threat_cohosting
Resolve a domain to its IP, run reverse DNS and CT log searches to find co-hosted domains, and flag suspicious hosting.
Instructions
Analyzes domain co-hosting by resolving the domain to its IP, performing reverse DNS (PTR) lookups, and searching CT logs for other domains on the same IP. Flags hosting with suspicious co-hosted domains.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | The domain to analyze for co-hosting relationships (e.g. 'example.com') |