Skip to main content

FeedDomainTools

This Integration is part of the DomainTools Feed Pack.#

Supported versions

Available on Cortex XSOAR (versions 5.5.0 and later) and Cortex XSIAM.

Real-Time Threat Intelligence Feeds provide data on the different stages of the domain lifecycle: from first-observed in the wild, to newly re-activated after a period of quiet. Newly Active Domains surfaces apex-level domains seen for the first time or after ten or more days of inactivity. Newly Observed Domains surfaces domains that we observe for the first time.

Configure FeedDomainTools in Cortex#

ParameterDescriptionRequired
API UsernameAPI Username and API KeyTrue
API KeyTrue
Session IDThe session id to serve as unique identifier. On it's initial use, it will retrieve data from the past 5 days. Defaults to 'dt-cortex-feeds'.False
AfterThe start of the query window in seconds, relative to the current time, inclusive. Defaults to -3600.False
TopLimits the number of results in the response payload. Defaults to 5000.False
Feed TypeThe DomainTools feed type to fetch. Defaults to 'ALL'.False
Fetch indicatorsFalse
Indicator ReputationIndicators from this integration instance will be marked with this reputation.False
Source ReliabilityReliability of the source providing the intelligence data.True
False
False
Feed Fetch IntervalFalse
Bypass exclusion listWhen selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system.False
Trust any certificate (not secure)False
Use system proxy settingsFalse
TagsSupports CSV values.
Traffic Light Protocol ColorThe Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feedFalse

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

domaintools-get-indicators#


Gets indicators from the feed.

Base Command#

domaintools-get-indicators

Input#

Argument NameDescriptionRequired
feed_typeThe DomainTools integration feed type to fetch. Possible values are: nod, nad, noh, domainrdap, domaindiscovery, domainrisk, domainhotlist, iphotlist, iprisk. Default is nod.Optional
session_idThe session id to serve as unique identifier. On its initial use, it will retrieve data from the past 5 days. Default is dt-cortex-feeds.Optional
domainThe top level domain to query (e.g. *.com).Optional
afterThe start of the query window in seconds, relative to the current time, inclusive. Defaults to 3600 seconds (1h). Default is -3600.Optional
beforeThe end of the query window in seconds, relative to the current time, inclusive.Optional
topLimits the number of results in the response payload. Default is 50.Optional
pdns_resolutions_minIP Hotlist/IP Risk filter: minimum number of domains seen on this IP in the last 24 hours.Optional
bad_pdns_resolutions_minIP Hotlist/IP Risk filter: minimum number of confirmed bad domains seen on this IP in the last 24 hours.Optional
total_domains_maxIP Hotlist/IP Risk filter: exclude IPs hosting more than this many total domains (removes superhosters).Optional
third_party_threats_minIP Hotlist/IP Risk filter: minimum number of domains confirmed with threats on external feeds.Optional
all_threats_combined_percent_minIP Hotlist/IP Risk filter: minimum percentage of confirmed or predicted malicious domains (0-100).Optional
combined_phishing_percent_minIP Hotlist/IP Risk filter: minimum combined phishing threat percentage (0-100).Optional
combined_malware_percent_minIP Hotlist/IP Risk filter: minimum combined malware threat percentage (0-100).Optional
combined_spam_percent_minIP Hotlist/IP Risk filter: minimum combined spam threat percentage (0-100).Optional
asnIP Hotlist/IP Risk filter: filter by autonomous system number (digits only).Optional
organizationIP Hotlist/IP Risk filter: exact match organization name filter.Optional
country_codeIP Hotlist/IP Risk filter: two-letter country code to filter by geographic location.Optional
percent_phishing_minIP Hotlist/IP Risk filter: minimum confirmed phishing percentage (0-100).Optional
percent_malware_minIP Hotlist/IP Risk filter: minimum confirmed malware percentage (0-100).Optional
percent_spam_minIP Hotlist/IP Risk filter: minimum confirmed spam percentage (0-100).Optional
all_threats_percent_minIP Risk filter: minimum percentage threshold for all threat classifications combined (0-100).Optional

Context Output#

There is no context output for this command.