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup *.$domain/AAAA

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup *.$domain/AAAA
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwclDomainAAAA
Input Entitiesmaltego.Domain
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup *.$domain/CNAME

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup *.$domain/CNAME
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwclDomainCNAME
Input Entitiesmaltego.Domain
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup *.$phrase

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup *.$phrase
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwclPhrase
Input Entitiesmaltego.Phrase
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup $dnsname.*

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup $dnsname.*
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwcrDNSName
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup $dnsname.*/A

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup $dnsname.*/A
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwcrDNSNameA
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup $dnsname.*/AAAA

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup $dnsname.*/AAAA
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwcrDNSNameAAAA
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup $dnsname.*/CNAME

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup $dnsname.*/CNAME
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwcrDNSNameCNAME
Input Entitiesmaltego.DNSName
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup $domain.*

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup $domain.*
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwcrDomain
Input Entitiesmaltego.Domain
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup $domain.*/A

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup $domain.*/A
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwcrDomainA
Input Entitiesmaltego.Domain
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup $domain.*/AAAA

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup $domain.*/AAAA
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwcrDomainAAAA
Input Entitiesmaltego.Domain
Output EntitiesPhrase
Short Description 

[DNSDB] Lookup $domain.*/CNAME

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] Lookup $domain.*/CNAME
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwcrDomainCNAME
Input Entitiesmaltego.Domain
Output EntitiesPhrase
Short Description 

[DNSDB] lookup $phrase.*

Transform Settings

AuthenticationDefault ValueDisplay NameOptionalPopupSetting Type
False API KeyFalseTruestring

Transform Meta Info

InformationValue
Display Name[DNSDB] lookup $phrase.*
OwnerFarsight Security
Authorsupport@farsightsecurity.com
Data SourceDNSDB
Transform NamednsdbrrsetwcrPhrase
Input Entitiesmaltego.Phrase
Output EntitiesPhrase
Short Description 

Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.