Skip to main content

Darkmon - Enrich Domain

This Playbook is part of the Darkmon Pack.#

Supported versions

Available on Cortex XSOAR (versions 6.8.0 and later).

Sub-playbook that calls the Darkmon !domain command and returns DBotScore + Common.Domain for the input Domain indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • Darkmon

Scripts#

This playbook does not use any scripts.

Commands#

  • domain

Playbook Inputs#


NameDescriptionDefault ValueRequired
DomainThe Domain indicator value to enrich. Defaults to ${Domain.Name}.Domain.NameRequired

Playbook Outputs#


PathDescriptionType
DBotScore.IndicatorThe indicator value.string
DBotScore.TypeThe indicator type.string
DBotScore.VendorThe vendor reporting the score (Darkmon).string
DBotScore.ScoreThe reputation score (0=Unknown, 1=Good, 2=Suspicious, 3=Bad).number
DBotScore.ReliabilitySource reliability per the Admiralty code.string
Domain.NameThe Domain value.string
Domain.Malicious.VendorThe vendor that flagged this Domain as malicious (Darkmon).string
Domain.Malicious.DescriptionReason this Domain was flagged as malicious.string
Darkmon.SearchResultFull search result records returned by Darkmon for this indicator.unknown