This repository contains my write-up for the TryHackMe room IP and Domain Threat Intel.
The room focused on enriching IP addresses and domains using open-source threat intelligence sources. I worked through DNS records, RDAP/WHOIS lookups, ASN information, geolocation, exposed services, TLS certificate data, VirusTotal relations, and historical WHOIS findings.
- DNS record analysis
- IP geolocation validation
- ASN and RIR enrichment
- RDAP and WHOIS investigation
- Shodan exposed service review
- Censys TLS certificate checks
- crt.sh certificate transparency lookup
- VirusTotal relations analysis
- Passive DNS and historical WHOIS review
- IOC enrichment for SOC triage
- nslookup.io
- client.rdap.org
- ipinfo.io
- Shodan
- Censys
- crt.sh
- VirusTotal
- Historical WHOIS lookup sources
The full walkthrough is available here: