Skip to main content

DomainTools Iris

This Integration is part of the DomainTools Iris Investigate Pack.#

DomainTools Iris Playbook#


Configure DomainTools Iris on Cortex XSOAR#


  1. Navigate to Settings > Integrations > Servers & Services.
  2. Search for DomainTools Iris.
  3. Click Add instance to create and configure a new integration instance.
    • Name: a textual name for the integration instance.
    • API Username
    • API Key
    • High-Risk Threshold
    • Young Domain Timeframe (within Days)
    • Trust any certificate (not secure)
    • Use system proxy settings
  4. Click Test to validate the URLs, token, and connection.

Fetched Incidents Data#


Commands#


You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

  1. domain
  2. domaintoolsiris-analytics
  3. domaintoolsiris-threat-profile
  4. domaintoolsiris-pivot

1. domain#


Get a complete profile of the domain provided.

Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.

Base Command#

domain

Input#
Argument NameDescriptionRequired
domainDomain nameRequired
Context Output#
PathTypeDescription
Domain.NameStringDomain Name
Domain.DNSStringDomain DNS
Domain.DomainStatusBooleanDomain Status
Domain.CreationDateDateDomain Creation Date
Domain.ExpirationDateDateDomain Expiration Date
Domain.NameServersStringDomain NameServers
Domain.Registrant.CountryStringDomain Registrant Country
Domain.Registrant.EmailStringDomain Registrant Email
Domain.Registrant.NameStringDomain Registrant Name
Domain.Registrant.PhoneStringDomain Registrant Phone
Domain.Malicious.VendorStringVendor that saw domain as malicious
Domain.Malicious.DescriptionStringDescription of why domain was found to be malicious
DomainTools.Domains.NameStringDomainTools Domain Name
DomainTools.Domains.LastEnrichedDateLast Time DomainTools Enriched Domain Data
DomainTools.Domains.Analytics.OverallRiskScoreNumberDomainTools Overall Risk Score
DomainTools.Domains.Analytics.ProximityRiskScoreNumberDomainTools Proximity Risk Score
DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScoreNumberDomainTools Threat Profile Risk Score
DomainTools.Domains.Analytics.ThreatProfileRiskScore.ThreatsStringDomainTools Threat Profile Threats
DomainTools.Domains.Analytics.ThreatProfileRiskScore.EvidenceStringDomainTools Threat Profile Evidence
DomainTools.Domains.Analytics.WebsiteResponseCodeNumberWebsite Response Code
DomainTools.Domains.Analytics.AlexaRankNumberAlexa Rank
DomainTools.Domains.Analytics.TagsStringDomainTools Tags
DomainTools.Domains.Identity.RegistrantNameStringRegistrant Name
DomainTools.Domains.Identity.RegistrantOrgStringRegistrant Org
DomainTools.Domains.Identity.RegistrantContact.Country.valueStringRegistrant Contact Country value
DomainTools.Domains.Identity.RegistrantContact.Country.countNumberRegistrant Contact Country count
DomainTools.Domains.Identity.RegistrantContact.Email.valueStringRegistrant Contact Email value
DomainTools.Domains.Identity.RegistrantContact.Email.countNumberRegistrant Contact Email count
DomainTools.Domains.Identity.RegistrantContact.Name.valueStringRegistrant Contact Name value
DomainTools.Domains.Identity.RegistrantContact.Name.countNumberRegistrant Contact Name count
DomainTools.Domains.Identity.RegistrantContact.Phone.valueStringRegistrant Contact Phone value
DomainTools.Domains.Identity.RegistrantContact.Phone.countNumberRegistrant Contact Phone count
DomainTools.Domains.Identity.SOAEmailStringSOA Record Email
DomainTools.Domains.Identity.SSLCertificateEmailStringSSL Certificate Email
DomainTools.Domains.Identity.AdminContact.Country.valueStringAdmin Contact Country value
DomainTools.Domains.Identity.AdminContact.Country.countNumberAdmin Contact Country count
DomainTools.Domains.Identity.AdminContact.Email.valueStringAdmin Contact Email value
DomainTools.Domains.Identity.AdminContact.Email.countNumberAdmin Contact Email count
DomainTools.Domains.Identity.AdminContact.Name.valueStringAdmin Contact Name value
DomainTools.Domains.Identity.AdminContact.Name.countNumberAdmin Contact Name count
DomainTools.Domains.Identity.AdminContact.Phone.valueStringAdmin Contact Phone value
DomainTools.Domains.Identity.AdminContact.Phone.countNumberAdmin Contact Phone count
DomainTools.Domains.Identity.TechnicalContact.Country.valueStringTechnical Contact Country value
DomainTools.Domains.Identity.TechnicalContact.Country.countNumberTechnical Contact Country count
DomainTools.Domains.Identity.TechnicalContact.Email.valueStringTechnical Contact Email value
DomainTools.Domains.Identity.TechnicalContact.Email.countNumberTechnical Contact Email count
DomainTools.Domains.Identity.TechnicalContact.Name.valueStringTechnical Contact Name value
DomainTools.Domains.Identity.TechnicalContact.Name.countNumberTechnical Contact Name count
DomainTools.Domains.Identity.TechnicalContact.Phone.valueStringTechnical Contact Phone value
DomainTools.Domains.Identity.TechnicalContact.Phone.countNumberTechnical Contact Phone count
DomainTools.Domains.Identity.BillingContact.Country.valueStringBilling Contact Country value
DomainTools.Domains.Identity.BillingContact.Country.countNumberBilling Contact Country count
DomainTools.Domains.Identity.BillingContact.Email.valueStringBilling Contact Email value
DomainTools.Domains.Identity.BillingContact.Email.countNumberBilling Contact Email count
DomainTools.Domains.Identity.BillingContact.Name.valueStringBilling Contact Name value
DomainTools.Domains.Identity.BillingContact.Name.countNumberBilling Contact Name count
DomainTools.Domains.Identity.BillingContact.Phone.valueStringBilling Contact Phone value
DomainTools.Domains.Identity.BillingContact.Phone.countNumberBilling Contact Phone count
DomainTools.Domains.Identity.EmailDomainsStringEmail Domains
DomainTools.Domains.Identity.AdditionalWhoisEmails.valueStringAdditional Whois Emails value
DomainTools.Domains.Identity.AdditionalWhoisEmails.countNumberAdditional Whois Emails count
DomainTools.Domains.Registration.DomainRegistrantStringDomain Registrant
DomainTools.Domains.Registration.RegistrarStatusStringRegistrar Status
DomainTools.Domains.Registration.DomainStatusBooleanDomain Active Status
DomainTools.Domains.Registration.CreateDateDateCreate Date
DomainTools.Domains.Registration.ExpirationDateDateExpiration Date
DomainTools.Domains.Hosting.IPAddresses.address.valueStringIP Addresses Info address value
DomainTools.Domains.Hosting.IPAddresses.address.countNumberIP Addresses Info address count
DomainTools.Domains.Hosting.IPAddresses.asn.valueStringIP Addresses Info asn value
DomainTools.Domains.Hosting.IPAddresses.asn.countNumberIP Addresses Info asn count
DomainTools.Domains.Hosting.IPAddresses.country_code.valueStringIP Addresses Info country_code value
DomainTools.Domains.Hosting.IPAddresses.country_code.countNumberIP Addresses Info country_code count
DomainTools.Domains.Hosting.IPAddresses.isp.valueStringIP Addresses Info isp value
DomainTools.Domains.Hosting.IPAddresses.isp.countNumberIP Addresses Info isp count
DomainTools.Domains.Hosting.IPCountryCodeStringIP Country Code
DomainTools.Domains.Hosting.MailServers.domain.valueStringMail Servers Info domain value
DomainTools.Domains.Hosting.MailServers.domain.countNumberMail Servers Info domain count
DomainTools.Domains.Hosting.MailServers.host.valueStringMail Servers Info host value
DomainTools.Domains.Hosting.MailServers.host.countNumberMail Servers Info host count
DomainTools.Domains.Hosting.MailServers.ip.valueStringMail Servers Info ip value
DomainTools.Domains.Hosting.MailServers.ip.countNumberMail Servers Info ip count
DomainTools.Domains.Hosting.SPFRecordStringSPF Record Info
DomainTools.Domains.Hosting.NameServers.domain.valueStringDomainTools Domains NameServers domain value
DomainTools.Domains.Hosting.NameServers.domain.countNumberDomainTools Domains NameServers domain count
DomainTools.Domains.Hosting.NameServers.host.valueStringDomainTools Domains NameServers host value
DomainTools.Domains.Hosting.NameServers.host.countNumberDomainTools Domains NameServers host count
DomainTools.Domains.Hosting.NameServers.ip.valueStringDomainTools Domains NameServers ip value
DomainTools.Domains.Hosting.NameServers.ip.countNumberDomainTools Domains NameServers ip count
DomainTools.Domains.Hosting.SSLCertificate.hash.valueStringSSL Certificate Info hash value
DomainTools.Domains.Hosting.SSLCertificate.hash.countNumberSSL Certificate Info hash count
DomainTools.Domains.Hosting.SSLCertificate.organization.valueStringSSL Certificate Info organization value
DomainTools.Domains.Hosting.SSLCertificate.organization.countNumberSSL Certificate Info organization count
DomainTools.Domains.Hosting.SSLCertificate.subject.valueStringSSL Certificate Info subject value
DomainTools.Domains.Hosting.SSLCertificate.subject.countNumberSSL Certificate Info subject count
DomainTools.Domains.Hosting.RedirectsTo.valueStringDomains it Redirects To value
DomainTools.Domains.Hosting.RedirectsTo.countNumberDomains it Redirects To count
DomainTools.Domains.Analytics.GoogleAdsenseTrackingCodeNumberGoogle Adsense Tracking Code
DomainTools.Domains.Analytics.GoogleAnalyticTrackingCodeNumberGoogle Analytics Tracking Code
DBotScore.IndicatorStringDBotScore Indicator
DBotScore.TypeStringDBotScore Indicator Type
DBotScore.VendorStringVendor used to calculate the score
DBotScore.ScoreNumberThe actual score
Command Example#

!domain domain=demisto.com

Context Example#
Human Readable Output#

2. domaintoolsiris-analytics#


Provides markdown table with DomainTools Analytic data

Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.

Base Command#

domaintoolsiris-analytics

Input#
Argument NameDescriptionRequired
domainDomain nameRequired
Context Output#
PathTypeDescription
Domain.NameStringDomain Name
Domain.DNSStringDomain DNS
Domain.DomainStatusBooleanDomain Status
Domain.CreationDateDateDomain Creation Date
Domain.ExpirationDateDateDomain Expiration Date
Domain.NameServersStringDomain NameServers
Domain.Registrant.CountryStringDomain Registrant Country
Domain.Registrant.EmailStringDomain Registrant Email
Domain.Registrant.NameStringDomain Registrant Name
Domain.Registrant.PhoneStringDomain Registrant Phone
Domain.Malicious.VendorStringVendor that saw domain as malicious
Domain.Malicious.DescriptionStringDescription of why domain was found to be malicious
DomainTools.Domains.NameStringDomainTools Domain Name
DomainTools.Domains.LastEnrichedDateLast Time DomainTools Enriched Domain Data
DomainTools.Domains.Analytics.OverallRiskScoreNumberDomainTools Overall Risk Score
DomainTools.Domains.Analytics.ProximityRiskScoreNumberDomainTools Proximity Risk Score
DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScoreNumberDomainTools Threat Profile Risk Score
DomainTools.Domains.Analytics.ThreatProfileRiskScore.ThreatsStringDomainTools Threat Profile Threats
DomainTools.Domains.Analytics.ThreatProfileRiskScore.EvidenceStringDomainTools Threat Profile Evidence
DomainTools.Domains.Analytics.WebsiteResponseCodeNumberWebsite Response Code
DomainTools.Domains.Analytics.AlexaRankNumberAlexa Rank
DomainTools.Domains.Analytics.TagsStringDomainTools Tags
DomainTools.Domains.Identity.RegistrantNameStringRegistrant Name
DomainTools.Domains.Identity.RegistrantOrgStringRegistrant Org
DomainTools.Domains.Identity.RegistrantContact.Country.valueStringRegistrant Contact Country value
DomainTools.Domains.Identity.RegistrantContact.Country.countNumberRegistrant Contact Country count
DomainTools.Domains.Identity.RegistrantContact.Email.valueStringRegistrant Contact Email value
DomainTools.Domains.Identity.RegistrantContact.Email.countNumberRegistrant Contact Email count
DomainTools.Domains.Identity.RegistrantContact.Name.valueStringRegistrant Contact Name value
DomainTools.Domains.Identity.RegistrantContact.Name.countNumberRegistrant Contact Name count
DomainTools.Domains.Identity.RegistrantContact.Phone.valueStringRegistrant Contact Phone value
DomainTools.Domains.Identity.RegistrantContact.Phone.countNumberRegistrant Contact Phone count
DomainTools.Domains.Identity.SOAEmailStringSOA Record Email
DomainTools.Domains.Identity.SSLCertificateEmailStringSSL Certificate Email
DomainTools.Domains.Identity.AdminContact.Country.valueStringAdmin Contact Country value
DomainTools.Domains.Identity.AdminContact.Country.countNumberAdmin Contact Country count
DomainTools.Domains.Identity.AdminContact.Email.valueStringAdmin Contact Email value
DomainTools.Domains.Identity.AdminContact.Email.countNumberAdmin Contact Email count
DomainTools.Domains.Identity.AdminContact.Name.valueStringAdmin Contact Name value
DomainTools.Domains.Identity.AdminContact.Name.countNumberAdmin Contact Name count
DomainTools.Domains.Identity.AdminContact.Phone.valueStringAdmin Contact Phone value
DomainTools.Domains.Identity.AdminContact.Phone.countNumberAdmin Contact Phone count
DomainTools.Domains.Identity.TechnicalContact.Country.valueStringTechnical Contact Country value
DomainTools.Domains.Identity.TechnicalContact.Country.countNumberTechnical Contact Country count
DomainTools.Domains.Identity.TechnicalContact.Email.valueStringTechnical Contact Email value
DomainTools.Domains.Identity.TechnicalContact.Email.countNumberTechnical Contact Email count
DomainTools.Domains.Identity.TechnicalContact.Name.valueStringTechnical Contact Name value
DomainTools.Domains.Identity.TechnicalContact.Name.countNumberTechnical Contact Name count
DomainTools.Domains.Identity.TechnicalContact.Phone.valueStringTechnical Contact Phone value
DomainTools.Domains.Identity.TechnicalContact.Phone.countNumberTechnical Contact Phone count
DomainTools.Domains.Identity.BillingContact.Country.valueStringBilling Contact Country value
DomainTools.Domains.Identity.BillingContact.Country.countNumberBilling Contact Country count
DomainTools.Domains.Identity.BillingContact.Email.valueStringBilling Contact Email value
DomainTools.Domains.Identity.BillingContact.Email.countNumberBilling Contact Email count
DomainTools.Domains.Identity.BillingContact.Name.valueStringBilling Contact Name value
DomainTools.Domains.Identity.BillingContact.Name.countNumberBilling Contact Name count
DomainTools.Domains.Identity.BillingContact.Phone.valueStringBilling Contact Phone value
DomainTools.Domains.Identity.BillingContact.Phone.countNumberBilling Contact Phone count
DomainTools.Domains.Identity.EmailDomainsStringEmail Domains
DomainTools.Domains.Identity.AdditionalWhoisEmails.valueStringAdditional Whois Emails value
DomainTools.Domains.Identity.AdditionalWhoisEmails.countNumberAdditional Whois Emails count
DomainTools.Domains.Registration.DomainRegistrantStringDomain Registrant
DomainTools.Domains.Registration.RegistrarStatusStringRegistrar Status
DomainTools.Domains.Registration.DomainStatusBooleanDomain Active Status
DomainTools.Domains.Registration.CreateDateDateCreate Date
DomainTools.Domains.Registration.ExpirationDateDateExpiration Date
DomainTools.Domains.Hosting.IPAddresses.address.valueStringIP Addresses Info address value
DomainTools.Domains.Hosting.IPAddresses.address.countNumberIP Addresses Info address count
DomainTools.Domains.Hosting.IPAddresses.asn.valueStringIP Addresses Info asn value
DomainTools.Domains.Hosting.IPAddresses.asn.countNumberIP Addresses Info asn count
DomainTools.Domains.Hosting.IPAddresses.country_code.valueStringIP Addresses Info country_code value
DomainTools.Domains.Hosting.IPAddresses.country_code.countNumberIP Addresses Info country_code count
DomainTools.Domains.Hosting.IPAddresses.isp.valueStringIP Addresses Info isp value
DomainTools.Domains.Hosting.IPAddresses.isp.countNumberIP Addresses Info isp count
DomainTools.Domains.Hosting.IPCountryCodeStringIP Country Code
DomainTools.Domains.Hosting.MailServers.domain.valueStringMail Servers Info domain value
DomainTools.Domains.Hosting.MailServers.domain.countNumberMail Servers Info domain count
DomainTools.Domains.Hosting.MailServers.host.valueStringMail Servers Info host value
DomainTools.Domains.Hosting.MailServers.host.countNumberMail Servers Info host count
DomainTools.Domains.Hosting.MailServers.ip.valueStringMail Servers Info ip value
DomainTools.Domains.Hosting.MailServers.ip.countNumberMail Servers Info ip count
DomainTools.Domains.Hosting.SPFRecordStringSPF Record Info
DomainTools.Domains.Hosting.NameServers.domain.valueStringDomainTools Domains NameServers domain value
DomainTools.Domains.Hosting.NameServers.domain.countNumberDomainTools Domains NameServers domain count
DomainTools.Domains.Hosting.NameServers.host.valueStringDomainTools Domains NameServers host value
DomainTools.Domains.Hosting.NameServers.host.countNumberDomainTools Domains NameServers host count
DomainTools.Domains.Hosting.NameServers.ip.valueStringDomainTools Domains NameServers ip value
DomainTools.Domains.Hosting.NameServers.ip.countNumberDomainTools Domains NameServers ip count
DomainTools.Domains.Hosting.SSLCertificate.hash.valueStringSSL Certificate Info hash value
DomainTools.Domains.Hosting.SSLCertificate.hash.countNumberSSL Certificate Info hash count
DomainTools.Domains.Hosting.SSLCertificate.organization.valueStringSSL Certificate Info organization value
DomainTools.Domains.Hosting.SSLCertificate.organization.countNumberSSL Certificate Info organization count
DomainTools.Domains.Hosting.SSLCertificate.subject.valueStringSSL Certificate Info subject value
DomainTools.Domains.Hosting.SSLCertificate.subject.countNumberSSL Certificate Info subject count
DomainTools.Domains.Hosting.RedirectsTo.valueStringDomains it Redirects To value
DomainTools.Domains.Hosting.RedirectsTo.countNumberDomains it Redirects To count
DomainTools.Domains.Analytics.GoogleAdsenseTrackingCodeNumberGoogle Adsense Tracking Code
DomainTools.Domains.Analytics.GoogleAnalyticTrackingCodeNumberGoogle Analytics Tracking Code
DBotScore.IndicatorStringDBotScore Indicator
DBotScore.TypeStringDBotScore Indicator Type
DBotScore.VendorStringVendor used to calculate the score
DBotScore.ScoreNumberThe actual score
Command Example#

!domaintoolsiris-analytics domain=demisto.com

Context Example#
Human Readable Output#

3. domaintoolsiris-threat-profile#


Provides markdown table with DomainTools Threat Profile data

Base Command#

domaintoolsiris-threat-profile

Input#
Argument NameDescriptionRequired
domainDomain nameRequired
Context Output#
PathTypeDescription
Domain.NameStringDomain Name
Domain.DNSStringDomain DNS
Domain.DomainStatusBooleanDomain Status
Domain.CreationDateDateDomain Creation Date
Domain.ExpirationDateDateDomain Expiration Date
Domain.NameServersStringDomain NameServers
Domain.Registrant.CountryStringDomain Registrant Country
Domain.Registrant.EmailStringDomain Registrant Email
Domain.Registrant.NameStringDomain Registrant Name
Domain.Registrant.PhoneStringDomain Registrant Phone
Domain.Malicious.VendorStringVendor that saw domain as malicious
Domain.Malicious.DescriptionStringDescription of why domain was found to be malicious
DomainTools.Domains.NameStringDomainTools Domain Name
DomainTools.Domains.LastEnrichedDateLast Time DomainTools Enriched Domain Data
DomainTools.Domains.Analytics.OverallRiskScoreNumberDomainTools Overall Risk Score
DomainTools.Domains.Analytics.ProximityRiskScoreNumberDomainTools Proximity Risk Score
DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScoreNumberDomainTools Threat Profile Risk Score
DomainTools.Domains.Analytics.ThreatProfileRiskScore.ThreatsStringDomainTools Threat Profile Threats
DomainTools.Domains.Analytics.ThreatProfileRiskScore.EvidenceStringDomainTools Threat Profile Evidence
DomainTools.Domains.Analytics.WebsiteResponseCodeNumberWebsite Response Code
DomainTools.Domains.Analytics.AlexaRankNumberAlexa Rank
DomainTools.Domains.Analytics.TagsStringDomainTools Tags
DomainTools.Domains.Identity.RegistrantNameStringRegistrant Name
DomainTools.Domains.Identity.RegistrantOrgStringRegistrant Org
DomainTools.Domains.Identity.RegistrantContact.Country.valueStringRegistrant Contact Country value
DomainTools.Domains.Identity.RegistrantContact.Country.countNumberRegistrant Contact Country count
DomainTools.Domains.Identity.RegistrantContact.Email.valueStringRegistrant Contact Email value
DomainTools.Domains.Identity.RegistrantContact.Email.countNumberRegistrant Contact Email count
DomainTools.Domains.Identity.RegistrantContact.Name.valueStringRegistrant Contact Name value
DomainTools.Domains.Identity.RegistrantContact.Name.countNumberRegistrant Contact Name count
DomainTools.Domains.Identity.RegistrantContact.Phone.valueStringRegistrant Contact Phone value
DomainTools.Domains.Identity.RegistrantContact.Phone.countNumberRegistrant Contact Phone count
DomainTools.Domains.Identity.SOAEmailStringSOA Record Email
DomainTools.Domains.Identity.SSLCertificateEmailStringSSL Certificate Email
DomainTools.Domains.Identity.AdminContact.Country.valueStringAdmin Contact Country value
DomainTools.Domains.Identity.AdminContact.Country.countNumberAdmin Contact Country count
DomainTools.Domains.Identity.AdminContact.Email.valueStringAdmin Contact Email value
DomainTools.Domains.Identity.AdminContact.Email.countNumberAdmin Contact Email count
DomainTools.Domains.Identity.AdminContact.Name.valueStringAdmin Contact Name value
DomainTools.Domains.Identity.AdminContact.Name.countNumberAdmin Contact Name count
DomainTools.Domains.Identity.AdminContact.Phone.valueStringAdmin Contact Phone value
DomainTools.Domains.Identity.AdminContact.Phone.countNumberAdmin Contact Phone count
DomainTools.Domains.Identity.TechnicalContact.Country.valueStringTechnical Contact Country value
DomainTools.Domains.Identity.TechnicalContact.Country.countNumberTechnical Contact Country count
DomainTools.Domains.Identity.TechnicalContact.Email.valueStringTechnical Contact Email value
DomainTools.Domains.Identity.TechnicalContact.Email.countNumberTechnical Contact Email count
DomainTools.Domains.Identity.TechnicalContact.Name.valueStringTechnical Contact Name value
DomainTools.Domains.Identity.TechnicalContact.Name.countNumberTechnical Contact Name count
DomainTools.Domains.Identity.TechnicalContact.Phone.valueStringTechnical Contact Phone value
DomainTools.Domains.Identity.TechnicalContact.Phone.countNumberTechnical Contact Phone count
DomainTools.Domains.Identity.BillingContact.Country.valueStringBilling Contact Country value
DomainTools.Domains.Identity.BillingContact.Country.countNumberBilling Contact Country count
DomainTools.Domains.Identity.BillingContact.Email.valueStringBilling Contact Email value
DomainTools.Domains.Identity.BillingContact.Email.countNumberBilling Contact Email count
DomainTools.Domains.Identity.BillingContact.Name.valueStringBilling Contact Name value
DomainTools.Domains.Identity.BillingContact.Name.countNumberBilling Contact Name count
DomainTools.Domains.Identity.BillingContact.Phone.valueStringBilling Contact Phone value
DomainTools.Domains.Identity.BillingContact.Phone.countNumberBilling Contact Phone count
DomainTools.Domains.Identity.EmailDomainsStringEmail Domains
DomainTools.Domains.Identity.AdditionalWhoisEmails.valueStringAdditional Whois Emails value
DomainTools.Domains.Identity.AdditionalWhoisEmails.countNumberAdditional Whois Emails count
DomainTools.Domains.Registration.DomainRegistrantStringDomain Registrant
DomainTools.Domains.Registration.RegistrarStatusStringRegistrar Status
DomainTools.Domains.Registration.DomainStatusBooleanDomain Active Status
DomainTools.Domains.Registration.CreateDateDateCreate Date
DomainTools.Domains.Registration.ExpirationDateDateExpiration Date
DomainTools.Domains.Hosting.IPAddresses.address.valueStringIP Addresses Info address value
DomainTools.Domains.Hosting.IPAddresses.address.countNumberIP Addresses Info address count
DomainTools.Domains.Hosting.IPAddresses.asn.valueStringIP Addresses Info asn value
DomainTools.Domains.Hosting.IPAddresses.asn.countNumberIP Addresses Info asn count
DomainTools.Domains.Hosting.IPAddresses.country_code.valueStringIP Addresses Info country_code value
DomainTools.Domains.Hosting.IPAddresses.country_code.countNumberIP Addresses Info country_code count
DomainTools.Domains.Hosting.IPAddresses.isp.valueStringIP Addresses Info isp value
DomainTools.Domains.Hosting.IPAddresses.isp.countNumberIP Addresses Info isp count
DomainTools.Domains.Hosting.IPCountryCodeStringIP Country Code
DomainTools.Domains.Hosting.MailServers.domain.valueStringMail Servers Info domain value
DomainTools.Domains.Hosting.MailServers.domain.countNumberMail Servers Info domain count
DomainTools.Domains.Hosting.MailServers.host.valueStringMail Servers Info host value
DomainTools.Domains.Hosting.MailServers.host.countNumberMail Servers Info host count
DomainTools.Domains.Hosting.MailServers.ip.valueStringMail Servers Info ip value
DomainTools.Domains.Hosting.MailServers.ip.countNumberMail Servers Info ip count
DomainTools.Domains.Hosting.SPFRecordStringSPF Record Info
DomainTools.Domains.Hosting.NameServers.domain.valueStringDomainTools Domains NameServers domain value
DomainTools.Domains.Hosting.NameServers.domain.countNumberDomainTools Domains NameServers domain count
DomainTools.Domains.Hosting.NameServers.host.valueStringDomainTools Domains NameServers host value
DomainTools.Domains.Hosting.NameServers.host.countNumberDomainTools Domains NameServers host count
DomainTools.Domains.Hosting.NameServers.ip.valueStringDomainTools Domains NameServers ip value
DomainTools.Domains.Hosting.NameServers.ip.countNumberDomainTools Domains NameServers ip count
DomainTools.Domains.Hosting.SSLCertificate.hash.valueStringSSL Certificate Info hash value
DomainTools.Domains.Hosting.SSLCertificate.hash.countNumberSSL Certificate Info hash count
DomainTools.Domains.Hosting.SSLCertificate.organization.valueStringSSL Certificate Info organization value
DomainTools.Domains.Hosting.SSLCertificate.organization.countNumberSSL Certificate Info organization count
DomainTools.Domains.Hosting.SSLCertificate.subject.valueStringSSL Certificate Info subject value
DomainTools.Domains.Hosting.SSLCertificate.subject.countNumberSSL Certificate Info subject count
DomainTools.Domains.Hosting.RedirectsTo.valueStringDomains it Redirects To value
DomainTools.Domains.Hosting.RedirectsTo.countNumberDomains it Redirects To count
DomainTools.Domains.Analytics.GoogleAdsenseTrackingCodeNumberGoogle Adsense Tracking Code
DomainTools.Domains.Analytics.GoogleAnalyticTrackingCodeNumberGoogle Analytics Tracking Code
DBotScore.IndicatorStringDBotScore Indicator
DBotScore.TypeStringDBotScore Indicator Type
DBotScore.VendorStringVendor used to calculate the score
DBotScore.ScoreNumberThe actual score
Command Example#

!domaintoolsiris-threat-profile domain=demisto.com

Context Example#
Human Readable Output#

4. domaintoolsiris-pivot#


Using one of the arguements allows a user to get back data on domains related to IPs, Email Addresses, etc.

Base Command#

domaintoolsiris-pivot

Input#
Argument NameDescriptionRequired
ipIP AddressOptional
emailE-mail AddressOptional
nameserver_ipName Server IP AddressOptional
ssl_hashSSL HashOptional
nameserver_hostFully-qualified host name of the name server (ns1.domaintools.net)Optional
mailserver_hostFully-qualified host name of the mail server (mx.domaintools.net)Optional
Context Output#
PathTypeDescription
DomainTools.PivotedDomains.NameStringDomainTools Domain Name
DomainTools.PivotedDomains.LastEnrichedDateLast Time DomainTools Enriched Domain Data
DomainTools.PivotedDomains.Analytics.OverallRiskScoreNumberDomainTools Overall Risk Score
DomainTools.PivotedDomains.Analytics.ProximityRiskScoreNumberDomainTools Proximity Risk Score
DomainTools.PivotedDomains.Analytics.ThreatProfileRiskScore.RiskScoreNumberDomainTools Threat Profile Risk Score
DomainTools.PivotedDomains.Analytics.ThreatProfileRiskScore.ThreatsStringDomainTools Threat Profile Threats
DomainTools.PivotedDomains.Analytics.ThreatProfileRiskScore.EvidenceStringDomainTools Threat Profile Evidence
DomainTools.PivotedDomains.Analytics.WebsiteResponseCodeNumberWebsite Response Code
DomainTools.PivotedDomains.Analytics.AlexaRankNumberAlexa Rank
DomainTools.PivotedDomains.Analytics.TagsStringDomainTools Tags
DomainTools.PivotedDomains.Identity.RegistrantNameStringRegistrant Name
DomainTools.PivotedDomains.Identity.RegistrantOrgStringRegistrant Org
DomainTools.PivotedDomains.Identity.RegistrantContact.Country.valueStringRegistrant Contact Country value
DomainTools.PivotedDomains.Identity.RegistrantContact.Country.countNumberRegistrant Contact Country count
DomainTools.PivotedDomains.Identity.RegistrantContact.Email.valueStringRegistrant Contact Email value
DomainTools.PivotedDomains.Identity.RegistrantContact.Email.countNumberRegistrant Contact Email count
DomainTools.PivotedDomains.Identity.RegistrantContact.Name.valueStringRegistrant Contact Name value
DomainTools.PivotedDomains.Identity.RegistrantContact.Name.countNumberRegistrant Contact Name count
DomainTools.PivotedDomains.Identity.RegistrantContact.Phone.valueStringRegistrant Contact Phone value
DomainTools.PivotedDomains.Identity.RegistrantContact.Phone.countNumberRegistrant Contact Phone count
DomainTools.PivotedDomains.Identity.SOAEmailStringSOA Record Email
DomainTools.PivotedDomains.Identity.SSLCertificateEmailStringSSL Certificate Email
DomainTools.PivotedDomains.Identity.AdminContact.Country.valueStringAdmin Contact Country value
DomainTools.PivotedDomains.Identity.AdminContact.Country.countNumberAdmin Contact Country count
DomainTools.PivotedDomains.Identity.AdminContact.Email.valueStringAdmin Contact Email value
DomainTools.PivotedDomains.Identity.AdminContact.Email.countNumberAdmin Contact Email count
DomainTools.PivotedDomains.Identity.AdminContact.Name.valueStringAdmin Contact Name value
DomainTools.PivotedDomains.Identity.AdminContact.Name.countNumberAdmin Contact Name count
DomainTools.PivotedDomains.Identity.AdminContact.Phone.valueStringAdmin Contact Phone value
DomainTools.PivotedDomains.Identity.AdminContact.Phone.countNumberAdmin Contact Phone count
DomainTools.PivotedDomains.Identity.TechnicalContact.Country.valueStringTechnical Contact Country value
DomainTools.PivotedDomains.Identity.TechnicalContact.Country.countNumberTechnical Contact Country count
DomainTools.PivotedDomains.Identity.TechnicalContact.Email.valueStringTechnical Contact Email value
DomainTools.PivotedDomains.Identity.TechnicalContact.Email.countNumberTechnical Contact Email count
DomainTools.PivotedDomains.Identity.TechnicalContact.Name.valueStringTechnical Contact Name value
DomainTools.PivotedDomains.Identity.TechnicalContact.Name.countNumberTechnical Contact Name count
DomainTools.PivotedDomains.Identity.TechnicalContact.Phone.valueStringTechnical Contact Phone value
DomainTools.PivotedDomains.Identity.TechnicalContact.Phone.countNumberTechnical Contact Phone count
DomainTools.PivotedDomains.Identity.BillingContact.Country.valueStringBilling Contact Country value
DomainTools.PivotedDomains.Identity.BillingContact.Country.countNumberBilling Contact Country count
DomainTools.PivotedDomains.Identity.BillingContact.Email.valueStringBilling Contact Email value
DomainTools.PivotedDomains.Identity.BillingContact.Email.countNumberBilling Contact Email count
DomainTools.PivotedDomains.Identity.BillingContact.Name.valueStringBilling Contact Name value
DomainTools.PivotedDomains.Identity.BillingContact.Name.countNumberBilling Contact Name count
DomainTools.PivotedDomains.Identity.BillingContact.Phone.valueStringBilling Contact Phone value
DomainTools.PivotedDomains.Identity.BillingContact.Phone.countNumberBilling Contact Phone count
DomainTools.PivotedDomains.Identity.EmailDomainsStringEmail Domains
DomainTools.PivotedDomains.Identity.AdditionalWhoisEmails.valueStringAdditional Whois Emails value
DomainTools.PivotedDomains.Identity.AdditionalWhoisEmails.countNumberAdditional Whois Emails count
DomainTools.PivotedDomains.Registration.DomainRegistrantStringDomain Registrant
DomainTools.PivotedDomains.Registration.RegistrarStatusStringRegistrar Status
DomainTools.PivotedDomains.Registration.DomainStatusBooleanDomain Active Status
DomainTools.PivotedDomains.Registration.CreateDateDateCreate Date
DomainTools.PivotedDomains.Registration.ExpirationDateDateExpiration Date
DomainTools.PivotedDomains.Hosting.IPAddresses.address.valueStringIP Addresses Info address value
DomainTools.PivotedDomains.Hosting.IPAddresses.address.countNumberIP Addresses Info address count
DomainTools.PivotedDomains.Hosting.IPAddresses.asn.valueStringIP Addresses Info asn value
DomainTools.PivotedDomains.Hosting.IPAddresses.asn.countNumberIP Addresses Info asn count
DomainTools.PivotedDomains.Hosting.IPAddresses.country_code.valueStringIP Addresses Info country_code value
DomainTools.PivotedDomains.Hosting.IPAddresses.country_code.countNumberIP Addresses Info country_code count
DomainTools.PivotedDomains.Hosting.IPAddresses.isp.valueStringIP Addresses Info isp value
DomainTools.PivotedDomains.Hosting.IPAddresses.isp.countNumberIP Addresses Info isp count
DomainTools.PivotedDomains.Hosting.IPCountryCodeStringIP Country Code
DomainTools.PivotedDomains.Hosting.MailServers.domain.valueStringMail Servers Info domain value
DomainTools.PivotedDomains.Hosting.MailServers.domain.countNumberMail Servers Info domain count
DomainTools.PivotedDomains.Hosting.MailServers.host.valueStringMail Servers Info host value
DomainTools.PivotedDomains.Hosting.MailServers.host.countNumberMail Servers Info host count
DomainTools.PivotedDomains.Hosting.MailServers.ip.valueStringMail Servers Info ip value
DomainTools.PivotedDomains.Hosting.MailServers.ip.countNumberMail Servers Info ip count
DomainTools.PivotedDomains.Hosting.SPFRecordStringSPF Record Info
DomainTools.PivotedDomains.Hosting.NameServers.domain.valueStringDomainTools Domains NameServers domain value
DomainTools.PivotedDomains.Hosting.NameServers.domain.countNumberDomainTools Domains NameServers domain count
DomainTools.PivotedDomains.Hosting.NameServers.host.valueStringDomainTools Domains NameServers host value
DomainTools.PivotedDomains.Hosting.NameServers.host.countNumberDomainTools Domains NameServers host count
DomainTools.PivotedDomains.Hosting.NameServers.ip.valueStringDomainTools Domains NameServers ip value
DomainTools.PivotedDomains.Hosting.NameServers.ip.countNumberDomainTools Domains NameServers ip count
DomainTools.PivotedDomains.Hosting.SSLCertificate.hash.valueStringSSL Certificate Info hash value
DomainTools.PivotedDomains.Hosting.SSLCertificate.hash.countNumberSSL Certificate Info hash count
DomainTools.PivotedDomains.Hosting.SSLCertificate.organization.valueStringSSL Certificate Info organization value
DomainTools.PivotedDomains.Hosting.SSLCertificate.organization.countNumberSSL Certificate Info organization count
DomainTools.PivotedDomains.Hosting.SSLCertificate.subject.valueStringSSL Certificate Info subject value
DomainTools.PivotedDomains.Hosting.SSLCertificate.subject.countNumberSSL Certificate Info subject count
DomainTools.PivotedDomains.Hosting.RedirectsTo.valueStringDomains it Redirects To value
DomainTools.PivotedDomains.Hosting.RedirectsTo.countNumberDomains it Redirects To count
DomainTools.PivotedDomains.Analytics.GoogleAdsenseTrackingCodeNumberGoogle Adsense Tracking Code
DomainTools.PivotedDomains.Analytics.GoogleAnalyticTrackingCodeNumberGoogle Analytics Tracking Code
Command Example#

domaintoolsiris-pivot ip=127.0.0.1

Context Example#
Human Readable Output#