Map domains pointing to your IP ranges or cloud accounts to uncover shadow IT, third-party assets, and external exposure that silently expand your attack surface. Combine DNS data with domain records to see your full perimeter from the outside.
Your attack surface isn't what your CMDB says — it's what the internet sees. Forgotten marketing sites on old IPs, dev buckets with dangling DNS, vendor subdomains pointing to your ranges, and shadow IT spun up in a branch cloud account never make it into the asset inventory. Primitive Host maps domains that resolve to your IP ranges and cloud accounts using 276M+ DNS-enriched records. You see every externally reachable name tied to your infrastructure, with NS, MX, A, CNAME and TXT to prioritize. Track drift daily, prove perimeter reduction to auditors, and stop attackers finding what you forgot.
What you can do
External Perimeter Inventory
Enumerate every domain pointing at your ranges from an attacker's perspective — not your CMDB.
Shadow IT & Dangling DNS
Find forgotten dev, staging and marketing hosts that expand exposure and enable takeover.
Third-Party Risk Mapping
Map vendor and subsidiary domains sharing your infrastructure for supply-chain reviews.
Key features
- Discover all domains resolving to your IP ranges and cloud accounts
- Identify shadow IT, forgotten subdomains and dangling DNS
- Map third-party assets and vendor dependencies by DNS footprint
- DNS-enriched records: NS, MX, A, CNAME, and TXT with daily refresh
- Track infrastructure changes over time for drift detection and audit proof
GET /v1/domains?ip_range=198.51.100.0/24
Authorization: Bearer <token>
{
"ip": "198.51.100.42",
"domains": ["legacy-app.example.com", "old-marketing.example.com"],
"total": 17
}