The problem
When a security team finds a phishing page or a malware host, the slow part is rarely the detection. It is working out who can actually take the content down: the registrar, the hosting network, or a CDN that is only forwarding traffic. That means WHOIS or RDAP lookups against the registry, a separate query to the right Regional Internet Registry for each IP, and a judgement call about whether a Cloudflare or Fastly address is the real host. The free ACID Tool on this site's work page answers that question for one domain at a time in a browser. Security teams asked for the same answer as structured data they could call from their own tooling, at volume, with consistent output.
