dns-whois

Query DNS, WHOIS, ASN, and ownership data using local CLI tools.

81|14|Updated Jul 8, 2026
One-click install
npx skills add https://github.com/guaidao2/XuanMu-RedTeam-Agent --skill dns-whois
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dns-whois
Source: https://github.com/guaidao2/XuanMu-RedTeam-Agent/tree/main/sandbox/.agents/skills/dns-whois
Command: npx skills add https://github.com/guaidao2/XuanMu-RedTeam-Agent --skill dns-whois

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill streamlines authorized DNS, WHOIS, ASN, mail, nameserver, and ownership triage by applying targeted queries, evidence validation, and clear reporting practices.

Core Features & Use Cases

  • DNS Investigation: Query records for domains, hosts, nameservers, mail infrastructure, and related indicators using local command-line tools.
  • Ownership Triage: Examine WHOIS, registry, delegation, resolution, and ASN signals while accounting for stale, proxied, incomplete, or privacy-protected data.
  • Evidence Reporting: Capture queried identifiers, commands, query times, relevant results, confidence levels, output paths, and unresolved conflicts for authorized security assessments.

Quick Start

Use the dns-whois skill to investigate the DNS records, registration details, nameservers, and ownership signals for an in-scope domain and summarize the evidence with confidence and query time.

Frequently Asked Questions about dns-whois

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage DNS and WHOIS intelligence for a domain during security assessments?

Triage DNS and WHOIS intelligence by applying targeted queries to local CLI tools, validating evidence, and reporting confidence levels with query times. Investigate DNS records, registration details, nameservers, and ownership signals for in-scope domains.

Can I perform ASN lookup and nameserver analysis using local command-line tools?

Yes, ASN lookup and nameserver analysis are performed using local command-line tools like dig, nslookup, and whois. The Skill executes targeted queries against these tools to gather registry, delegation, and resolution signals for infrastructure assessment.

What is the best way to handle privacy-protected or stale WHOIS data in domain ownership verification?

Domain ownership verification handles privacy-protected or stale WHOIS data by examining WHOIS, registry, delegation, and ASN signals while accounting for data uncertainty, validating evidence, and reporting confidence levels with unresolved conflicts for authorized security triage.

Do I need local dig and whois tools installed to use this domain intelligence workflow?

Yes, local dig, nslookup, whois, and related CLI tools are required. The domain intelligence workflow depends on these local command-line utilities to execute targeted queries, record evidence, validate results, and report uncertainty for scoped security assessments.

How does evidence reporting work for DNS and mail infrastructure investigations?

Evidence reporting for DNS and mail infrastructure investigations captures queried identifiers, executed commands, query times, relevant results, confidence levels, output paths, and unresolved conflicts to provide validated documentation for authorized security assessments.

Why does WHOIS ownership triage sometimes report incomplete or proxied registration data?

WHOIS ownership triage reports incomplete or proxied registration data because privacy protection services and stale registry records obscure true ownership. The Skill accounts for these limitations by validating evidence and reporting confidence levels with unresolved conflicts.