Blog & How To Guides | WhoisXML API

WhoisXML API Blog

November 2024: Domain Activity Highlights

The WhoisXML API research team analyzed 8.2 million domains registered between 1 and 30 November 2024 to identify the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

We also determined the top TLD extensions used by 59.6 billion domains from our DNS database’s A record full file released in the same month.

Next, we studied the top TLDs of 1.1 million domains detected as indicators of compromise (IoCs) in November.

Finally, we summed up our findings and provided links to the threat reports produced using DNS, IP, and domain intelligence sources during the period.

Our Passive DNS APIs Are Now Enriched with Wildcard and Active Output Parameters

We are thrilled to announce that several of our APIs have been upgraded to include new data points, namely, wildcard and active. In particular, both fields are now optional output parameters for Reverse IP API, Reverse DNS API, Reverse MX API, and Reverse NS API. Our newly launched DNS Chronicle API, meanwhile, has a wildcard field as part of its default output format.

With the new wildcard field, WhoisXML API users can now:

WhoisXML API Unveils First Watch Malicious Domains Data Feed with 97% Predictive Precision

We are excited to introduce First Watch Malicious Domains Data Feed, the newest addition to our predictive threat intelligence product line. This innovative solution is designed to enhance early threat detection and response by identifying substantially more malicious domains than traditional feeds, right at the point of registration.

First Watch Malicious Domains Data Feed offers several key advantages for cybersecurity teams, whether they are part of in-house Security Operations Centers (SOCs) or Managed Security Service Providers (MSSPs).

Decoding the Encoded

Authors:
Ed Gibbs, Field CTO, WHOIS API Inc.
Jeff Vogelpohl

Introduction

Growing up, I remember the vast array of candies and ice cream flavors while visiting quaint candy shops. Today, we’re overwhelmed by the plethora of technologies any imaginative person could want – thanks to the provocativeness of human ingenuity. As flavors were designed for these memories of delightful treats, this same ingenuity has brought technological advancements like AI to aid and improve all life whereas some provide just the opposite. Our adversaries continuously exploit and weaponize our ingenuity to degrade life. Life is worth protecting.

Managing a Passive DNS Database Using PostgreSQL

Abstract

This document outlines the setup of a PostgreSQL database on Ubuntu Linux to efficiently manage and query WHOISXMLAPI’s Premium DNS database. Designed to store and analyze billions of DNS records, this database will handle large-scale data ingestion, facilitate rapid data retrieval, and support extensive analytical operations. PostgreSQL's robust performance, scalability, and support for advanced indexing make it ideal for managing DNS data, while its compatibility with open-source tools provides a flexible environment for future scaling and data processing.

Managing a Passive DNS Database Using Apache Cassandra

Abstract

Apache Cassandra is a highly scalable, distributed NoSQL database designed for handling massive volumes of data across many commodity servers without a single point of failure. Its decentralized nature and robust architecture make it particularly well-suited for applications that require high availability, fault tolerance, and horizontal scalability. Cassandra is engineered to handle very large datasets, supporting billions of records with ease, making it an ideal choice for organizations dealing with large-scale, real-time applications such as time-series data, IoT data, and customer logs. Through its use of a partitioned architecture and the ability to add nodes seamlessly as data grows, Cassandra offers an efficient means of managing big data with low latency and high throughput.

October 2024: Domain Activity Highlights

The WhoisXML API research team analyzed more than 8.2 million domains registered between 1 and 31 October 2024 to identify the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

We also determined the top TLD extensions used by the more than 57.4 billion domains from our DNS database’s A record full file released in the same month.

Next, we studied the top TLDs of more than 1.0 million domains detected as indicators of compromise (IoCs) in October.

Finally, we summed up our findings and provided links to the threat reports produced using DNS, IP, and domain intelligence sources during the period.

DNS Database Download Is Now Reinforced with Wildcard and Active Fields

We are excited to announce that the Standard and Premium DNS Database files from DNS Database Download are now enriched with two new columns, namely, wildcard and active. These additions allow you to determine if a DNS record is part of a wildcard entry and check if a domain name or subdomain is active based on its most recent resolution status.

Try our WhoisXML API for free
Get started