Skip to main content

What are the URL & Domains search parameters of Threat Hunting?

Updated over a week ago

In this article, you'll find the URL & Domains search parameters, along with usage examples for each. If you have any questions, please contact our support team.

Additionally, we provide multiple search parameters to help you refine your results when searching for URLs and domains. All of these parameters are available when you access the result details. Below, we have organized the search parameters into a hierarchy to optimize your analysis.


1. Primary URL & Domain Identification

These fields are essential for identifying and classifying URLs and domains:

Parameter

Description

Example

reference

Full reference of the URL or domain

domain

Registered domain of the reference

domain="malicious-example.com"

domainCreationDate

Domain creation date (useful for identifying newly created domains)

domainCreationDate>2025-01-16

origin

Origin of the reference

origin=phishtank OR origin=urlscan

host

Host related to the reference

host="secure-bank.example.com"

subdomain

Subdomain associated with the reference

subdomain="login"


2. Threat & Phishing Indicators

Parameter

Description

Example

contentType

Type of Content

contentType="e-commerce","parked domain", "financial", "news", "social media", "forum", "message app", "error page", "blank page", "login page", "adult", "gambling", "games", "captcha", "under construction", "other"

impersonatedBrand

Targeted brand impersonation

impersonatedBrand="Netflix" OR impersonatedBrand="Facebook"

impersonatedBrandsHigh, impersonatedBrandsMedium

Brand impersonation level

impersonatedBrandsHigh="Apple" OR impersonatedBrandsMedium="Microsoft"

companiesMentioned

Companies mentioned in the HTML or screenshot

companiesMentioned="Amazon" OR companiesMentioned="Tesla"

companyLogo

Detected company logos

companyLogo="paypal" OR companyLogo="visa"

languages

Languages present in the content

languages="english" OR languages="spanish" OR languages="french" OR languages="portuguese"

predominantLanguage

Predominant language in the content

predominantLanguage="english" OR predominantLanguage="spanish"

imageDescription

Image description (Available in English)

imageDescription="yellow background" AND imageDescription="casino"

predominantColor

Predominant color in text format

predominantColorHex="orange"

predominantColorHex

Predominant color in hexadecimal format

predominantColorHex="#FE3131"

predominantColorRGB

Predominant color in RGB

predominantColorRGB="[254, 49, 49]"

contentHTML

Search by textual content of the page

htmlLinks

Search by links contained on the page


3. Technical URL Analysis

Parameter

Description

Example

referenceIp

IP associated with the reference

referenceIp="45.67.89.101"

protocol

URL protocol

protocol="http" OR protocol="ftp"

queryStrings

URL query parameters

queryStrings="?sessionid=abcd1234"

httpStatus

HTTP response status code

httpStatus=404 OR httpStatus=503

redirectedTo

URL where redirection occurred

finalUrl

Final URL after redirections


4. WHOIS Data (Domain Registration)

Parameter

Description

Example

domainStatus

Current domain status

domainStatus="suspended"

registrant, registrantOrganization, registrantEmail

Registrant information

registrant="Anonymous" OR registrantEmail="[email protected]"

administrator, administratorOrganization, administratorEmail

Domain administrator information

administrator="John Doe" OR administratorEmail="[email protected]"

technical, technicalOrganization, technicalEmail

Technical contact information

technical="Tech Support" OR technicalEmail="[email protected]"

registrar, registrarEmail

Domain registrar company

registrar="Namecheap" OR registrarEmail="[email protected]"

nameServers

List of name servers

nameServers="ns1.fake-dns.com" OR nameServers="ns2.fake-dns.com"

ipAddresses

IP addresses associated with name servers

ipAddresses="185.199.108.153"


5. DNS Records & Infrastructure

Parameter

Description

Example

dnsRecordType (A)

IPv4 address record for the domain

dnsRecordType="A" AND dnsRecordValue="192.0.2.1"

dnsRecordType (AAAA)

IPv6 address record for the domain

dnsRecordType="AAAA" AND dnsRecordValue="2001:db8::1"

dnsRecordType (CNAME)

Canonical name record (alias for another domain)

dnsRecordType="CNAME" AND dnsRecordValue="example.com"

dnsRecordType (NS)

Name server record, indicating authoritative DNS servers

dnsRecordType="NS" AND dnsRecordValue="ns1.example.com"

dnsRecordType (MX)

Mail exchange record, specifying mail servers for the domain

dnsRecordType="MX" AND dnsRecordValue="mail.example.com"

ipAddresses

IP addresses associated with name servers

ipAddresses="185.199.108.153"


6. How to search for Geolocation information?

Parameter

Description

Example

geolocationCountryName

Indicates the country where the server is located.

geolocationCountryName="United States"

geolocationCountryCode

Indicates the country code where the server is located.

geolocationCountryCode="CN"

geolocationIp

Geolocation IP

geolocationIp = "203.0.113.45"

latitude

Represents the latitude coordinate of the estimated IP location.

latitude="54.6876"

longitude

Represents the longitude coordinate of the estimated IP location.

longitude="25.2806"

isp

Server related to the reference.

isp=Cloudflare


7. How can I search for signal data from the 'facebook-ads-coll' source in the Meta Ad Library?

Parameter

Description

Example

metaAdId

Ad ID

metaAdId=24286785267571234

metaAdUrl

Ad URL

metaAdvertiserProfiles

Advertiser profile

metaProfileId

Profile ID

metaProfileId=123489169657887

metaProfileName

Profile Name

metaProfileName="Discount Store"


If you have any questions, feel free to reach out at [email protected] 😊

Did this answer your question?