Pivot map
Use this map to decide whether New Domain Hunter accepts the lead you are holding, and what kind of lead it may return for the next step.
Pivot from here
Outputs from New Domain Hunter can become inputs for the next tool. These are the most relevant follow-on pivots in the library.
A global, open, stable, and secure Internet that serves the entire Asia Pacific community
ARIN is a nonprofit, member-based organization that administers IP addresses & ASNs in support of the operation and growth of the Internet.
AbuseIPDB provides IP reputation data and community abuse reports for identifying malicious hosts in network and threat investigations.
AccountKiller provides direct deletion links and step-by-step instructions for removing accounts on hundreds of websites and social platforms.
Investigator Use
Hunting New Registered Domains is an open-source Python tool available on GitHub that automates the monitoring and analysis of newly registered domains for suspicious patterns, brand abuse, typosquatting, and phishing infrastructure. It retrieves daily newly registered domain feeds and applies detection rules to flag domains matching configured threat patterns.
For OSINT investigators and threat intelligence analysts, newly registered domain monitoring is a proactive intelligence capability — identifying malicious domains before they are weaponized, or immediately after deployment, provides a tactical advantage over reactive detection. Many phishing campaigns, brand impersonation attacks, and credential harvesting operations use domains registered within days of attack launch.
The tool's pattern matching capabilities allow investigators to monitor for: domains containing a target brand name or common misspellings (typosquatting), domains using lookalike characters in international alphabets (homograph attacks), domains following naming patterns consistent with known threat actor infrastructure, and domains registered in combinations suggesting fraudulent intent (company-name-login.com, company-name-verify.com patterns).
Daily monitoring of newly registered domains relevant to a protected brand allows brand protection teams to proactively identify and take down impersonating domains before victims reach them. For financial institutions, law firms, and other high-phishing-risk organizations, this proactive monitoring significantly reduces the harm from phishing campaigns.
The tool outputs discovered suspicious domains with registration timestamps, registrar data, and name servers, allowing investigators to prioritize domains for immediate investigation and potential takedown action.
Integration with threat intelligence platforms and security tooling is supported through its configurable output formats, enabling new domain alerts to automatically populate watchlists and detection rules.
Installation requires Python 3 and a source for newly registered domain feeds (several free sources are supported). Configure pattern rules based on protected brands and known threat actor naming conventions. Run daily against fresh domain registration feeds for continuous monitoring coverage.
Document all configuration rules, detection logic, and flagged domains with registration dates for case records.
Before You Pivot
Capture the target, search terms, and why this source is relevant before you leave the page.
Archive volatile pages, save screenshots, and keep timestamps for anything that may change.
Treat one tool as a lead source. Confirm important findings with independent sources.
Related tools
ARIN is a nonprofit, member-based organization that administers IP addresses & ASNs in support of the operation and growth of the Internet.
Free online network tools, including traceroute, nslookup, dig, whois, ping, and our own Domain Dossier and Email Dossier. Works with IPv6.
An open source intelligence tool to crawl the graph of certificate Alternate Names
Finds certificates and subdomains using Certificate Transparency data. An alternative to crt.sh that presents the information a bit differently.
DNS History archives historical DNS records, letting investigators track IP changes, hosting migrations, and infrastructure pivots over time.
DNS Twister generates and monitors domain permutations for typosquatting detection, brand protection, and phishing infrastructure discovery.