Skip to main content

DomainExtractAndInvestigate

This Script is part of the DomainTools Iris Investigate Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.6.0 and later.

Resolves a URL or fully qualified domain name (FQDN) and looks up a complete profile of the domain on the DomainTools Iris Investigate API.

Script Data#


NameDescription
Script Typepython3
TagsDomainTools
Cortex XSOAR Version6.9.0

Dependencies#


This script uses the following commands and scripts.

  • domain
  • ExtractDomainFromUrlAndEmail

Inputs#


Argument NameDescription
urlResolve and investigate domains from this URL. Also accepts a comma-separated list of up to 1,000 URLs.
include_contextOptionally include the investigate results into the Context Data. Defaults to false.

Outputs#


PathDescriptionType
Domain.NameThe name of the domain.String
Domain.DNSThe DNS of the domain.String
Domain.DomainStatusThe status of the domain.Boolean
Domain.CreationDateThe creation date.Date
Domain.ExpirationDateThe expiration date of the domain.Date
Domain.NameServersThe nameServers of the domain.String
Domain.Registrant.CountryThe registrant country of the domain.String
Domain.Registrant.EmailThe registrant email of the domain.String
Domain.Registrant.NameThe registrant name of the domain.String
Domain.Registrant.PhoneThe registrant phone number of the domain.String
Domain.Malicious.VendorThe vendor who classified the domain as malicious.String
Domain.Malicious.DescriptionThe description as to why the domain was found to be malicious.String
DomainTools.Domains.NameThe domain name in DomainTools.String
DomainTools.Domains.LastEnrichedThe last Time DomainTools enriched domain data.Date
DomainTools.Domains.Analytics.OverallRiskScoreThe Overall Risk Score in DomainTools.Number
DomainTools.Domains.Analytics.ProximityRiskScoreThe Proximity Risk Score in DomainTools.Number
DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScoreThe Threat Profile Risk Score in DomainTools.Number
DomainTools.Domains.Analytics.ThreatProfileRiskScore.ThreatsThe threats of the Threat Profile Risk Score in DomainTools.String
DomainTools.Domains.Analytics.ThreatProfileRiskScore.EvidenceThe Threat Profile Risk Score Evidence in DomainTools.String
DomainTools.Domains.Analytics.WebsiteResponseCodeThe Website Response Code in DomainTools.Number
DomainTools.Domains.Analytics.AlexaRankThe Alexa Rank in DomainTools.Number
DomainTools.Domains.Analytics.TagsThe Tags in DomainTools.String
DomainTools.Domains.Identity.RegistrantNameThe name of the registrant.String
DomainTools.Domains.Identity.RegistrantOrgThe organization of the registrant.String
DomainTools.Domains.Identity.RegistrantContact.Country.valueThe country value of the registrant contact.String
DomainTools.Domains.Identity.RegistrantContact.Country.countThe count of the registrant contact country.Number
DomainTools.Domains.Identity.RegistrantContact.Email.valueThe Email value of the registrant contact.String
DomainTools.Domains.Identity.RegistrantContact.Email.countThe Email count of the registrant contact.Number
DomainTools.Domains.Identity.RegistrantContact.Name.valueThe name value of the registrant contact.String
DomainTools.Domains.Identity.RegistrantContact.Name.countThe name count of the registrant contact.Number
DomainTools.Domains.Identity.RegistrantContact.Phone.valueThe phone value of the registrant contact.String
DomainTools.Domains.Identity.RegistrantContact.Phone.countThe phone count of the registrant contact.Number
DomainTools.Domains.Identity.SOAEmailThe SOA record of the Email.String
DomainTools.Domains.Identity.SSLCertificateEmailThe Email of the SSL certificate.String
DomainTools.Domains.Identity.AdminContact.Country.valueThe country value of the administrator contact.String
DomainTools.Domains.Identity.AdminContact.Country.countThe country count of the administrator contact.Number
DomainTools.Domains.Identity.AdminContact.Email.valueThe Email value of the administrator contact.String
DomainTools.Domains.Identity.AdminContact.Email.countThe Email count of the administrator contact.Number
DomainTools.Domains.Identity.AdminContact.Name.valueThe name value of the administrator contact.String
DomainTools.Domains.Identity.AdminContact.Name.countThe name count of the administrator contact.Number
DomainTools.Domains.Identity.AdminContact.Phone.valueThe phone value of the administrator contact.String
DomainTools.Domains.Identity.AdminContact.Phone.countThe phone count of the administrator contact.Number
DomainTools.Domains.Identity.TechnicalContact.Country.valueThe country value of the technical contact.String
DomainTools.Domains.Identity.TechnicalContact.Country.countThe country count of the technical contact.Number
DomainTools.Domains.Identity.TechnicalContact.Email.valueThe Email value of the technical contact.String
DomainTools.Domains.Identity.TechnicalContact.Email.countThe Email count of the technical contact.Number
DomainTools.Domains.Identity.TechnicalContact.Name.valueThe name value of the technical Contact.String
DomainTools.Domains.Identity.TechnicalContact.Name.countThe name count of the technical contact.Number
DomainTools.Domains.Identity.TechnicalContact.Phone.valueThe phone value of the technical contact.String
DomainTools.Domains.Identity.TechnicalContact.Phone.countThe phone count of the technical contact.Number
DomainTools.Domains.Identity.BillingContact.Country.valueThe country value of the billing contact.String
DomainTools.Domains.Identity.BillingContact.Country.countThe country count of the billing contact.Number
DomainTools.Domains.Identity.BillingContact.Email.valueThe Email value of the billing contact.String
DomainTools.Domains.Identity.BillingContact.Email.countThe Email count of the billing contact.Number
DomainTools.Domains.Identity.BillingContact.Name.valueThe name value of the billing contact.String
DomainTools.Domains.Identity.BillingContact.Name.countThe name count of the billing contact.Number
DomainTools.Domains.Identity.BillingContact.Phone.valueThe phone value of the billing contact.String
DomainTools.Domains.Identity.BillingContact.Phone.countThe phone count of the billing contact.Number
DomainTools.Domains.Identity.EmailDomainsThe Email Domains.String
DomainTools.Domains.Identity.AdditionalWhoisEmails.valueThe value of the Additional Whois Emails record.String
DomainTools.Domains.Identity.AdditionalWhoisEmails.countThe count of the Additional Whois Emails record.Number
DomainTools.Domains.Registration.DomainRegistrantThe registrant of the domain.String
DomainTools.Domains.Registration.RegistrarStatusThe status of the registrar.String
DomainTools.Domains.Registration.DomainStatusThe active status of the domain.Boolean
DomainTools.Domains.Registration.CreateDateThe date the domain was created.Date
DomainTools.Domains.Registration.ExpirationDateThe expiration date of the domain.Date
DomainTools.Domains.Hosting.IPAddresses.address.valueThe address value of IP addresses.String
DomainTools.Domains.Hosting.IPAddresses.address.countThe address count of IP addresses.Number
DomainTools.Domains.Hosting.IPAddresses.asn.valueThe ASN value of IP addresses.String
DomainTools.Domains.Hosting.IPAddresses.asn.countThe ASN count of IP addresses.Number
DomainTools.Domains.Hosting.IPAddresses.country_code.valueThe country code value of IP addresses.String
DomainTools.Domains.Hosting.IPAddresses.country_code.countThe country code count of IP addresses.Number
DomainTools.Domains.Hosting.IPAddresses.isp.valueThe ISP value of IP addresses.String
DomainTools.Domains.Hosting.IPAddresses.isp.countThe ISP count of IP addresses.Number
DomainTools.Domains.Hosting.IPCountryCodeThe country code of the IP address.String
DomainTools.Domains.Hosting.MailServers.domain.valueThe domain value of the Mail Servers.String
DomainTools.Domains.Hosting.MailServers.domain.countThe domain count of the Mail Servers.Number
DomainTools.Domains.Hosting.MailServers.host.valueThe host value of the Mail Servers.String
DomainTools.Domains.Hosting.MailServers.host.countThe host count of the Mail Servers.Number
DomainTools.Domains.Hosting.MailServers.ip.valueThe IP value of the Mail Servers.String
DomainTools.Domains.Hosting.MailServers.ip.countThe IP count of the Mail Servers.Number
DomainTools.Domains.Hosting.SPFRecordThe SPF Record.String
DomainTools.Domains.Hosting.NameServers.domain.valueThe domain value of the domain NameServers.String
DomainTools.Domains.Hosting.NameServers.domain.countThe domain count of the domain NameServers.Number
DomainTools.Domains.Hosting.NameServers.host.valueThe host value of the domain NameServers.String
DomainTools.Domains.Hosting.NameServers.host.countThe host count of the domain NameServers.Number
DomainTools.Domains.Hosting.NameServers.ip.valueThe IP value of the domain NameServers.String
DomainTools.Domains.Hosting.NameServers.ip.countThe IP count of domain NameServers.Number
DomainTools.Domains.Hosting.SSLCertificate.hash.valueThe hash value of the SSL certificate.String
DomainTools.Domains.Hosting.SSLCertificate.hash.countThe hash count of the SSL certificate.Number
DomainTools.Domains.Hosting.SSLCertificate.organization.valueThe organization value of the SSL certificate.String
DomainTools.Domains.Hosting.SSLCertificate.organization.countThe organization count of the SSL certificate information.Number
DomainTools.Domains.Hosting.SSLCertificate.subject.valueThe subject value of the SSL certificate information.String
DomainTools.Domains.Hosting.SSLCertificate.subject.countThe subject count of the SSL certificate information.Number
DomainTools.Domains.Hosting.RedirectsTo.valueThe Redirects To Value of the domain.String
DomainTools.Domains.Hosting.RedirectsTo.countThe Redirects To Count of the domain.Number
DomainTools.Domains.Analytics.GoogleAdsenseTrackingCodeThe tracking code of Google Adsense.Number
DomainTools.Domains.Analytics.GoogleAnalyticTrackingCodeThe tracking code of Google Analytics.Number
DBotScore.IndicatorThe indicator of the DBotScore.String
DBotScore.TypeThe indicator type of the DBotScore.String
DBotScore.VendorThe vendor used to calculate the score.String
DBotScore.ScoreThe actual score.Number