Skip to main content

Cross-search (pipeline)

Cross-search is the engine behind several Profundis tools. It chains searches across datasets (hosts, DNS, WHOIS and certificates) and feeds the results of one step into the next, so you can follow a relationship across datasets in a single run instead of copying values between separate searches by hand.

note

The tools below provide the web interface. Their signed-in requests use the internal pipeline route; this page is a guide to the tools, not a supported public API schema.

You use it through the tools built on top of it:

  • Registrant Explorer: start from an organization name and pull back its domains, hosts and DNS records.
  • Entity Intelligence Hub: start from a root domain or company name and map its hosts, certificates, domains, nameservers and IPs.
  • Threat Graph: expand a node (domain, IP, certificate, nameserver, ASN, analytics tag or registrar) to pull in related assets.
  • Domain Portfolio Analyzer: compare up to 10 domains across their infrastructure and technology.

What it does​

Cross-search runs a sequence of steps. Each step searches one dataset, then passes selected values from its results into the next step's search. Following that chain lets you move from one kind of asset to another without writing a single query yourself.

A couple of examples, in words:

  • Start from an organization in WHOIS, collect the domains it registered, then look up the hosts behind those domains. You go from a company name to its live infrastructure in one run. This needs a paid plan or purchased credits (see below).
  • Start from a domain's private nameservers, then find other domains that use the same nameservers. That surfaces related assets that share hosting setup but don't share an obvious name.

Limits​

Signed-in personal accounts can use cross-search in the web app, including Free accounts. API-token access has a separate entitlement requirement. Organization members use the selected organization and client with their shared budget. The depth of a personal run depends on the plan.

Free / SoloProfessional
Steps per run35
Results per step1550
Chained values between steps20100
Aggregation buckets1050
Load more on large result sets-yes

Cross-search spends 1 credit per step. See the Credits page for details.

Which WHOIS fields can a Free account use?​

On a Free account without purchased credits, WHOIS steps use public fields only:

  • A WHOIS step can filter, extract values or aggregate on domain, registrar_name, nameservers and expiration_date only. A step that uses another WHOIS field, such as registrant_organization or registrant_email, is refused before any credit is charged.
  • WHOIS results show only the domain, registrar, name servers, expiration date and observation date.

A paid plan or purchased credits remove this restriction. Lookalike domains searches WHOIS by domain name only, so it works on a Free account. A company-name search in Find an organization's domains matches registrant fields, so its WHOIS part needs a paid plan or purchased credits.

Frequent questions​

No. Any logged-in user can use the tools built on cross-search. Professional raises the limits in the table above and adds Load more on large result sets. Solo retains the reduced pipeline limits. Without a paid plan or purchased credits, WHOIS steps are limited to public fields. Some individual tools have their own access rules, listed on their own pages.

What happens when a step returns no results?​

The run continues. Later steps receive no input, so their results are empty, but the run still completes and shows you each step's output. That lets you see where the chain stopped.

Can the same dataset appear in more than one step?​

Yes. A common pattern is WHOIS then WHOIS: take a domain's nameservers, then find other domains that use the same nameservers.

How much does a run cost?​

One credit per step. A 3-step run costs 3 credits, a 5-step run costs 5. See Credits.