Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

IP and Domain Threat Intel – TryHackMe Write-Up

This repository contains my write-up for the TryHackMe room IP and Domain Threat Intel.

The room focused on enriching IP addresses and domains using open-source threat intelligence sources. I worked through DNS records, RDAP/WHOIS lookups, ASN information, geolocation, exposed services, TLS certificate data, VirusTotal relations, and historical WHOIS findings.

Skills Practiced

  • DNS record analysis
  • IP geolocation validation
  • ASN and RIR enrichment
  • RDAP and WHOIS investigation
  • Shodan exposed service review
  • Censys TLS certificate checks
  • crt.sh certificate transparency lookup
  • VirusTotal relations analysis
  • Passive DNS and historical WHOIS review
  • IOC enrichment for SOC triage

Tools Used

  • nslookup.io
  • client.rdap.org
  • ipinfo.io
  • Shodan
  • Censys
  • crt.sh
  • VirusTotal
  • Historical WHOIS lookup sources

Walkthrough

The full walkthrough is available here:

View the PDF write-up

About

TryHackMe write-up focused on IP/domain threat intelligence, DNS records, ASN lookups, geolocation, exposed services, and passive DNS analysis.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors