Evidence Input
| IP | ASN | Prefix | Country | Registry | Allocated | AS Name |
|---|
IP RDAP / WHOIS
Lookup Sources
ASN
Team Cymru bulk whois service: whois.cymru.com:43
IP Registration
IANA RDAP bootstrap is used to route each IP to ARIN, RIPE NCC, APNIC, LACNIC, AFRINIC, or an indicated NIR/referral source.
DNS
The server resolver queries A, AAAA, CNAME, MX, NS, TXT, SOA, CAA, and SRV records.
How Registry Lens Works
Registry Lens turns pasted indicators from logs into network, DNS, and registration context. It extracts IP addresses and domains, then performs live lookups against public infrastructure data sources.
IP Path
- Extract valid IPv4 and IPv6 addresses
- Query Team Cymru for ASN and prefix data
- Use IANA RDAP bootstrap to find the correct RIR/NIR
- Fetch RDAP registration details and contacts
Domain Path
- Extract domains and hostnames from text
- Query DNS records and parent-domain context
- Fetch domain registration data using RDAP or WHOIS
- Send resolved A/AAAA IPs through the IP path
What The Results Mean
ASN
Shows the network announcing or associated with an IP prefix. This is routing context, not necessarily the end customer.
IP RDAP / WHOIS
Shows registration data from ARIN, RIPE NCC, APNIC, LACNIC, AFRINIC, or a referred NIR where available.
Domain Registration
Shows registrar, dates, status, nameservers, and contacts from domain RDAP or WHOIS fallback.
Data Sources
- Team Cymru bulk whois service for IP-to-ASN lookups.
- IANA RDAP bootstrap files for routing IP and domain RDAP requests.
- RIR and NIR RDAP services for IP registration data.
- TLD RDAP and WHOIS servers for domain registration data.
- The server DNS resolver for DNS record lookups.
Limitations
- Results are live and can change over time.
- External services may timeout, rate-limit, redact fields, or return referral records.
- DNS answers may vary by resolver, geography, and TTL.
- ASN data, IP registration data, and domain registration data answer different questions.
Credits
Registry Lens was developed by Adli Wahid.
Contact: adli@apnic.net