Network Investigation Lab

Normalize domains, URLs, IPs, and CIDRs, compare DNS snapshots locally, save evidence, and continue into DNS, WHOIS, TLS, PCAP, and firewall tools.

Advertisement

One target, one investigation context

Network Investigation Lab normalizes a domain, IP address, CIDR, or HTTP URL and classifies special-use scope before you move into focused network tools. It does not silently scan a target or relay unrestricted requests through a server.

Compare evidence without a lookup

Paste bounded before-and-after DNS answer snapshots to identify added, removed, and TTL-only changes. Save normalized findings, notes, and tags as a local JSON evidence record, then continue into DNS, WHOIS, reputation, TLS, packet, subnet, redirect, and firewall analysis.

Frequently Asked Questions

Does the lab scan a domain or IP address?+

No. Target normalization and DNS snapshot comparison are local. Live DNS, WHOIS, reputation, redirect, or TLS activity occurs only after you explicitly open a focused lookup tool.

Which target formats are supported?+

Enter an HTTP or HTTPS URL, a domain name, an IPv4 or IPv6 address, or an IPv4/IPv6 CIDR. The lab identifies private, loopback, link-local, multicast, and documentation ranges.

What DNS formats can I compare?+

The parser accepts common dig answer lines, zone-style records, and normalized whitespace-separated records for A, AAAA, CNAME, MX, TXT, NS, SOA, CAA, SRV, PTR, DS, DNSKEY, and TLSA.

Related tools

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.