DomainTools's Avatar

DomainTools

@domaintools.bsky.social

A global leader for internet #intel that enables security practitioners to proactively defend their organization in a constantly evolving threat landscape.

56 Followers  |  3 Following  |  41 Posts  |  Joined: 25.11.2024  |  1.835

Latest posts by domaintools.bsky.social on Bluesky

Preview
Inside the Great Firewall Part 3: Geopolitical and Societal Ramifications - DomainTools Investigations | DTI Part 3 analyzes the GFW as geopolitical infrastructure: economic protectionism, the export of cyber sovereignty norms, and the emergence of an authoritarian coalition (Russia, Iran).

๐ŸŒŽ Geopolitics and the Global Reach of the GFW
Part 3 dives into the Geopolitical and Societal Ramifications, revealing how China projects digital control abroad.
๐Ÿงต Read the final report: https://dti.domaintools.com/inside-the-great-firewall-part-3-geopolitical-and-societal-ramifications/

13.11.2025 20:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
How Domain Intelligence and Passive DNS create Full Profile DomainTools walks users through how using domain intelligence and passive DNS tools together create a fuller picture of a domain profile

Are your queries working as hard as they could be?

Using Iris Investigate + Farsight DNSDB in tandem gives you the fuller picture needed for better preventative decisions. Stop missing key pivots.

Read our latest blog post: https://bit.ly/3VzTr9V

13.11.2025 19:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Request a Demo | DomainTools - Start here. Know now. Discover how DomainTools can enhance your organizations capabilities and stop threats before they happen. Request a DomainTools demo today.

Looking to get the most out of your year-end budget?

DomainTools integrations delivers best-in-class DNS intelligence directly into your security stack to enrich alerts, automate investigations, and enhance threat detection.

Request a demo today! https://www.domaintools.com/demo/

12.11.2025 19:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Request a Demo | DomainTools - Start here. Know now. Discover how DomainTools can enhance your organizations capabilities and stop threats before they happen. Request a DomainTools demo today.

An independent study surveying DomainTools customers from Enterprise Strategy Group found DomainTools provided OEM partners 11 months faster time to value, reduced risk, and operational savings of 92%. Schedule a conversation with us here to learn more: https://www.domaintools.com/demo/

11.11.2025 19:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Inside the Great Firewall Part 2: Technical Infrastructure - DomainTools Investigations | DTI See the Great Firewall's technical blueprint. DomainTools Investigations details the TSG core, packet interception methods, and routines that detect tools like V2Ray/Psiphon.

๐ŸงตDTI researchers leveraged the leaked data from Chinaโ€™s Great Firewall to map the core design of the censorship stack in Part 2 of Inside the Great Firewall.

Read the technical deep dive here: https://dti.domaintools.com/inside-the-great-firewall-part-2-technical-infrastructure/

06.11.2025 20:29 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
DomainTools Demo - DomainTools | Start Here. Know Now.

DomainTools customers report wins from cost savings & improved detection rates, identifying up to 83% more malicious domains up to 96% faster with DomainTools than with industry-standard blocklist sources.
Set up a conversation with us to learn more: https://www.domaintools.com/domaintools-demo/

06.11.2025 19:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Request a Demo | DomainTools - Start here. Know now. Discover how DomainTools can enhance your organizations capabilities and stop threats before they happen. Request a DomainTools demo today.

DomainTools integrations deliver critical DNS intelligence into your TIP, SIEM, SOAR, E/XDR, and LLM solutions to:
๐Ÿ’กEnrich alerts
โš ๏ธGet predictive Risk Scores
๐Ÿ”—Make infrastructure pivots
๐Ÿ”Get instant Whois/RDAP data
Learn more: https://www.domaintools.com/demo/

05.11.2025 19:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Request a Demo | DomainTools - Start here. Know now. Discover how DomainTools can enhance your organizations capabilities and stop threats before they happen. Request a DomainTools demo today.

DomainTools maximizes the value of OEM products by identifying up to 83% more malicious domains, 96% faster compared to industry-standard blocklists. Want to learn more? Schedule a conversation with us here: https://www.domaintools.com/demo/

04.11.2025 19:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Inside the Great Firewall Part 1: The Dump - DomainTools Investigations | DTI Analysis of the 500GB+ Great Firewall data breach revealing Chinaโ€™s state censorship network, VPN evasion tactics, and the operators behind it.

500GB+ of data from China's digital censorship infrastructure was leaked last month. In Part 1 of our analysis, DomainTools Investigations maps the implicated entities and initial attribution clusters.

๐Ÿงต Don't miss the thread.
https://dti.domaintools.com/inside-the-great-firewall-part-1-the-dump/

30.10.2025 19:19 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
DomainTools Demo - DomainTools | Start Here. Know Now.

Ransomware & phishing campaigns are evolving fast. DomainTools helps Federal defenders stay ahead by exposing the infrastructure behind the threats.
Schedule a demo today to learn how your team can use DNS intelligence to strengthen your cyber posture: https://www.domaintools.com/domaintools-demo/

30.10.2025 16:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Request a Demo | DomainTools - Start here. Know now. Discover how DomainTools can enhance your organizations capabilities and stop threats before they happen. Request a DomainTools demo today.

Year-end budgets are in play. Are you making them count? ๐Ÿค”DomainTools integrations instantly enhance your security stack & deliver key DNS intelligence so you can:
๐Ÿ”Enrich alerts
โšกAutomate investigations
๐Ÿ—บ๏ธMap adversary infrastructure
Request a demo today! https://www.domaintools.com/demo/

29.10.2025 16:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

From NPM bypasses to crypto scam networksโ€”October brought a wave of complexity, and weโ€™ve got the full analysis.

Read and subscribe to Octoberโ€™s edition of the DomainTools Investigations Newsletter here: https://www.linkedin.com/newsletters/dt-investigations-news-7289801727560630273/

28.10.2025 20:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Is your team maximizing it DNS intel? DomainTools helps defenders uncover adversary infrastructure before it becomes a threat. Download our Best Practices Guide for OEMs to learn how our data empowers proactive defense & delivers up to 17X ROI in the first year. https://ow.ly/VcEU50Xh3Le

28.10.2025 18:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Request a Demo | DomainTools - Start here. Know now. Discover how DomainTools can enhance your organizations capabilities and stop threats before they happen. Request a DomainTools demo today.

Tired of jumping between security tools? Weโ€™ve got you covered.

DomainTools integrates with your favorite SOC platforms to deliver comprehensive DNS intelligence. Get the right data where you need it.

Request a demo to see our integrations in action.
https://www.domaintools.com/demo/

27.10.2025 16:01 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Request a Demo | DomainTools - Start here. Know now. Discover how DomainTools can enhance your organizations capabilities and stop threats before they happen. Request a DomainTools demo today.

Get the intelligence you need, right where you work ๐Ÿ’ป DomainTools integrates with your favorite tools to deliver:
๐ŸšจAlert/Event Enrichment
๐Ÿ”ฎPredictive Risk Scoring
๐Ÿ”—Infrastructure Pivots
๐Ÿ”Whois/RDAP Data
See how our integrations support your team.
https://www.domaintools.com/demo/

24.10.2025 16:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Government and military systems are among the highest-profile targets for attackers. Passive DNS data from DomainTools aids government agencies worldwide in gaining context on attacks against government or military infrastructure & networks. Learn more: https://youtu.be/NEf4hMR6qo8?t=130

23.10.2025 19:01 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Mapping Hidden Alliances in Russian-Affiliated Ransomware - DomainTools Investigations | DTI Explore the hidden web of Russian-affiliated ransomware groups through a visual map revealing human overlaps, shared infrastructure, and evolving cybercriminal alliances in the post-Conti era

How do you uncover the infrastructure behind state sponsored ransomware? Our analysts used domain risk scoring to expose connections between Russian-affiliated threat groups. Read the full investigation: dti.domaintools.com/mapping-hidd... #ThreatIntel #APT #Ransomware #DomainTools #CyberOps

23.10.2025 16:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
SecuritySnack: Repo The Repo - NPM Phishing - DomainTools Investigations | DTI A deep dive into the 4-stage NPM phishing attack flow that led to high-profile repository account takeover. Protect your development security.

๐ŸšจNPM developers are being targeted by sophisticated phishing that defeats MFA.

Attackers use multi-stage fake login pages to steal both credentials and MFA/OTP codes. Account takeover is fast and silent.
Read more:
dti.domaintools.com/securitysnac...

#CyberSecurity #NPM #InfoSec

16.10.2025 19:37 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

Thanks to all that attended Ian Campbell and @mjwalk.bsky.social #BSidesNoVA talks this morning. Please donโ€™t hesitate to stop by our table and say hello ๐Ÿ‘‹ !

11.10.2025 16:38 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
The Race Against New Threats: How Formula 1 Became a Hotbed of Cyber Activity Cyber and racing enthusiasts alike: Start. Your. Engines! The evolution of technology used in Formula 1 (F1) racing has caused each vehicle on the track to become computers on wheels. Formula 1 may be...

Donโ€™t miss @mjwalk.bsky.social lightening talk on the relationships between F1 and surrounding cyber activities at 11:30 at #BSidesNoVA!

bsidesnova-2025.sessionize.com/session/1000...

11.10.2025 14:26 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

At 11:30 AM Ian is presenting on DNS and domain intelligence as it applies to investigative journalist investigations. In related news, Allan Liska is selling โ€œThe Press Guardianโ€. We highly recommend checking out his table as well!

bsidesnova-2025.sessionize.com/session/1001...

11.10.2025 13:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Malachi and Ian standing at the DomainTools tabletop

Malachi and Ian standing at the DomainTools tabletop

Attending #BSidesNoVA? Be sure to say hello to Malachi and Ian at the DomainTools table before their talks at 11:30!

11.10.2025 13:01 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Inside a Crypto Scam Nexus - DomainTools Investigations | DTI A massive crypto wallet-drain conspiracy links fake trading sites to a single criminal IP address. See our investigative deep dive into how these orchestrated scams are draining user funds.

๐Ÿ’ฐ One attacker, one IP address. DTI discovered a coordinated web of wallet-drain scams all traced back to the same infrastructure. Learn how one setup runs multiple scams.

Full report:

๐Ÿ”— dti.domaintools.com/inside-a-cry...

#Crypto #Cybercrime #ThreatIntel

09.10.2025 16:44 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
SecuritySnack: 18+E-Crime - DomainTools Investigations | DTI Starting in September 2024, a financially motivated cluster of more than 80 spoofed domain names and lure websites began targeting users with fake applications and websites themed as government tax si...

New from DTI: A financially-motivated cluster of spoofed domains disguised as age 18+ social media content, government tax sites, consumer banking, and online gambling apps targeting Windows and Android users. Learn more โฌ‡๏ธ dti.domaintools.com/securitysnac...

#cybercrime #cybersecurity #threatintel

03.10.2025 16:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Cybersecurity Reading List - Week of 2025-09-29 - DomainTools Investigations | DTI Commentary followed by links to cybersecurity articles that caught our interest internally.

๐Ÿ“– Dive into this month's essential #cybersecurity reading list. Discover new research and articles from Google, The Record , @schneier.com , and more. Explore the list here: dti.domaintools.com/cybersecurit...

#InfoSec #ThreatIntel

30.09.2025 20:31 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
DT Investigations News | LinkedIn Monthly updates featuring community-based research focused on Domain- and DNS-based attacks

JUST DROPPED: Our Head of Investigationsโ€™ monthly newsletter!

๐Ÿ“ฐThis edition shares research on Salt Typhoon, the Kimsuky leak, PoisonSeed, and a banker trojan targeting android users in Southeast Asia: www.linkedin.com/newsletters/...

#Cybersecurity #ThreatIntel #InfoSec

30.09.2025 20:29 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Proactive Defense with DomainTools Real-Time Feeds - DomainTools | Start Here. Know Now. Stop domain-based threats before they start. Discover how DomainTools Real-Time Feeds deliver instant visibility into over 97% of the Internet, combining our predictive Risk Score with real-time updates for proactive cybersecurity.

Big news! Our Real-Time Threat Feeds are now available.

With feeds for high-risk and newly-discovered domains, you get instant, 97%+ Internet-wide visibility to strengthen your blue team and threat detection efforts.

Learn how: www.domaintools.com/resources/bl...

29.09.2025 23:41 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Inside Salt Typhoon: Chinaโ€™s State-Corporate Advanced Persistent Threat - DomainTools Investigations | DTI Salt Typhoon is a Chinese state-sponsored cyber threat group aligned with the Ministry of State Security (MSS), specializing in long-term espionage operations targeting global telecommunications infra...

DomainTools Investigations analyzed infrastructure and operational profiles for Salt Typhoon. Our research includes crucial intelligence for attribution, detection, and threat modeling. Read more hereโžก๏ธ dti.domaintools.com/inside-salt-...

#ThreatIntel #SaltTyphoon #Cybersecurity #NationStateAPT

25.09.2025 16:24 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Avoiding Activation Scams this Football Season - DomainTools | Start Here. Know Now. Learn how to use the DomainTools real-time Feed API within Splunk. This API enables faster detection, more flexible integration, and rapid adaptation to threats.

Football season is back, and so are the scammers! ๐Ÿˆ Learn how to avoid activation scams spoofing services like ESPN & CBS, and get essential security tips for organizations and end-users. Read our latest research today:
https://bit.ly/4nr2o0W

16.09.2025 13:32 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Speaker presenting at a podium with a "Confs Tech" banner on it, at a conference event. The presentation slide behind reads, "Splunk around the Phishmas Tree."

Speaker presenting at a podium with a "Confs Tech" banner on it, at a conference event. The presentation slide behind reads, "Splunk around the Phishmas Tree."

Steve Behm at #splunkconf25 shared a 2-year investigation into attacks on USPS & Amazon. His talk highlighted how to use Splunk and DomainTools to detect DGA domains and automate domain discovery.

#Cybersecurity #ThreatIntelligence #Splunk #Phishing

10.09.2025 19:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@domaintools is following 3 prominent accounts