GO KALI FREE
IntermediateOSINT

OSINT Reconnaissance Using WHOIS Data

Master advanced WHOIS-based OSINT techniques including reverse lookups, historical data analysis, email harvesting, and combining WHOIS with other intelligence sources.

#WHOIS#OSINT#Reconnaissance#Intelligence Gathering#Domain Analysis

WHOIS as an OSINT Foundation

WHOIS data forms the backbone of domain-focused OSINT investigations. While individual WHOIS records provide limited information, combining multiple lookups, analyzing patterns, and cross-referencing with other sources reveals valuable intelligence about targets, their infrastructure, and relationships.

OSINT Methodology with WHOIS

The WHOIS Intelligence Cycle

  • **Initial query** — Gather basic domain registration data
  • **Pattern analysis** — Identify naming conventions, registration patterns
  • **Correlation** — Cross-reference with other domains and infrastructure
  • **Enrichment** — Combine with DNS, IP, and web intelligence
  • **Reporting** — Document findings and relationships
  • Advanced WHOIS Techniques

    Reverse WHOIS Lookup

    Find all domains registered by the same entity:

    # Using command-line tools
    # First, identify the registrant organization or email from a known domain
    whois known-domain.com | grep -i "registrant organization"
    
    # Then search for other domains by that organization
    # Use online services or tools like:
    # - domaintools.com/reverse-whois
    # - whoisfreaks.com
    # - securitytrails.com
    

    Historical WHOIS Analysis

    Track changes in domain registration over time:

    # Historical data reveals:
    # - Previous owners
    # - Registration transfers
    # - Contact information changes
    # - Name server migrations
    
    # Services for historical WHOIS:
    # - DomainTools (paid)
    # - WhoisFreaks (paid)
    # - SecurityTrails (freemium)
    # - WHOIS History API
    

    Bulk WHOIS Analysis

    Analyze multiple domains efficiently:

    #!/bin/bash
    # Bulk WHOIS analysis script
    DOMAINS_FILE=$1
    
    while read domain; do
      echo "=== $domain ==="
      whois "$domain" | grep -E "Registrar:|Creation Date:|Name Server:|Registrant Organization:"
      echo ""
    done < "$DOMAINS_FILE"
    

    Intelligence Gathering Techniques

    Registrant Correlation

    Link domains to the same owner despite privacy protections:

    # 1. Find domains sharing the same name servers
    whois domain1.com | grep "Name Server" > ns1.txt
    whois domain2.com | grep "Name Server" > ns2.txt
    diff ns1.txt ns2.txt
    
    # 2. Check for registration pattern similarities
    # Same registrar + same privacy service + similar dates = likely same owner
    
    # 3. Analyze DNS infrastructure overlap
    # Shared hosting, CDN, or email providers indicate relationships
    

    Email Harvesting

    Extract email-related intelligence from WHOIS:

    # Look for registrant email (if not redacted)
    whois example.com | grep -i "email"
    
    # Check for abuse contact
    whois example.com | grep -i "abuse"
    
    # Cross-reference with email OSINT
    # Use theHarvester to find associated emails
    theharvester -d example.com -b all
    

    Infrastructure Mapping

    Use WHOIS to map target infrastructure:

    # 1. Query IP addresses found in DNS
    whois $(dig example.com A +short) | grep -E "NetRange|CIDR|OrgName"
    
    # 2. Check reverse DNS for related domains
    for ip in $(dig example.com A +short); do
      echo "=== IP: $ip ==="
      whois $ip | grep -E "NetName|OrgName|OrgId"
    done
    
    # 3. Identify hosting provider and ASN
    whois $(dig example.com A +short) | grep -i "origin"
    

    Combining WHOIS with Other OSINT Sources

    WHOIS + DNS Integration

    # Complete DNS profile
    echo "=== DNS Records ==="
    dig example.com A +short
    dig example.com MX +short
    dig example.com NS +short
    dig example.com TXT +short
    
    # Cross-reference with WHOIS
    echo "=== WHOIS Name Servers ==="
    whois example.com | grep -i "name server"
    
    # Compare DNS name servers with WHOIS name servers
    # Discrepancies may indicate recent changes or hijacking
    

    WHOIS + Certificate Transparency

    # Find subdomains via CT logs
    curl -s "https://crt.sh/?q=%25.example.com&output=json" | \
      jq -r '.[].name_value' | sort -u | tee ct_subdomains.txt
    
    # Cross-reference with WHOIS data
    while read subdomain; do
      echo "=== $subdomain ==="
      whois "$subdomain" 2>/dev/null | grep -E "Registrar:|Creation Date:"
    done < ct_subdomains.txt
    

    WHOIS + Shodan

    # Use WHOIS to identify IP ranges, then scan with Shodan
    IP_RANGE=$(whois example.com | grep "NetRange" | awk '{print $2}')
    shodan search "net:$IP_RANGE" --fields ip_str,port,org
    

    Real-World OSINT Scenarios

    Investigating a Phishing Domain

    # Step 1: Basic WHOIS lookup
    whois phishing-site.com
    
    # Step 2: Check domain age
    CREATION=$(whois phishing-site.com | grep "Creation Date" | awk '{print $NF}')
    echo "Domain created: $CREATION"
    
    # Step 3: Identify registrar and abuse contact
    whois phishing-site.com | grep -i "registrar|abuse"
    
    # Step 4: Check name servers for infrastructure
    whois phishing-site.com | grep -i "name server"
    
    # Step 5: Query the hosting IP
    IP=$(dig phishing-site.com A +short)
    whois $IP | grep -E "NetRange|OrgName|Country"
    

    Mapping a Target Organization

    # Step 1: Start with known domain
    whois target-company.com
    
    # Step 2: Check name servers for shared infrastructure
    NS=$(whois target-company.com | grep "Name Server" | head -1 | awk '{print $NF}')
    
    # Step 3: Find other domains using the same name servers
    # Use SecurityTrails or similar service
    
    # Step 4: Analyze IP ranges
    dig target-company.com A +short | while read ip; do
      whois $ip | grep -E "NetRange|OrgName"
    done
    
    # Step 5: Cross-reference with employee LinkedIn profiles
    # Identify potential domain naming patterns
    

    Tracking Threat Actor Infrastructure

    # Step 1: WHOIS on known malicious domain
    whois evil-domain.com
    
    # Step 2: Check for shared registration patterns
    # Look for same registrar, similar creation dates
    
    # Step 3: Monitor name server changes
    # Changes may indicate infrastructure migration
    
    # Step 4: Correlate with threat intelligence feeds
    # Use MISP, OTX, or VirusTotal for enrichment
    

    Tools for WHOIS OSINT

    | Tool | Purpose | Access |

    |------|---------|--------|

    | whois | Basic command-line queries | Pre-installed on Kali |

    | theHarvester | Email and subdomain harvesting | Pre-installed on Kali |

    | maltego | Visual relationship mapping | Pre-installed on Kali |

    | recon-ng | Automated OSINT framework | Pre-installed on Kali |

    | SecurityTrails | Historical DNS and WHOIS | Freemium |

    | DomainTools | WHOIS intelligence | Paid |

    | Shodan | IP and infrastructure search | Freemium |

    Frequently Asked Questions

    How do I find domains owned by the same person?

    Use reverse WHOIS services to search by registrant name, email, or organization. Cross-reference name server patterns and registration dates to confirm relationships.

    Can WHOIS data reveal hidden infrastructure?

    Yes. Name servers, IP ranges, and registration patterns often reveal hosting relationships, shared infrastructure, and organizational connections that aren't immediately obvious.

    What if WHOIS data is redacted?

    Focus on available data: registrar, creation date, name servers, and domain status. Combine with Certificate Transparency logs, DNS analysis, and web archives to build a complete picture.

    How often should I check WHOIS data?

    For active investigations, check weekly. For monitoring brand abuse or threat actors, set up automated alerts through services like DomainTools or SecurityTrails.

    Is WHOIS OSINT legal?

    Yes. Querying public WHOIS databases is legal. However, the information gathered must be used responsibly and within your organization's legal framework and ethical guidelines.

    Frequently Asked Questions

    How do I find domains owned by the same person?

    Use reverse WHOIS services (DomainTools, WhoisFreaks) to search by registrant name, email, or organization. Cross-reference name server patterns, registration dates, and registrar information to confirm relationships.

    Can WHOIS data reveal hidden infrastructure?

    Yes. Name servers, IP ranges, and registration patterns reveal hosting relationships, shared infrastructure, and organizational connections. WHOIS is often the starting point for mapping a target's digital footprint.

    What if WHOIS data is redacted?

    Focus on available data: registrar, creation date, name servers, and domain status. Combine with Certificate Transparency logs (crt.sh), DNS analysis, web archives, and Shodan for infrastructure intelligence.

    How often should I check WHOIS data?

    For active investigations, check weekly. For brand monitoring or threat actor tracking, set up automated alerts through services like DomainTools or SecurityTrails to detect registration changes.

    What is a reverse WHOIS lookup?

    A reverse WHOIS lookup finds all domains registered by the same entity. Search by registrant name, email, organization, or other identifying information to map an organization's complete domain portfolio.

    How do you correlate domains through WHOIS?

    Compare name servers, registrar, creation dates, and registration patterns. Domains sharing the same name servers, registered around the same time, or through the same privacy service likely have the same owner.

    What tools are used for WHOIS OSINT?

    Command-line `whois`, theHarvester (email harvesting), Maltego (visual mapping), recon-ng (automation), and online services like SecurityTrails, DomainTools, and Shodan for enrichment.

    How do you investigate phishing domains with WHOIS?

    Query the domain for registrar and creation date (newly registered = suspicious), check name servers for infrastructure, analyze the hosting IP range, and cross-reference with threat intelligence feeds.