Logo
Sign in
Product Logo
Farsight Newly Observed HostnamesDomainTools

Real-time detection of emerging hostnames to combat phishing and domain-based threats.

DomainTools-Threat-Intelligence-Feeds-Farsight-NOH-Header-Image.png
Platform_B…ure_EN (1).pdf
Product details

Overview

Farsight Newly Observed Hostnames (NOH) is a threat intelligence feed provided by DomainTools that offers real-time visibility into new hostnames and fully qualified domain names (FQDNs) as they become active on the internet. This immediate insight is crucial for organizations aiming to detect and mitigate threats such as phishing, domain shadowing, and other malicious activities that exploit newly created hostnames. By monitoring these hostnames from the moment they appear, NOH enables security teams to respond swiftly to potential threats, enhancing their overall cybersecurity posture.

Features and Capabilities

  • Immediate Detection of New Hostnames: Provides visibility into new hostnames and FQDNs within minutes of their first appearance on the internet, allowing for prompt threat identification.
  • Identification of Wildcarded and Tagged Hostnames: Detects wildcarded and uniquely tagged hostnames, which are often employed in phishing schemes or to bypass domain-focused investigations.
  • Brand Protection: Assists in safeguarding brand integrity by identifying unauthorized or malicious use of brand-related hostnames.
  • Detection of Domain Shadowing: Helps uncover instances where attackers create subdomains under legitimate domains without authorization, a tactic known as domain shadowing.
  • Integration with Security Systems: Can be integrated into existing security infrastructures, such as SIEM and SOAR platforms, to enhance threat detection and response capabilities.
  • Support for Threat Hunting and Incident Response: Provides valuable data for threat hunting activities and aids in the investigation and response to security incidents involving newly observed hostnames.