Endpoint map
Result limits depend on the account and endpoint. Use response metadata instead of assuming every route returns 100 results.
Which endpoint should I use?
- Start with IP Lookup for network, provider, and associated context.
- Add Tor Lookup when the investigation needs a Tor exit-node observation.
- Use Passive DNS to find historical hostname relationships.
- Use Cloud TLS Certificates to pivot through certificate DNS names.
- Use Domain Collection for company-to-domain and domain-to-company research.
- Use WHOIS Lookup and Search for registration and nameserver pivots.
Authentication
Investigation guidance
- Preserve the original indicator and response timestamp.
- Record each Nexus observation independently.
- Treat organization and ownership fields as evidence requiring corroboration.
- Cache stable registration data according to your freshness requirements.
- Deduplicate repeated records before creating tickets or alerts.
