wtfis
« Back to VersTracker
Description:
Passive hostname, domain, and IP lookup tool
Type: Formula  |  Latest Version: 0.14.0@2  |  Tracked Since: Dec 3, 2025
Links: Homepage  |  formulae.brew.sh
Category: Security
Tags: security threat-intelligence reconnaissance cli dns whois
Install: brew install wtfis
About:
wtfis is a command-line tool that performs passive DNS and WHOIS lookups to investigate hostnames, domains, and IP addresses. It aggregates data from multiple sources like VirusTotal and Shodan to provide comprehensive threat intelligence and ownership details. The tool helps security professionals quickly assess the reputation and context of potentially malicious infrastructure.
Key Features:
  • Multi-source intelligence aggregation (VirusTotal, Shodan, WHOIS)
  • Rich domain and IP reputation data
  • Clean CLI output with colorized formatting
  • No active scanning (passive reconnaissance only)
Use Cases:
  • Investigating suspicious emails and phishing domains
  • Threat intelligence research and IOC enrichment
  • Security incident response and forensics
  • Reconnaissance during penetration testing
Alternatives:
  • whois – Basic WHOIS lookup tool without threat intelligence
  • dig – DNS resolution tool, lacks enrichment data
  • urlscan – Web-based scanner with active probing
Version History
Detected Version Rev Change Commit
Jan 11, 2026 8:25am 2 REVISION_ONLY ce7ff6b0
Dec 3, 2025 11:38am 0 VERSION_BUMP 9ebacc8f
Nov 1, 2025 11:49pm 0 VERSION_BUMP 94216708
Nov 1, 2025 3:23pm 0 VERSION_BUMP f0066e21
Oct 12, 2025 10:21am 0 VERSION_BUMP 37f29a7c