← OSINT Collection — Sources, Tradecraft, and Analyst OPSEC

Module Quiz

10 questions · Pass at 80%

Question 1 of 10

An analyst receives an IP address from an incident report and wants to map the threat actor's infrastructure. After querying passive DNS for historical domains resolving to that IP, what is the MOST productive next step?