Search history¶
Search history provides a visual graph of your investigation, showing all searches, pivots, and branches. Navigate through your investigation, annotate key findings, and organize domains with tags.
Navigate with search history¶
Each time you pivot on your results, Iris Investigate moves your investigation forward to a new node in your Search History. Each new node connects to its originating node with a line/edge.

Visual indicators¶
The search history graph uses color coding and icons to convey information:
| Indicator | Meaning |
|---|---|
| Green nodes | Your active investigation path |
| Orange nodes | Searches outside of your active investigation path |
| Blue 'document' icon nodes | Passive DNS results |
| Number bubbles | Count of search notes on a node |
| Star icon | Nodes marked as important |
Keyboard shortcuts¶
- Toggle fullscreen mode: Press
h - Complete list of shortcuts: Visit https://iris.domaintools.com/investigate/help/
Navigate your investigation¶
Return to previous searches¶
- Locate the node in the search history graph.
- Select the node.
- Iris Investigate loads the Pivot Engine and Data Panels for that query.
Create new branches¶
Continue with new pivots from any node, and Iris Investigate creates a new branch. This allows you to:
- Explore alternative hypotheses
- Investigate different aspects of a domain
- Organize complex investigations
To create a new, empty history branch:
- Select the + button near the top right corner of the Pivot Engine.
- Your next query becomes the root node of the new branch.
To start a new branch with the current node as the root:
- Select Manage History.
- Select New History Branch.
- Select Start it with the Current Search.
Delete nodes and branches¶
Warning: Once you delete a node or a branch, you can't recover it.
To delete:
- Locate the node or branch in the search history graph.
- Select the delete option.
- Confirm deletion.
Annotate with the search node drawer¶
Hovering over a search node invokes the search node drawer, which provides annotation options:

Mark as important¶
Highlight critical nodes in your investigation:
- Hover over a search node.
- Select Mark as Important.
- The node displays a star icon.
Use this feature to:
- Flag key findings
- Mark nodes for follow-up
- Highlight significant pivots
Export search hash¶
Share specific searches with others:
- Hover over a search node.
- Select the export icon.
- The search hash copies to your clipboard.
Search hashes reproduce search terms but don't include tags or other investigation-specific information. For more details, see Search Hashes.
Add search notes¶
Document your analysis and findings:
- Hover over a search node.
- Select the notes icon or Search Notes section.
- Enter your notes.
- Save.
When notes exist for a node, a number bubble on the node indicates the note count.
Interactive notes¶
Enter an IP address, domain name, or email address in your notes, and Iris Investigate enables Operations Menus to search or filter directly from the notes. This allows you to:
- Pivot on values mentioned in notes
- Create new searches from documented findings
- Link notes to investigation actions
Tag domains and share tags¶
Tags attach to domains, include an editable description field, and can be modified by the Iris Investigate APIs. Edit, search, and filter by tag.
Tag use cases¶
Apply tags to support:
- Attribution labeling - Identify threat actors or campaigns
- Threat profile type - Categorize by malware family, phishing, etc.
- Operational status - Mark as active, monitoring, resolved
- Case inclusion - Associate with specific incidents or tickets
- Triage status - Track investigation progress
- Programmatic decision-making - Enable automated workflows
Access tags¶
Tags are available in multiple locations:
Pivot Engine:
- Select one or multiple domains.
- Select the Tag button.
- Add, edit, or remove tags.
- Optionally export tags.
Operations Menu:
- Right-click a domain.
- Select Edit Tags.
- Modify tags for that domain.
Tag Manager:
- Open the Product Menu.
- Select Tag Manager.
- View all tags from your investigations and group.
Stats Data Panel:
- Visualizes tag distribution across your result set
- Shows tag counts and relationships
Tag sharing¶
Your tags automatically share with other users in your group. This enables:
- Consistent categorization across the team
- Shared threat intelligence
- Collaborative analysis
Your investigations are private by default, but tags are visible to your group regardless of investigation sharing status.
If you export a Search Hash to a user outside of your group, your tags aren't visible to them.
Tag Manager¶

The Tag Manager displays:
- All tags you've created
- Tags used by your group
- Domains associated with each tag
- Tag descriptions
Use the Tag Manager to:
- Review tag usage across investigations
- Find domains by tag
- Edit or delete tags
- Maintain consistent tagging practices
Best practices¶
Annotation strategy¶
- Mark important nodes - Flag key findings as you discover them
- Add context in notes - Document why a node is significant
- Use consistent tagging - Establish team tagging conventions
- Export key searches - Share search hashes for reproducibility
Organization tips¶
- Create branches for different hypotheses - Keep investigation paths separate
- Delete dead ends - Remove unsuccessful branches to reduce clutter
- Name investigations descriptively - Make it easy to find later
- Regular review - Periodically review and clean up old investigations
Collaboration¶
- Share tags liberally - Help your team benefit from your analysis
- Document in notes - Explain your reasoning for future reference
- Mark important findings - Draw attention to critical discoveries
- Export search hashes - Enable others to reproduce your searches
Next steps¶
- Collaboration: Share investigations and export results
- Tag Manager: Manage tags across investigations
- Stats Panel: Visualize tag distribution