DomainTools Iris
Together, DomainTools and Cortex XSOAR automate and orchestrate the incident response process with essential domain profile, web crawl, SSL and infrastructure data. SOCs can create custom, automated workflows to trigger Indicator of Compromise (IoC) investigations, block threats based on connected infrastructure, and identify potentially malicious domains before weaponization. The DomainTools App for Cortex XSOAR is shipped with pre-built playbooks to enable automated enrichment, decision logic, ad-hoc investigations, and the ability to persist enriched intelligence.
Data Enrichment & Threat Intelligence · DomainTools Iris Investigate
Details
| ID | DomainTools Iris |
|---|---|
| Provider | DomainTools |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.0.0 |
| Docker Image | demisto/vendors-sdk:1.0.0.10120494 |
| Supported Modules | Agentix XSIAM |
README
Together, DomainTools and Cortex XSOAR automate and orchestrate the incident response process with essential domain profile, web crawl, SSL and infrastructure data. SOCs can create custom, automated workflows to trigger Indicator of Compromise (IoC) investigations, block threats based on connected infrastructure, and identify potentially malicious domains before weaponization. The DomainTools App for Cortex XSOAR is shipped with pre-built playbooks to enable automated enrichment, decision logic, ad-hoc investigations, and the ability to persist enriched intelligence.
This integration was integrated and tested with version 1.0 of DomainTools Iris.
Configure DomainTools Iris in Cortex
| Parameter | Description | Required |
|---|---|---|
| API Username | False | |
| API Key | False | |
| High-Risk Threshold | True | |
| Young Domain Timeframe (within Days) | True | |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False | |
| Domain Result Type | Result type of the domain command: Iris returns full investigate results; Verdict returns only the domain risk score | False |
| Source Reliability | Reliability of the source providing the intelligence data. | False |
| False | ||
| False | ||
| Guided Pivot Threshold | When a small set of domains share an attribute (e.g. registrar), that can often be pivoted on in order to find other similar domains of interest. DomainTools tracks how many domains share each attribute and can highlight it for further investigation when the number of domains is beneath the set threshold. | True |
| Enabled on Monitoring Domains by Iris Search Hash | False | |
| Domaintools Iris Investigate Search Hash | The DomainTools Iris Investigate Search hash | False |
| Enabled on Monitoring Domains by Iris Tags | False | |
| Domaintools Iris Tags | The DomainTools Iris Tags (Values should be a comma separated value. e.g. (tag1,tag2)) | False |
| Maximum number of incidents to fetch | This is a required field by XSOAR and should be set to 2, one for each possible feed type iris search hash and iris tags. | False |
| Incident type | ||
| Fetch incidents | ||
| First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) | This is a required field by XSOAR and should be set to 2, one for each possible feed type iris search hash and iris tags. | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
domain
Provides data enrichment for domains.
Base Command
domain
Input
| Argument Name | Description | Required |
|---|---|---|
| domain | The domain to enrich. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Domain.Name | String | The name of the domain. |
| Domain.DNS | String | The DNS of the domain. |
| Domain.DomainStatus | Boolean | The status of the domain. |
| Domain.CreationDate | Date | The creation date. |
| Domain.ExpirationDate | Date | The expiration date of the domain. |
| Domain.NameServers | String | The nameServers of the domain. |
| Domain.Registrant.Country | String | The registrant country of the domain. |
| Domain.Registrant.Email | String | The registrant email of the domain. |
| Domain.Registrant.Name | String | The registrant name of the domain. |
| Domain.Registrant.Phone | String | The registrant phone number of the domain. |
| Domain.Malicious.Vendor | String | The vendor who classified the domain as malicious. |
| Domain.Malicious.Description | String | The description as to why the domain was found to be malicious. |
| DomainTools.Name | String | The domain name in DomainTools. |
| DomainTools.LastEnriched | Date | The last Time DomainTools enriched domain data. |
| DomainTools.Analytics.OverallRiskScore | Number | The Overall Risk Score in DomainTools. |
| DomainTools.Analytics.ProximityRiskScore | Number | The Proximity Risk Score in DomainTools. |
| DomainTools.Analytics.ThreatProfileRiskScore.RiskScore | Number | The Threat Profile Risk Score in DomainTools. |
| DomainTools.Analytics.ThreatProfileRiskScore.Threats | String | The threats of the Threat Profile Risk Score in DomainTools. |
| DomainTools.Analytics.ThreatProfileRiskScore.Evidence | String | The Threat Profile Risk Score Evidence in DomainTools. |
| DomainTools.Analytics.WebsiteResponseCode | Number | The Website Response Code in DomainTools. |
| DomainTools.Analytics.Tags | String | The Tags in DomainTools. |
| DomainTools.Identity.RegistrantName | String | The name of the registrant. |
| DomainTools.Identity.RegistrantOrg | String | The organization of the registrant. |
| DomainTools.Identity.RegistrantContact.Country.value | String | The country value of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Country.count | Number | The count of the registrant contact country. |
| DomainTools.Identity.RegistrantContact.Email.value | String | The Email value of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Email.count | Number | The Email count of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Name.value | String | The name value of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Name.count | Number | The name count of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Phone.value | String | The phone value of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Phone.count | Number | The phone count of the registrant contact. |
| DomainTools.Identity.SOAEmail | String | The SOA record of the Email. |
| DomainTools.Identity.SSLCertificateEmail | String | The Email of the SSL certificate. |
| DomainTools.Identity.AdminContact.Country.value | String | The country value of the administrator contact. |
| DomainTools.Identity.AdminContact.Country.count | Number | The country count of the administrator contact. |
| DomainTools.Identity.AdminContact.Email.value | String | The Email value of the administrator contact. |
| DomainTools.Identity.AdminContact.Email.count | Number | The Email count of the administrator contact. |
| DomainTools.Identity.AdminContact.Name.value | String | The name value of the administrator contact. |
| DomainTools.Identity.AdminContact.Name.count | Number | The name count of the administrator contact. |
| DomainTools.Identity.AdminContact.Phone.value | String | The phone value of the administrator contact. |
| DomainTools.Identity.AdminContact.Phone.count | Number | The phone count of the administrator contact. |
| DomainTools.Identity.TechnicalContact.Country.value | String | The country value of the technical contact. |
| DomainTools.Identity.TechnicalContact.Country.count | Number | The country count of the technical contact. |
| DomainTools.Identity.TechnicalContact.Email.value | String | The Email value of the technical contact. |
| DomainTools.Identity.TechnicalContact.Email.count | Number | The Email count of the technical contact. |
| DomainTools.Identity.TechnicalContact.Name.value | String | The name value of the technical Contact. |
| DomainTools.Identity.TechnicalContact.Name.count | Number | The name count of the technical contact. |
| DomainTools.Identity.TechnicalContact.Phone.value | String | The phone value of the technical contact. |
| DomainTools.Identity.TechnicalContact.Phone.count | Number | The phone count of the technical contact. |
| DomainTools.Identity.BillingContact.Country.value | String | The country value of the billing contact. |
| DomainTools.Identity.BillingContact.Country.count | Number | The country count of the billing contact. |
| DomainTools.Identity.BillingContact.Email.value | String | The Email value of the billing contact. |
| DomainTools.Identity.BillingContact.Email.count | Number | The Email count of the billing contact. |
| DomainTools.Identity.BillingContact.Name.value | String | The name value of the billing contact. |
| DomainTools.Identity.BillingContact.Name.count | Number | The name count of the billing contact. |
| DomainTools.Identity.BillingContact.Phone.value | String | The phone value of the billing contact. |
| DomainTools.Identity.BillingContact.Phone.count | Number | The phone count of the billing contact. |
| DomainTools.Identity.EmailDomains | String | The Email Domains. |
| DomainTools.Identity.AdditionalWhoisEmails.value | String | The value of the Additional Whois Emails record. |
| DomainTools.Identity.AdditionalWhoisEmails.count | Number | The count of the Additional Whois Emails record. |
| DomainTools.Registration.DomainRegistrant | String | The registrant of the domain. |
| DomainTools.Registration.RegistrarStatus | String | The status of the registrar. |
| DomainTools.Registration.DomainStatus | Boolean | The active status of the domain. |
| DomainTools.Registration.CreateDate | Date | The date the domain was created. |
| DomainTools.Registration.ExpirationDate | Date | The expiration date of the domain. |
| DomainTools.Hosting.IPAddresses.address.value | String | The address value of IP addresses. |
| DomainTools.Hosting.IPAddresses.address.count | Number | The address count of IP addresses. |
| DomainTools.Hosting.IPAddresses.asn.value | String | The ASN value of IP addresses. |
| DomainTools.Hosting.IPAddresses.asn.count | Number | The ASN count of IP addresses. |
| DomainTools.Hosting.IPAddresses.country_code.value | String | The country code value of IP addresses. |
| DomainTools.Hosting.IPAddresses.country_code.count | Number | The country code count of IP addresses. |
| DomainTools.Hosting.IPAddresses.isp.value | String | The ISP value of IP addresses. |
| DomainTools.Hosting.IPAddresses.isp.count | Number | The ISP count of IP addresses. |
| DomainTools.Hosting.IPCountryCode | String | The country code of the IP address. |
| DomainTools.Hosting.MailServers.domain.value | String | The domain value of the Mail Servers. |
| DomainTools.Hosting.MailServers.domain.count | Number | The domain count of the Mail Servers. |
| DomainTools.Hosting.MailServers.host.value | String | The host value of the Mail Servers. |
| DomainTools.Hosting.MailServers.host.count | Number | The host count of the Mail Servers. |
| DomainTools.Hosting.MailServers.ip.value | String | The IP value of the Mail Servers. |
| DomainTools.Hosting.MailServers.ip.count | Number | The IP count of the Mail Servers. |
| DomainTools.Hosting.SPFRecord | String | The SPF Record. |
| DomainTools.Hosting.NameServers.domain.value | String | The domain value of the domain NameServers. |
| DomainTools.Hosting.NameServers.domain.count | Number | The domain count of the domain NameServers. |
| DomainTools.Hosting.NameServers.host.value | String | The host value of the domain NameServers. |
| DomainTools.Hosting.NameServers.host.count | Number | The host count of the domain NameServers. |
| DomainTools.Hosting.NameServers.ip.value | String | The IP value of the domain NameServers. |
| DomainTools.Hosting.NameServers.ip.count | Number | The IP count of domain NameServers. |
| DomainTools.Hosting.SSLCertificate.hash.value | String | The hash value of the SSL certificate. |
| DomainTools.Hosting.SSLCertificate.hash.count | Number | The hash count of the SSL certificate. |
| DomainTools.Hosting.SSLCertificate.organization.value | String | The organization value of the SSL certificate. |
| DomainTools.Hosting.SSLCertificate.organization.count | Number | The organization count of the SSL certificate information. |
| DomainTools.Hosting.SSLCertificate.subject.value | String | The subject value of the SSL certificate information. |
| DomainTools.Hosting.SSLCertificate.subject.count | Number | The subject count of the SSL certificate information. |
| DomainTools.Hosting.RedirectsTo.value | String | The Redirects To Value of the domain. |
| DomainTools.Hosting.RedirectsTo.count | Number | The Redirects To Count of the domain. |
| DomainTools.Analytics.GoogleAdsenseTrackingCode | Number | The tracking code of Google Adsense. |
| DomainTools.Analytics.GoogleAnalyticTrackingCode | Number | The tracking code of Google Analytics. |
| DomainTools.Domains.Analytics.GA4TrackingCode | Number | The tracking code of ga4. |
| DomainTools.Domains.Analytics.GTMTrackingCode | Number | The tracking code of gtm. |
| DomainTools.Domains.Analytics.FBTrackingCode | Number | The tracking code of fb. |
| DomainTools.Domains.Analytics.HotJarTrackingCode | Number | The tracking code of Hot Jar. |
| DomainTools.Domains.Analytics.BaiduTrackingCode | Number | The tracking code of Baidu. |
| DomainTools.Domains.Analytics.YandexTrackingCode | Number | The tracking code of Yandex. |
| DomainTools.Domains.Analytics.MatomoTrackingCode | Number | The tracking code of Matomo. |
| DomainTools.Domains.Analytics.StatcounterProjectTrackingCode | Number | The tracking code of Stat Counter Project. |
| DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode | Number | The tracking code of Stat Counter Security. |
| DomainTools.WebsiteTitle | Number | The website title. |
| DomainTools.FirstSeen | Number | The date the domain was first seen. |
| DomainTools.ServerType | Number | The server type. |
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Type | String | The indicator type of the DBotScore. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| DBotScore.Score | Number | The actual score. |
domaintoolsiris-investigate
Returns a complete profile of the domain (SLD.TLD) using Iris Investigate. If parsing of FQDNs is desired, see domainExtractAndInvestigate.
Base Command
domaintoolsiris-investigate
Input
| Argument Name | Description | Required |
|---|---|---|
| domain | The domain name (SLD.TLD) to Investigate. Supports up to 1,000 comma-separated domains. | Required |
| include_context | Include the investigate results in Context Data. Defaults to true. Possible values are: true, false. Default is true. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Domain.Name | String | The name of the domain. |
| Domain.DNS | String | The DNS of the domain. |
| Domain.DomainStatus | Boolean | The status of the domain. |
| Domain.CreationDate | Date | The creation date. |
| Domain.ExpirationDate | Date | The expiration date of the domain. |
| Domain.NameServers | String | The nameServers of the domain. |
| Domain.Registrant.Country | String | The registrant country of the domain. |
| Domain.Registrant.Email | String | The registrant email of the domain. |
| Domain.Registrant.Name | String | The registrant name of the domain. |
| Domain.Registrant.Phone | String | The registrant phone number of the domain. |
| Domain.Malicious.Vendor | String | The vendor who classified the domain as malicious. |
| Domain.Malicious.Description | String | The description as to why the domain was found to be malicious. |
| DomainTools.Name | String | The domain name in DomainTools. |
| DomainTools.LastEnriched | Date | The last Time DomainTools enriched domain data. |
| DomainTools.Analytics.OverallRiskScore | Number | The Overall Risk Score in DomainTools. |
| DomainTools.Analytics.ProximityRiskScore | Number | The Proximity Risk Score in DomainTools. |
| DomainTools.Analytics.ThreatProfileRiskScore.RiskScore | Number | The Threat Profile Risk Score in DomainTools. |
| DomainTools.Analytics.ThreatProfileRiskScore.Threats | String | The threats of the Threat Profile Risk Score in DomainTools. |
| DomainTools.Analytics.ThreatProfileRiskScore.Evidence | String | The Threat Profile Risk Score Evidence in DomainTools. |
| DomainTools.Analytics.WebsiteResponseCode | Number | The Website Response Code in DomainTools. |
| DomainTools.Analytics.Tags | String | The Tags in DomainTools. |
| DomainTools.Identity.RegistrantName | String | The name of the registrant. |
| DomainTools.Identity.RegistrantOrg | String | The organization of the registrant. |
| DomainTools.Identity.RegistrantContact.Country.value | String | The country value of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Country.count | Number | The count of the registrant contact country. |
| DomainTools.Identity.RegistrantContact.Email.value | String | The Email value of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Email.count | Number | The Email count of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Name.value | String | The name value of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Name.count | Number | The name count of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Phone.value | String | The phone value of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Phone.count | Number | The phone count of the registrant contact. |
| DomainTools.Identity.SOAEmail | String | The SOA record of the Email. |
| DomainTools.Identity.SSLCertificateEmail | String | The Email of the SSL certificate. |
| DomainTools.Identity.AdminContact.Country.value | String | The country value of the administrator contact. |
| DomainTools.Identity.AdminContact.Country.count | Number | The country count of the administrator contact. |
| DomainTools.Identity.AdminContact.Email.value | String | The Email value of the administrator contact. |
| DomainTools.Identity.AdminContact.Email.count | Number | The Email count of the administrator contact. |
| DomainTools.Identity.AdminContact.Name.value | String | The name value of the administrator contact. |
| DomainTools.Identity.AdminContact.Name.count | Number | The name count of the administrator contact. |
| DomainTools.Identity.AdminContact.Phone.value | String | The phone value of the administrator contact. |
| DomainTools.Identity.AdminContact.Phone.count | Number | The phone count of the administrator contact. |
| DomainTools.Identity.TechnicalContact.Country.value | String | The country value of the technical contact. |
| DomainTools.Identity.TechnicalContact.Country.count | Number | The country count of the technical contact. |
| DomainTools.Identity.TechnicalContact.Email.value | String | The Email value of the technical contact. |
| DomainTools.Identity.TechnicalContact.Email.count | Number | The Email count of the technical contact. |
| DomainTools.Identity.TechnicalContact.Name.value | String | The name value of the technical Contact. |
| DomainTools.Identity.TechnicalContact.Name.count | Number | The name count of the technical contact. |
| DomainTools.Identity.TechnicalContact.Phone.value | String | The phone value of the technical contact. |
| DomainTools.Identity.TechnicalContact.Phone.count | Number | The phone count of the technical contact. |
| DomainTools.Identity.BillingContact.Country.value | String | The country value of the billing contact. |
| DomainTools.Identity.BillingContact.Country.count | Number | The country count of the billing contact. |
| DomainTools.Identity.BillingContact.Email.value | String | The Email value of the billing contact. |
| DomainTools.Identity.BillingContact.Email.count | Number | The Email count of the billing contact. |
| DomainTools.Identity.BillingContact.Name.value | String | The name value of the billing contact. |
| DomainTools.Identity.BillingContact.Name.count | Number | The name count of the billing contact. |
| DomainTools.Identity.BillingContact.Phone.value | String | The phone value of the billing contact. |
| DomainTools.Identity.BillingContact.Phone.count | Number | The phone count of the billing contact. |
| DomainTools.Identity.EmailDomains | String | The Email Domains. |
| DomainTools.Identity.AdditionalWhoisEmails.value | String | The value of the Additional Whois Emails record. |
| DomainTools.Identity.AdditionalWhoisEmails.count | Number | The count of the Additional Whois Emails record. |
| DomainTools.Registration.DomainRegistrant | String | The registrant of the domain. |
| DomainTools.Registration.RegistrarStatus | String | The status of the registrar. |
| DomainTools.Registration.DomainStatus | Boolean | The active status of the domain. |
| DomainTools.Registration.CreateDate | Date | The date the domain was created. |
| DomainTools.Registration.ExpirationDate | Date | The expiration date of the domain. |
| DomainTools.Hosting.IPAddresses.address.value | String | The address value of IP addresses. |
| DomainTools.Hosting.IPAddresses.address.count | Number | The address count of IP addresses. |
| DomainTools.Hosting.IPAddresses.asn.value | String | The ASN value of IP addresses. |
| DomainTools.Hosting.IPAddresses.asn.count | Number | The ASN count of IP addresses. |
| DomainTools.Hosting.IPAddresses.country_code.value | String | The country code value of IP addresses. |
| DomainTools.Hosting.IPAddresses.country_code.count | Number | The country code count of IP addresses. |
| DomainTools.Hosting.IPAddresses.isp.value | String | The ISP value of IP addresses. |
| DomainTools.Hosting.IPAddresses.isp.count | Number | The ISP count of IP addresses. |
| DomainTools.Hosting.IPCountryCode | String | The country code of the IP address. |
| DomainTools.Hosting.MailServers.domain.value | String | The domain value of the Mail Servers. |
| DomainTools.Hosting.MailServers.domain.count | Number | The domain count of the Mail Servers. |
| DomainTools.Hosting.MailServers.host.value | String | The host value of the Mail Servers. |
| DomainTools.Hosting.MailServers.host.count | Number | The host count of the Mail Servers. |
| DomainTools.Hosting.MailServers.ip.value | String | The IP value of the Mail Servers. |
| DomainTools.Hosting.MailServers.ip.count | Number | The IP count of the Mail Servers. |
| DomainTools.Hosting.SPFRecord | String | The SPF Record. |
| DomainTools.Hosting.NameServers.domain.value | String | The domain value of the domain NameServers. |
| DomainTools.Hosting.NameServers.domain.count | Number | The domain count of the domain NameServers. |
| DomainTools.Hosting.NameServers.host.value | String | The host value of the domain NameServers. |
| DomainTools.Hosting.NameServers.host.count | Number | The host count of the domain NameServers. |
| DomainTools.Hosting.NameServers.ip.value | String | The IP value of the domain NameServers. |
| DomainTools.Hosting.NameServers.ip.count | Number | The IP count of domain NameServers. |
| DomainTools.Hosting.SSLCertificate.hash.value | String | The hash value of the SSL certificate. |
| DomainTools.Hosting.SSLCertificate.hash.count | Number | The hash count of the SSL certificate. |
| DomainTools.Hosting.SSLCertificate.organization.value | String | The organization value of the SSL certificate. |
| DomainTools.Hosting.SSLCertificate.organization.count | Number | The organization count of the SSL certificate information. |
| DomainTools.Hosting.SSLCertificate.subject.value | String | The subject value of the SSL certificate information. |
| DomainTools.Hosting.SSLCertificate.subject.count | Number | The subject count of the SSL certificate information. |
| DomainTools.Hosting.RedirectsTo.value | String | The Redirects To Value of the domain. |
| DomainTools.Hosting.RedirectsTo.count | Number | The Redirects To Count of the domain. |
| DomainTools.Analytics.GoogleAdsenseTrackingCode | Number | The tracking code of Google Adsense. |
| DomainTools.Analytics.GoogleAnalyticTrackingCode | Number | The tracking code of Google Analytics. |
| DomainTools.Domains.Analytics.GA4TrackingCode | Number | The tracking code of ga4. |
| DomainTools.Domains.Analytics.GTMTrackingCode | Number | The tracking code of gtm. |
| DomainTools.Domains.Analytics.FBTrackingCode | Number | The tracking code of fb. |
| DomainTools.Domains.Analytics.HotJarTrackingCode | Number | The tracking code of Hot Jar. |
| DomainTools.Domains.Analytics.BaiduTrackingCode | Number | The tracking code of Baidu. |
| DomainTools.Domains.Analytics.YandexTrackingCode | Number | The tracking code of Yandex. |
| DomainTools.Domains.Analytics.MatomoTrackingCode | Number | The tracking code of Matomo. |
| DomainTools.Domains.Analytics.StatcounterProjectTrackingCode | Number | The tracking code of Stat Counter Project. |
| DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode | Number | The tracking code of Stat Counter Security. |
| DomainTools.WebsiteTitle | Number | The website title. |
| DomainTools.FirstSeen | Number | The date the domain was first seen. |
| DomainTools.ServerType | Number | The server type. |
| DBotScore.Indicator | String | The indicator of the DBotScore. |
| DBotScore.Type | String | The indicator type of the DBotScore. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| DBotScore.Score | Number | The actual score. |
domaintoolsiris-enrich
Returns a complete profile of the domain (SLD.TLD) using Iris Enrich. If parsing of URLs or FQDNs is desired, see domainExtractAndEnrich.
Base Command
domaintoolsiris-enrich
Input
| Argument Name | Description | Required |
|---|---|---|
| domain | The domain name (SLD.TLD), or a comma-separated list of up to 6,000 domains. | Required |
| include_context | Include the investigate results in Context Data. Defaults to true. Possible values are: true, false. Default is true. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Domain.Name | String | The name of the domain. |
| Domain.DNS | String | The DNS of the domain. |
| Domain.DomainStatus | Boolean | The status of the domain. |
| Domain.CreationDate | Date | The creation date. |
| Domain.ExpirationDate | Date | The expiration date of the domain. |
| Domain.NameServers | String | The nameServers of the domain. |
| Domain.Registrant.Country | String | The registrant country of the domain. |
| Domain.Registrant.Email | String | The registrant email of the domain. |
| Domain.Registrant.Name | String | The registrant name of the domain. |
| Domain.Registrant.Phone | String | The registrant phone number of the domain. |
| Domain.Malicious.Vendor | String | The vendor who classified the domain as malicious. |
| Domain.Malicious.Description | String | The description as to why the domain was found to be malicious. |
| DomainTools.Name | String | The domain name in DomainTools. |
| DomainTools.LastEnriched | Date | The last Time DomainTools enriched domain data. |
| DomainTools.Analytics.OverallRiskScore | Number | The Overall Risk Score in DomainTools. |
| DomainTools.Analytics.ProximityRiskScore | Number | The Proximity Risk Score in DomainTools. |
| DomainTools.Analytics.ThreatProfileRiskScore.RiskScore | Number | The Threat Profile Risk Score in DomainTools. |
| DomainTools.Analytics.ThreatProfileRiskScore.Threats | String | The threats of the Threat Profile Risk Score in DomainTools. |
| DomainTools.Analytics.ThreatProfileRiskScore.Evidence | String | The Threat Profile Risk Score Evidence in DomainTools. |
| DomainTools.Analytics.WebsiteResponseCode | Number | The Website Response Code in DomainTools. |
| DomainTools.Analytics.Tags | String | The Tags in DomainTools. |
| DomainTools.Identity.RegistrantName | String | The name of the registrant. |
| DomainTools.Identity.RegistrantOrg | String | The organization of the registrant. |
| DomainTools.Identity.RegistrantContact.Country.value | String | The country value of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Country.count | Number | The count of the registrant contact country. |
| DomainTools.Identity.RegistrantContact.Email.value | String | The Email value of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Email.count | Number | The Email count of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Name.value | String | The name value of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Name.count | Number | The name count of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Phone.value | String | The phone value of the registrant contact. |
| DomainTools.Identity.RegistrantContact.Phone.count | Number | The phone count of the registrant contact. |
| DomainTools.Identity.SOAEmail | String | The SOA record of the Email. |
| DomainTools.Identity.SSLCertificateEmail | String | The Email of the SSL certificate. |
| DomainTools.Identity.AdminContact.Country.value | String | The country value of the administrator contact. |
| DomainTools.Identity.AdminContact.Country.count | Number | The country count of the administrator contact. |
| DomainTools.Identity.AdminContact.Email.value | String | The Email value of the administrator contact. |
| DomainTools.Identity.AdminContact.Email.count | Number | The Email count of the administrator contact. |
| DomainTools.Identity.AdminContact.Name.value | String | The name value of the administrator contact. |
| DomainTools.Identity.AdminContact.Name.count | Number | The name count of the administrator contact. |
| DomainTools.Identity.AdminContact.Phone.value | String | The phone value of the administrator contact. |
| DomainTools.Identity.AdminContact.Phone.count | Number | The phone count of the administrator contact. |
| DomainTools.Identity.TechnicalContact.Country.value | String | The country value of the technical contact. |
| DomainTools.Identity.TechnicalContact.Country.count | Number | The country count of the technical contact. |
| DomainTools.Identity.TechnicalContact.Email.value | String | The Email value of the technical contact. |
| DomainTools.Identity.TechnicalContact.Email.count | Number | The Email count of the technical contact. |
| DomainTools.Identity.TechnicalContact.Name.value | String | The name value of the technical Contact. |
| DomainTools.Identity.TechnicalContact.Name.count | Number | The name count of the technical contact. |
| DomainTools.Identity.TechnicalContact.Phone.value | String | The phone value of the technical contact. |
| DomainTools.Identity.TechnicalContact.Phone.count | Number | The phone count of the technical contact. |
| DomainTools.Identity.BillingContact.Country.value | String | The country value of the billing contact. |
| DomainTools.Identity.BillingContact.Country.count | Number | The country count of the billing contact. |
| DomainTools.Identity.BillingContact.Email.value | String | The Email value of the billing contact. |
| DomainTools.Identity.BillingContact.Email.count | Number | The Email count of the billing contact. |
| DomainTools.Identity.BillingContact.Name.value | String | The name value of the billing contact. |
| DomainTools.Identity.BillingContact.Name.count | Number | The name count of the billing contact. |
| DomainTools.Identity.BillingContact.Phone.value | String | The phone value of the billing contact. |
| DomainTools.Identity.BillingContact.Phone.count | Number | The phone count of the billing contact. |
| DomainTools.Identity.EmailDomains | String | The Email Domains. |
| DomainTools.Identity.AdditionalWhoisEmails.value | String | The value of the Additional Whois Emails record. |
| DomainTools.Identity.AdditionalWhoisEmails.count | Number | The count of the Additional Whois Emails record. |
| DomainTools.Registration.DomainRegistrant | String | The registrant of the domain. |
| DomainTools.Registration.RegistrarStatus | String | The status of the registrar. |
| DomainTools.Registration.DomainStatus | Boolean | The active status of the domain. |
| DomainTools.Registration.CreateDate | Date | The date the domain was created. |
| DomainTools.Registration.ExpirationDate | Date | The expiration date of the domain. |
| DomainTools.Hosting.IPAddresses.address.value | String | The address value of IP addresses. |
| DomainTools.Hosting.IPAddresses.address.count | Number | The address count of IP addresses. |
| DomainTools.Hosting.IPAddresses.asn.value | String | The ASN value of IP addresses. |
| DomainTools.Hosting.IPAddresses.asn.count | Number | The ASN count of IP addresses. |
| DomainTools.Hosting.IPAddresses.country_code.value | String | The country code value of IP addresses. |
| DomainTools.Hosting.IPAddresses.country_code.count | Number | The country code count of IP addresses. |
| DomainTools.Hosting.IPAddresses.isp.value | String | The ISP value of IP addresses. |
| DomainTools.Hosting.IPAddresses.isp.count | Number | The ISP count of IP addresses. |
| DomainTools.Hosting.IPCountryCode | String | The country code of the IP address. |
| DomainTools.Hosting.MailServers.domain.value | String | The domain value of the Mail Servers. |
| DomainTools.Hosting.MailServers.domain.count | Number | The domain count of the Mail Servers. |
| DomainTools.Hosting.MailServers.host.value | String | The host value of the Mail Servers. |
| DomainTools.Hosting.MailServers.host.count | Number | The host count of the Mail Servers. |
| DomainTools.Hosting.MailServers.ip.value | String | The IP value of the Mail Servers. |
| DomainTools.Hosting.MailServers.ip.count | Number | The IP count of the Mail Servers. |
| DomainTools.Hosting.SPFRecord | String | The SPF Record. |
| DomainTools.Hosting.NameServers.domain.value | String | The domain value of the domain NameServers. |
| DomainTools.Hosting.NameServers.domain.count | Number | The domain count of the domain NameServers. |
| DomainTools.Hosting.NameServers.host.value | String | The host value of the domain NameServers. |
| DomainTools.Hosting.NameServers.host.count | Number | The host count of the domain NameServers. |
| DomainTools.Hosting.NameServers.ip.value | String | The IP value of the domain NameServers. |
| DomainTools.Hosting.NameServers.ip.count | Number | The IP count of domain NameServers. |
| DomainTools.Hosting.SSLCertificate.hash.value | String | The hash value of the SSL certificate. |
| DomainTools.Hosting.SSLCertificate.hash.count | Number | The hash count of the SSL certificate. |
| DomainTools.Hosting.SSLCertificate.organization.value | String | The organization value of the SSL certificate. |
| DomainTools.Hosting.SSLCertificate.organization.count | Number | The organization count of the SSL certificate information. |
| DomainTools.Hosting.SSLCertificate.subject.value | String | The subject value of the SSL certificate information. |
| DomainTools.Hosting.SSLCertificate.subject.count | Number | The subject count of the SSL certificate information. |
| DomainTools.Hosting.RedirectsTo.value | String | The Redirects To Value of the domain. |
| DomainTools.Hosting.RedirectsTo.count | Number | The Redirects To Count of the domain. |
| DomainTools.Analytics.GoogleAdsenseTrackingCode | Number | The tracking code of Google Adsense. |
| DomainTools.Analytics.GoogleAnalyticTrackingCode | Number | The tracking code of Google Analytics. |
| DomainTools.Domains.Analytics.GA4TrackingCode | Number | The tracking code of ga4. |
| DomainTools.Domains.Analytics.GTMTrackingCode | Number | The tracking code of gtm. |
| DomainTools.Domains.Analytics.FBTrackingCode | Number | The tracking code of fb. |
| DomainTools.Domains.Analytics.HotJarTrackingCode | Number | The tracking code of Hot Jar. |
| DomainTools.Domains.Analytics.BaiduTrackingCode | Number | The tracking code of Baidu. |
| DomainTools.Domains.Analytics.YandexTrackingCode | Number | The tracking code of Yandex. |
| DomainTools.Domains.Analytics.MatomoTrackingCode | Number | The tracking code of Matomo. |
| DomainTools.Domains.Analytics.StatcounterProjectTrackingCode | Number | The tracking code of Stat Counter Project. |
| DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode | Number | The tracking code of Stat Counter Security. |
| DomainTools.WebsiteTitle | Number | The website title. |
| DomainTools.FirstSeen | Number | The date the domain was first seen. |
| DomainTools.ServerType | Number | The server type. |
| DBotScore.Indicator | String | The indicator of the DBotScore. |
| DBotScore.Type | String | The indicator type of the DBotScore. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| DBotScore.Score | Number | The actual score. |
domaintoolsiris-analytics
Displays DomainTools Analytic data in a markdown format table.
Base Command
domaintoolsiris-analytics
Input
| Argument Name | Description | Required |
|---|---|---|
| domain | The domain name to display. | Required |
| include_context | Include the enrich results in Context Data. Defaults to true. Possible values are: true, false. Default is true. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Domain.Name | String | The name of the domain. |
| Domain.DNS | String | The DNS of the domain. |
| Domain.DomainStatus | Boolean | The status of the domain. |
| Domain.CreationDate | Date | The creation date of the domain. |
| Domain.ExpirationDate | Date | The expiration date of the domain. |
| Domain.NameServers | String | The NameServers of the domain. |
| Domain.Registrant.Country | String | The registrant country of the domain. |
| Domain.Registrant.Email | String | The registrant Email of the domain. |
| Domain.Registrant.Name | String | The registrant name of the domain. |
| Domain.Registrant.Phone | String | The registrant phone number of the domain. |
| Domain.Malicious.Vendor | String | The vendor that classified the domain as malicious. |
| Domain.Malicious.Description | String | The description as to why the domain was found malicious. |
| DomainTools.Domains.Name | String | The domain name in DomainTools. |
| DomainTools.Domains.LastEnriched | Date | The last Time DomainTools enriched domain data. |
| DomainTools.Domains.Analytics.OverallRiskScore | Number | The DomainTools Overall Risk Score. |
| DomainTools.Domains.Analytics.ProximityRiskScore | Number | The DomainTools Proximity Risk Score. |
| DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScore | Number | The DomainTools Threat Profile Risk Score. |
| DomainTools.Domains.Analytics.ThreatProfileRiskScore.Threats | String | The DomainTools Threat Profile Threats. |
| DomainTools.Domains.Analytics.ThreatProfileRiskScore.Evidence | String | The DomainTools Threat Profile Evidence. |
| DomainTools.Domains.Analytics.WebsiteResponseCode | Number | The Website Response Code. |
| DomainTools.Domains.Analytics.Tags | String | The tags in DomainTools. |
| DomainTools.Domains.Identity.RegistrantName | String | The name of the registrant. |
| DomainTools.Domains.Identity.RegistrantOrg | String | The organization of the registrant. |
| DomainTools.Domains.Identity.RegistrantContact.Country.value | String | The country value of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Country.count | Number | The country count of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Email.value | String | The Email value of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Email.count | Number | The Email count of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Name.value | String | The name value of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Name.count | Number | The Name count of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Phone.value | String | The phone value of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Phone.count | Number | The phone count of the registrant contact. |
| DomainTools.Domains.Identity.SOAEmail | String | The SOA record Email. |
| DomainTools.Domains.Identity.SSLCertificateEmail | String | The email of the SSL certificate. |
| DomainTools.Domains.Identity.AdminContact.Country.value | String | The country value of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Country.count | Number | The country count of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Email.value | String | The Email value of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Email.count | Number | The Email count of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Name.value | String | The name value of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Name.count | Number | The name count of administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Phone.value | String | The phone value of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Phone.count | Number | The phone count of the administrator contact. |
| DomainTools.Domains.Identity.TechnicalContact.Country.value | String | The country value of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Country.count | Number | The country count of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Email.value | String | The Email value of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Email.count | Number | The Email count of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Name.value | String | The name value of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Name.count | Number | The name count of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Phone.value | String | The phone value of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Phone.count | Number | The phone count of the technical contact. |
| DomainTools.Domains.Identity.BillingContact.Country.value | String | The country value of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Country.count | Number | The country count of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Email.value | String | The email value of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Email.count | Number | The email count of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Name.value | String | The name value of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Name.count | Number | The name count of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Phone.value | String | The phone value of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Phone.count | Number | The phone count of the billing contact. |
| DomainTools.Domains.Identity.EmailDomains | String | The domain of the Email. |
| DomainTools.Domains.Identity.AdditionalWhoisEmails.value | String | The value of the Additional Whois Emails. |
| DomainTools.Domains.Identity.AdditionalWhoisEmails.count | Number | The count of the Additional Whois Emails. |
| DomainTools.Domains.Registration.DomainRegistrant | String | The registrant of the domain. |
| DomainTools.Domains.Registration.RegistrarStatus | String | The status of the registrar. |
| DomainTools.Domains.Registration.DomainStatus | Boolean | The active status of the domain. |
| DomainTools.Domains.Registration.CreateDate | Date | The date the domain was created. |
| DomainTools.Domains.Registration.ExpirationDate | Date | The date the domain expires. |
| DomainTools.Domains.Hosting.IPAddresses.address.value | String | The address values of the IP addresses. |
| DomainTools.Domains.Hosting.IPAddresses.address.count | Number | The address counts of the IP addresses. |
| DomainTools.Domains.Hosting.IPAddresses.asn.value | String | The ASN values of the IP addresses. |
| DomainTools.Domains.Hosting.IPAddresses.asn.count | Number | The ASN counts of the IP addresses. |
| DomainTools.Domains.Hosting.IPAddresses.country_code.value | String | The country code values of the IP addresses. |
| DomainTools.Domains.Hosting.IPAddresses.country_code.count | Number | The country code counts of the IP addresses. |
| DomainTools.Domains.Hosting.IPAddresses.isp.value | String | IP Addresses Info isp value. |
| DomainTools.Domains.Hosting.IPAddresses.isp.count | Number | IP Addresses Info isp count. |
| DomainTools.Domains.Hosting.IPCountryCode | String | IP Country Code. |
| DomainTools.Domains.Hosting.MailServers.domain.value | String | Mail Servers Info domain value. |
| DomainTools.Domains.Hosting.MailServers.domain.count | Number | Mail Servers Info domain count. |
| DomainTools.Domains.Hosting.MailServers.host.value | String | Mail Servers Info host value. |
| DomainTools.Domains.Hosting.MailServers.host.count | Number | Mail Servers Info host count. |
| DomainTools.Domains.Hosting.MailServers.ip.value | String | Mail Servers Info ip value. |
| DomainTools.Domains.Hosting.MailServers.ip.count | Number | Mail Servers Info ip count. |
| DomainTools.Domains.Hosting.SPFRecord | String | The SPF record. |
| DomainTools.Domains.Hosting.NameServers.domain.value | String | The domain value of the DomainTools Domains NameServers. |
| DomainTools.Domains.Hosting.NameServers.domain.count | Number | The domain count of the DomainTools Domains NameServers. |
| DomainTools.Domains.Hosting.NameServers.host.value | String | The host value of the DomainTools Domains NameServers. |
| DomainTools.Domains.Hosting.NameServers.host.count | Number | The host count of the DomainTools Domains NameServers. |
| DomainTools.Domains.Hosting.NameServers.ip.value | String | The IP value of the DomainTools Domains NameServers. |
| DomainTools.Domains.Hosting.NameServers.ip.count | Number | The IP count of the DomainTools Domains NameServers. |
| DomainTools.Domains.Hosting.SSLCertificate.hash.value | String | The hash value of the SSL certificate. |
| DomainTools.Domains.Hosting.SSLCertificate.hash.count | Number | The hash count of the SSL certificate. |
| DomainTools.Domains.Hosting.SSLCertificate.organization.value | String | The organization value of the SSL certificate. |
| DomainTools.Domains.Hosting.SSLCertificate.organization.count | Number | The organization count of the SSL certificate. |
| DomainTools.Domains.Hosting.SSLCertificate.subject.value | String | The subject value of the SSL certificate. |
| DomainTools.Domains.Hosting.SSLCertificate.subject.count | Number | The subject count of the SSL certificate. |
| DomainTools.Domains.Hosting.RedirectsTo.value | String | The Redirects To value of the domain. |
| DomainTools.Domains.Hosting.RedirectsTo.count | Number | The Redirects To count of the domain. |
| DomainTools.Domains.Analytics.GoogleAdsenseTrackingCode | Number | The tracking code of Google Adsense. |
| DomainTools.Analytics.GoogleAnalyticTrackingCode | Number | The tracking code of Google Analytics. |
| DomainTools.Domains.Analytics.GA4TrackingCode | Number | The tracking code of ga4. |
| DomainTools.Domains.Analytics.GTMTrackingCode | Number | The tracking code of gtm. |
| DomainTools.Domains.Analytics.FBTrackingCode | Number | The tracking code of fb. |
| DomainTools.Domains.Analytics.HotJarTrackingCode | Number | The tracking code of Hot Jar. |
| DomainTools.Domains.Analytics.BaiduTrackingCode | Number | The tracking code of Baidu. |
| DomainTools.Domains.Analytics.YandexTrackingCode | Number | The tracking code of Yandex. |
| DomainTools.Domains.Analytics.MatomoTrackingCode | Number | The tracking code of Matomo. |
| DomainTools.Domains.Analytics.StatcounterProjectTrackingCode | Number | The tracking code of Stat Counter Project. |
| DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode | Number | The tracking code of Stat Counter Security. |
| DBotScore.Indicator | String | The DBotScore indicator. |
| DBotScore.Type | String | The indicator type of the DBotScore. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| DBotScore.Score | Number | The actual score. |
domaintoolsiris-threat-profile
Displays DomainTools Threat Profile data in a markdown format table.
Base Command
domaintoolsiris-threat-profile
Input
| Argument Name | Description | Required |
|---|---|---|
| domain | The domain name. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Domain.Name | String | The name of the domain. |
| Domain.DNS | String | The DNS of the domain. |
| Domain.DomainStatus | Boolean | The status of the domain. |
| Domain.CreationDate | Date | The creation date of the domain. |
| Domain.ExpirationDate | Date | The expiration date of the domain. |
| Domain.NameServers | String | The NameServers of the domain. |
| Domain.Registrant.Country | String | The registrant country of the domain. |
| Domain.Registrant.Email | String | The Email of the registrant domain. |
| Domain.Registrant.Name | String | The registrant name of the domain. |
| Domain.Registrant.Phone | String | The phone value of the registrant domain. |
| Domain.Malicious.Vendor | String | Vendor that classified the domain as malicious. |
| Domain.Malicious.Description | String | The description as to why the domain was found to be malicious. |
| DomainTools.Domains.Name | String | The DomainTools domain name. |
| DomainTools.Domains.LastEnriched | Date | The last time DomainTools enriched the domain data. |
| DomainTools.Domains.Analytics.OverallRiskScore | Number | The DomainTools Overall Risk Score. |
| DomainTools.Domains.Analytics.ProximityRiskScore | Number | The DomainTools Proximity Risk Score. |
| DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScore | Number | The DomainTools Threat Profile Risk Score. |
| DomainTools.Domains.Analytics.ThreatProfileRiskScore.Threats | String | The DomainTools Threat Profile Threats. |
| DomainTools.Domains.Analytics.ThreatProfileRiskScore.Evidence | String | The DomainTools Threat Profile Evidence. |
| DomainTools.Domains.Analytics.WebsiteResponseCode | Number | The response code of the Website. |
| DomainTools.Domains.Analytics.Tags | String | The DomainTools Tags. |
| DomainTools.Domains.Identity.RegistrantName | String | The name of the registrant. |
| DomainTools.Domains.Identity.RegistrantOrg | String | The organization of the registrant. |
| DomainTools.Domains.Identity.RegistrantContact.Country.value | String | The country value of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Country.count | Number | The county count of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Email.value | String | The Email value of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Email.count | Number | The Email count of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Name.value | String | The name value of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Name.count | Number | The name count of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Phone.value | String | The phone value of the registrant contact. |
| DomainTools.Domains.Identity.RegistrantContact.Phone.count | Number | The phone count of the registrant contact. |
| DomainTools.Domains.Identity.SOAEmail | String | The SOA record Email. |
| DomainTools.Domains.Identity.SSLCertificateEmail | String | The SSL certificate Email. |
| DomainTools.Domains.Identity.AdminContact.Country.value | String | The country value of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Country.count | Number | The country count of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Email.value | String | The Email value of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Email.count | Number | The Email count of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Name.value | String | The name value of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Name.count | Number | The name count of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Phone.value | String | The phone value of the administrator contact. |
| DomainTools.Domains.Identity.AdminContact.Phone.count | Number | The phone count of the administrator contact. |
| DomainTools.Domains.Identity.TechnicalContact.Country.value | String | The country value of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Country.count | Number | The country count of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Email.value | String | The Email value of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Email.count | Number | The Email count of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Name.value | String | The name value of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Name.count | Number | The name count of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Phone.value | String | The phone value of the technical contact. |
| DomainTools.Domains.Identity.TechnicalContact.Phone.count | Number | The phone count of the technical contact. |
| DomainTools.Domains.Identity.BillingContact.Country.value | String | The country value of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Country.count | Number | The country count of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Email.value | String | The Email value of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Email.count | Number | The Email count of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Name.value | String | The name value of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Name.count | Number | The name count of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Phone.value | String | The phone value of the billing contact. |
| DomainTools.Domains.Identity.BillingContact.Phone.count | Number | The phone count of the billing contact. |
| DomainTools.Domains.Identity.EmailDomains | String | The Email domains. |
| DomainTools.Domains.Identity.AdditionalWhoisEmails.value | String | The value of the Additional Whois Emails. |
| DomainTools.Domains.Identity.AdditionalWhoisEmails.count | Number | The count of the Additional Whois Emails. |
| DomainTools.Domains.Registration.DomainRegistrant | String | The registrant of the domain. |
| DomainTools.Domains.Registration.RegistrarStatus | String | The status of the registrar. |
| DomainTools.Domains.Registration.DomainStatus | Boolean | The active status of the domain. |
| DomainTools.Domains.Registration.CreateDate | Date | The date the domain was created. |
| DomainTools.Domains.Registration.ExpirationDate | Date | The expiry date of the domain. |
| DomainTools.Domains.Hosting.IPAddresses.address.value | String | The address value of the IP Addresses. |
| DomainTools.Domains.Hosting.IPAddresses.address.count | Number | The address count of the IP Addresses. |
| DomainTools.Domains.Hosting.IPAddresses.asn.value | String | The ASN value of the IP Addresses. |
| DomainTools.Domains.Hosting.IPAddresses.asn.count | Number | The ASN count of the IP Addresses. |
| DomainTools.Domains.Hosting.IPAddresses.country_code.value | String | The country code of the IP Addresses. |
| DomainTools.Domains.Hosting.IPAddresses.country_code.count | Number | The country code count of the IP Addresses. |
| DomainTools.Domains.Hosting.IPAddresses.isp.value | String | ISP value of the IP Addresses. |
| DomainTools.Domains.Hosting.IPAddresses.isp.count | Number | The ISP count of the IP Addresses. |
| DomainTools.Domains.Hosting.IPCountryCode | String | The country code of the IP address. |
| DomainTools.Domains.Hosting.MailServers.domain.value | String | The domain value of the Mail Servers. |
| DomainTools.Domains.Hosting.MailServers.domain.count | Number | The domain count of the Mail Servers. |
| DomainTools.Domains.Hosting.MailServers.host.value | String | The host value of the Mail Servers. |
| DomainTools.Domains.Hosting.MailServers.host.count | Number | The host count of the Mail Servers. |
| DomainTools.Domains.Hosting.MailServers.ip.value | String | The IP value of the Mail Servers. |
| DomainTools.Domains.Hosting.MailServers.ip.count | Number | The IP count of the Mail Servers. |
| DomainTools.Domains.Hosting.SPFRecord | String | The SPF Record. |
| DomainTools.Domains.Hosting.NameServers.domain.value | String | The domain value of the DomainTools Domains NameServers. |
| DomainTools.Domains.Hosting.NameServers.domain.count | Number | The domain count of the DomainTools Domains NameServers. |
| DomainTools.Domains.Hosting.NameServers.host.value | String | The host value of the DomainTools Domains NameServers. |
| DomainTools.Domains.Hosting.NameServers.host.count | Number | The host count of the DomainTools Domains NameServers. |
| DomainTools.Domains.Hosting.NameServers.ip.value | String | The IP value of the DomainTools Domains NameServers. |
| DomainTools.Domains.Hosting.NameServers.ip.count | Number | The IP count of the DomainTools Domains NameServers. |
| DomainTools.Domains.Hosting.SSLCertificate.hash.value | String | The hash value of the SSL certificate. |
| DomainTools.Domains.Hosting.SSLCertificate.hash.count | Number | The hash count of the SSL certificate. |
| DomainTools.Domains.Hosting.SSLCertificate.organization.value | String | The organization value of the SSL certificate. |
| DomainTools.Domains.Hosting.SSLCertificate.organization.count | Number | The organization count of the SSL certificate. |
| DomainTools.Domains.Hosting.SSLCertificate.subject.value | String | The subject value of the SSL certificate. |
| DomainTools.Domains.Hosting.SSLCertificate.subject.count | Number | The subject count of the SSL certificate. |
| DomainTools.Domains.Hosting.RedirectsTo.value | String | The Redirects To value of the domain. |
| DomainTools.Domains.Hosting.RedirectsTo.count | Number | The Redirects To count of the domain. |
| DomainTools.Domains.Analytics.GoogleAdsenseTrackingCode | Number | The tracking code of Google Adsense. |
| DomainTools.Analytics.GoogleAnalyticTrackingCode | Number | The tracking code of Google Analytics. |
| DomainTools.Domains.Analytics.GA4TrackingCode | Number | The tracking code of ga4. |
| DomainTools.Domains.Analytics.GTMTrackingCode | Number | The tracking code of gtm. |
| DomainTools.Domains.Analytics.FBTrackingCode | Number | The tracking code of fb. |
| DomainTools.Domains.Analytics.HotJarTrackingCode | Number | The tracking code of Hot Jar. |
| DomainTools.Domains.Analytics.BaiduTrackingCode | Number | The tracking code of Baidu. |
| DomainTools.Domains.Analytics.YandexTrackingCode | Number | The tracking code of Yandex. |
| DomainTools.Domains.Analytics.MatomoTrackingCode | Number | The tracking code of Matomo. |
| DomainTools.Domains.Analytics.StatcounterProjectTrackingCode | Number | The tracking code of Stat Counter Project. |
| DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode | Number | The tracking code of Stat Counter Security. |
| DBotScore.Indicator | String | The DBotScore indicator. |
| DBotScore.Type | String | The indicator type of the DBotScore. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| DBotScore.Score | Number | The actual score. |
domaintoolsiris-pivot
Pivot on connected infrastructure (IP, email, SSL), or import domains from Iris Investigate using a search hash. Retrieves up to 5000 domains at a time. Optionally exclude results from context with include_context=false.
Base Command
domaintoolsiris-pivot
Input
| Argument Name | Description | Required |
|---|---|---|
| ip | The IP Address. | Optional |
| The Email Address. | Optional | |
| nameserver_ip | The Name Server IP Address. | Optional |
| ssl_hash | The hash of the SSL. | Optional |
| nameserver_host | The fully-qualified host name of the name server. For example, ns1.domaintools.net. | Optional |
| mailserver_host | The fully-qualified host name of the mail server. For example, mx.domaintools.net. | Optional |
| email_domain | Only the domain portion of a Whois or DNS SOA email address. | Optional |
| nameserver_domain | Registered domain portion of the name server. | Optional |
| registrar | Exact match to the Whois registrar field. | Optional |
| registrant | Exact match to the Whois registrant field. | Optional |
| registrant_org | Exact match to the Whois registrant organization field. | Optional |
| tagged_with_any | Comma-separated list of Iris Investigate tags. Returns domains tagged with any of the tags in a list. | Optional |
| tagged_with_all | Comma-separated list of tags. Only returns domains tagged with the full list of tags. | Optional |
| mailserver_domain | Only the registered domain portion of the mail server (domaintools.net). | Optional |
| mailserver_ip | IP address of the mail server. | Optional |
| redirect_domain | Find domains observed to redirect to another domain name. | Optional |
| ssl_org | Exact match to the organization name on the SSL certificate. | Optional |
| ssl_subject | Subject field from the SSL certificate. | Optional |
| ssl_email | Email address from the SSL certificate. | Optional |
| google_analytics | Domains with a Google Analytics tracking code. | Optional |
| adsense | Domains with a Google AdSense tracking code. | Optional |
| search_hash | Encoded search from the Iris UI. | Optional |
| include_context | Include the results of the pivot in Context Data. Defaults to true. Possible values are: true, false. Default is true. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| DomainTools.Pivots.PivotedDomains.Name | String | The DomainTools Domain Name. |
| DomainTools.Pivots.PivotedDomains.LastEnriched | Date | The last time DomainTools enriched the domain data. |
| DomainTools.Pivots.PivotedDomains.Analytics.OverallRiskScore | Number | The DomainTools Overall Risk Score. |
| DomainTools.Pivots.PivotedDomains.Analytics.ProximityRiskScore | Number | The DomainTools Proximity Risk Score. |
| DomainTools.Pivots.PivotedDomains.Analytics.ThreatProfileRiskScore.RiskScore | Number | The DomainTools Threat Profile Risk Score. |
| DomainTools.Pivots.PivotedDomains.Analytics.ThreatProfileRiskScore.Threats | String | The DomainTools Threat Profile Threats. |
| DomainTools.Pivots.PivotedDomains.Analytics.ThreatProfileRiskScore.Evidence | String | The DomainTools Threat Profile Evidence. |
| DomainTools.Pivots.PivotedDomains.Analytics.WebsiteResponseCode | Number | The response code of the website. |
| DomainTools.Pivots.PivotedDomains.Analytics.Tags | String | The DomainTools tags. |
| DomainTools.Pivots.PivotedDomains.Identity.RegistrantName | String | The name of the registrant. |
| DomainTools.Pivots.PivotedDomains.Identity.RegistrantOrg | String | The organization of the registrant. |
| DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Country.value | String | The country value of the registrant contact. |
| DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Country.count | Number | The country count of the registrant contact. |
| DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Email.value | String | The Email value of the registrant contact. |
| DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Email.count | Number | The Email count of the registrant contact. |
| DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Name.value | String | The name value of the registrant contact. |
| DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Name.count | Number | The name count of the registrant contact. |
| DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Phone.value | String | The phone value of of the registrant contact. |
| DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Phone.count | Number | The phone count of the registrant contact. |
| DomainTools.Pivots.PivotedDomains.Identity.SOAEmail | String | The SOA record Email. |
| DomainTools.Pivots.PivotedDomains.Identity.SSLCertificateEmail | String | The SSL certificate Email. |
| DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Country.value | String | The country value of the administrator contact. |
| DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Country.count | Number | The country count of the administrator contact. |
| DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Email.value | String | The Email value of the administrator contact. |
| DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Email.count | Number | The Email count of the administrator contact. |
| DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Name.value | String | The name value of the administrator contact. |
| DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Name.count | Number | The name count of the administrator contact. |
| DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Phone.value | String | The phone value of the administrator contact. |
| DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Phone.count | Number | The phone count of the administrator contact. |
| DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Country.value | String | The country value of the technical contact. |
| DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Country.count | Number | The country count of the technical contact. |
| DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Email.value | String | The Email value of the technical contact. |
| DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Email.count | Number | The Email count of the technical contact. |
| DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Name.value | String | The name value of the technical contact. |
| DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Name.count | Number | The name count of the technical contact. |
| DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Phone.value | String | The phone value of the technical contact. |
| DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Phone.count | Number | The phone count of the technical contact. |
| DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Country.value | String | The country value of the billing contact. |
| DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Country.count | Number | The country count of the billing contact. |
| DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Email.value | String | The Email value of the billing contact. |
| DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Email.count | Number | The Email count of the billing contact. |
| DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Name.value | String | The Name value of the billing contact. |
| DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Name.count | Number | The Name count of the billing contact. |
| DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Phone.value | String | The phone value of the billing contact. |
| DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Phone.count | Number | The phone count of the billing contact. |
| DomainTools.Pivots.PivotedDomains.Identity.EmailDomains | String | The Email domains. |
| DomainTools.Pivots.PivotedDomains.Identity.AdditionalWhoisEmails.value | String | The value of the Additional Whois Emails. |
| DomainTools.Pivots.PivotedDomains.Identity.AdditionalWhoisEmails.count | Number | The count of the Additional Whois Emails. |
| DomainTools.Pivots.PivotedDomains.Registration.DomainRegistrant | String | The Registrant of the domain. |
| DomainTools.Pivots.PivotedDomains.Registration.RegistrarStatus | String | The status of the registrar. |
| DomainTools.Pivots.PivotedDomains.Registration.DomainStatus | Boolean | The active status of the registrar. |
| DomainTools.Pivots.PivotedDomains.Registration.CreateDate | Date | The date the domain was created. |
| DomainTools.Pivots.PivotedDomains.Registration.ExpirationDate | Date | The Expiry date of the domain. |
| DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.address.value | String | The address value of IP addresses. |
| DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.address.count | Number | The address count of IP addresses. |
| DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.asn.value | String | The ASN value of IP addresses. |
| DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.asn.count | Number | The ASN count of IP addresses. |
| DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.country_code.value | String | The country code value of IP addresses. |
| DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.country_code.count | Number | The country code count of IP addresses. |
| DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.isp.value | String | The ISP value of IP addresses. |
| DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.isp.count | Number | The ISP count of IP addresses. |
| DomainTools.Pivots.PivotedDomains.Hosting.IPCountryCode | String | The country code of the IP address. |
| DomainTools.Pivots.PivotedDomains.Hosting.MailServers.domain.value | String | The domain value of the Mail Servers. |
| DomainTools.Pivots.PivotedDomains.Hosting.MailServers.domain.count | Number | The domain count of the Mail Servers. |
| DomainTools.Pivots.PivotedDomains.Hosting.MailServers.host.value | String | The host value of the Mail Servers. |
| DomainTools.Pivots.PivotedDomains.Hosting.MailServers.host.count | Number | The host count of the Mail Servers. |
| DomainTools.Pivots.PivotedDomains.Hosting.MailServers.ip.value | String | The IP address value of the Mail Servers. |
| DomainTools.Pivots.PivotedDomains.Hosting.MailServers.ip.count | Number | The IP address count of the Mail Servers. |
| DomainTools.Pivots.PivotedDomains.Hosting.SPFRecord | String | The SPF record Information. |
| DomainTools.Pivots.PivotedDomains.Hosting.NameServers.domain.value | String | The domain value of DomainTools Domains NameServers. |
| DomainTools.Pivots.PivotedDomains.Hosting.NameServers.domain.count | Number | The domain count of DomainTools Domains NameServers. |
| DomainTools.Pivots.PivotedDomains.Hosting.NameServers.host.value | String | The host value of DomainTools Domains NameServers. |
| DomainTools.Pivots.PivotedDomains.Hosting.NameServers.host.count | Number | The host count of DomainTools Domains NameServers. |
| DomainTools.Pivots.PivotedDomains.Hosting.NameServers.ip.value | String | The IP address value of DomainTools Domains NameServers. |
| DomainTools.Pivots.PivotedDomains.Hosting.NameServers.ip.count | Number | The IP address count of DomainTools Domains NameServers. |
| DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.hash.value | String | The hash value of the SSL certificate. |
| DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.hash.count | Number | The hash count of the SSL certificate. |
| DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.organization.value | String | The organization value of the SSL certificate. |
| DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.organization.count | Number | The organization count of the SSL certificate. |
| DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.subject.value | String | The subject value of the SSL certificate. |
| DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.subject.count | Number | The subject count of the SSL certificate. |
| DomainTools.Pivots.PivotedDomains.Hosting.RedirectsTo.value | String | The Redirects To value of the domain. |
| DomainTools.Pivots.PivotedDomains.Hosting.RedirectsTo.count | Number | The Redirects To count of the domain. |
| DomainTools.Pivots.PivotedDomains.Analytics.GoogleAdsenseTrackingCode | Number | The tracking code of Google Adsense. |
| DomainTools.Pivots.PivotedDomains.Analytics.GoogleAnalyticTrackingCode | Number | The tracking code Google Analytics. |
domaintools-whois-history
The DomainTools Whois History API endpoint returns up to 100 historical Whois records associated with a domain name.
Base Command
domaintools-whois-history
Input
| Argument Name | Description | Required |
|---|---|---|
| domain | A domain name to query (e.g. example.com). | Required |
| mode | options: list, count, check_existence. list: (default), return whois records. count: return how many total records are available. check_existence: return if any records exist. Default: list. Possible values are: list, count, check_existence. Default is list. | Optional |
| offset | numeric, the index from which to begin retrieving results. Default: 0. Default is 0. | Optional |
| limit | numeric, default: 100, max: 100, the total number of records to return. Default: 100. Default is 100. | Optional |
| sort | options: date_desc, date_asc. date_desc: (default), order records from newest to oldest. date_asc: sort order records from oldest to newest. Default: date_desc. Possible values are: date_desc, date_asc. Default is date_desc. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| DomainTools.History.Value | unknown | Name of domain. |
| DomainTools.History.WhoisHistory | unknown | Domain Whois history data. |
domaintools-hosting-history
Hosting History will list IP address, name server and registrar history.
Base Command
domaintools-hosting-history
Input
| Argument Name | Description | Required |
|---|---|---|
| domain | A domain name to query (e.g. example.com). | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| DomainTools.History.Value | unknown | Name of domain. |
| DomainTools.History.IPHistory | unknown | Domain IP history data. |
| DomainTools.History.NameserverHistory | unknown | Domain Nameserver history data. |
| DomainTools.History.RegistrarHistory | unknown | Domain Registrar history data. |
domaintools-reverse-whois
The DomainTools Reverse Whois API provides a list of domain names that share the same Registrant Information. You can enter terms that describe a domain owner, like an email address or a company name, and you’ll get a list of domain names that have your search terms listed in the Whois record.
Base Command
domaintools-reverse-whois
Input
| Argument Name | Description | Required |
|---|---|---|
| terms | (default) List of one or more terms to search for in the Whois record, separated with the pipe character ( | ). | Required |
| exclude | Domain names with Whois records that match these terms will be excluded from the result set. Separate multiple terms with the pipe character ( | ). | Optional |
| onlyHistoricScope | Show only historic records. Possible values are: true, false. Default is false. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| DomainTools.ReverseWhois.Value | unknown | Search term to reverse whois lookup on. |
| DomainTools.ReverseWhois.Results | unknown | List of results for reverse whois lookup. |
domaintools-whois
The DomainTools Parsed Whois API provides parsed information extracted from the raw Whois record. The API is optimized to quickly retrieve the Whois record, group important data together and return a well-structured format. The Parsed Whois API is ideal for anyone wishing to search for, index, or cross-reference data from one or multiple Whois records.
Base Command
domaintools-whois
Input
| Argument Name | Description | Required |
|---|---|---|
| query | A domain name or IP address (e.g. example.com or 192.168.1.1). | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Domain.Name | unknown | Requested domain name. |
| Domain.Whois | unknown | Parsed Whois data. |
| Domain.WhoisRecords | unknown | Full Whois record. |
domainRdap
Returns the most recent Domain-RDAP registration record.
Base Command
domainRdap
Input
| Argument Name | Description | Required |
|---|---|---|
| domain | Specify the domain (e.g., mycompany.com). | Required |
Context Output
There is no context output for this command.
reverseNameServer
Reverse nameserver lookup.
Base Command
reverseNameServer
Input
| Argument Name | Description | Required |
|---|---|---|
| nameServer | Specify the name of the primary or secondary nameserver. | Required |
| limit | Limit the size of the domain list than can appear in a response. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Domain.Name | unknown | Name of the domain returned by the query. |
reverseIP
Reverse loopkup of an IP address or a domain.
Base Command
reverseIP
Input
| Argument Name | Description | Required |
|---|---|---|
| ip | Specify the IP address to query. | Optional |
| domain | If a domain name is provided, DomainTools will respond with the list of other domains that share the same IP. | Optional |
| limit | Limits the size of the domain list than can appear in a response. The limit is applied per-IP address, not for the entire request. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Domain.Name | unknown | Domain name returned by the query. |
| Domain.DNS.Address | unknown | The IP address associated with the returned domains. |
Configuration parameters
credentials— API Usernameusername— API Usernameapikey— API Keyrisk_threshold— High-Risk Threshold (required)young_domain_timeframe— Young Domain Timeframe (within Days) (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingsdomain_result_type— Domain Result Typedomain_enrichment_method— Domain Enrichment Method (DomainTools)domain_auto_enrich— Domain Auto-Enrich on IngestionintegrationReliability— Source ReliabilityfeedExpirationPolicy—feedExpirationInterval—pivot_threshold— Guided Pivot Threshold (required)monitor_iris_search_hash— Enabled on Monitoring Domains by Iris Search Hashdomaintools_iris_search_hash— Domaintools Iris Investigate Search Hashmonitor_iris_tags— Enabled on Monitoring Domains by Iris Tagsdomaintools_iris_tags— Domaintools Iris Tagsmax_fetch— Maximum number of incidents to fetchincidentType— Incident typeincidentFetchInterval— Incidents Fetch IntervalisFetch— Fetch incidentsfirst_fetch— First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
Commands (13)
-
domainProvides data enrichment for domains.
-
domainRdapReturns the most recent Domain-RDAP registration record.
-
domaintools-hosting-historyHosting History will list IP address, name server and registrar history.
-
domaintools-reverse-whoisThe DomainTools Reverse Whois API provides a list of domain names that share the same Registrant Information. You can enter terms that describe a domain owner, like an email address or a company name, and you’ll get a list of domain names that have your search terms listed in the Whois record.
-
domaintools-whoisThe DomainTools Parsed Whois API provides parsed information extracted from the raw Whois record. The API is optimized to quickly retrieve the Whois record, group important data together and return a well-structured format. The Parsed Whois API is ideal for anyone wishing to search for, index, or cross-reference data from one or multiple Whois records.
-
domaintools-whois-historyThe DomainTools Whois History API endpoint returns up to 100 historical Whois records associated with a domain name.
-
domaintoolsiris-analyticsDisplays DomainTools Analytic data in a markdown format table.
-
domaintoolsiris-enrichReturns a complete profile of the domain (SLD.TLD) using Iris Enrich. If parsing of URLs or FQDNs is desired, see domainExtractAndEnrich.
-
domaintoolsiris-investigateReturns a complete profile of the domain (SLD.TLD) using Iris Investigate. If parsing of FQDNs is desired, see domainExtractAndInvestigate.
-
domaintoolsiris-pivotPivot on connected infrastructure (IP, email, SSL), or import domains from Iris Investigate using a search hash. Retrieves up to 5000 domains at a time. Optionally exclude results from context with include_context=false.
-
domaintoolsiris-threat-profileDisplays DomainTools Threat Profile data in a markdown format table.
-
reverseIPReverse loopkup of an IP address or a domain.
-
reverseNameServerReverse nameserver lookup.
category: Data Enrichment & Threat Intelligence provider: DomainTools commonfields: id: DomainTools Iris version: -1 configuration: - display: API Username name: credentials type: 9 required: false displaypassword: API Key section: Connect - display: API Username name: username required: false hidden: true type: 0 section: Connect - display: API Key name: apikey required: false hidden: true type: 4 section: Connect - display: High-Risk Threshold name: risk_threshold required: true type: 0 defaultvalue: '70' section: Connect - defaultvalue: '7' display: Young Domain Timeframe (within Days) name: young_domain_timeframe required: true type: 0 section: Connect - display: Trust any certificate (not secure) name: insecure required: false type: 8 section: Connect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - display: Domain Result Type name: domain_result_type type: 15 required: false additionalinfo: "Result type of the domain command: Iris returns full investigate results; Verdict returns only the domain risk score" defaultvalue: Iris options: - Iris - Verdict section: Collect - defaultvalue: Iris Investigate display: 'Domain Enrichment Method (DomainTools)' name: domain_enrichment_method options: - Iris Investigate - Iris Enrich type: 15 required: false section: Collect additionalinfo: "Iris API to be used for domain enrichment. Defaults to Iris Investigate." - defaultvalue: 'Disabled' name: domain_auto_enrich display: 'Domain Auto-Enrich on Ingestion' type: 15 required: false section: Collect options: - Enabled - Disabled additionalinfo: "Enable real-time enrichment for incoming ingested domain. Note: This may consume Iris API quotas." - defaultvalue: 'B - Usually reliable' name: integrationReliability display: 'Source Reliability' type: 15 required: false section: Collect options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged additionalinfo: Reliability of the source providing the intelligence data. - display: '' name: feedExpirationPolicy defaultvalue: 'indicatorType' type: 17 required: false section: Collect options: - never - interval - indicatorType - suddenDeath - display: '' name: feedExpirationInterval type: 1 required: false section: Collect defaultvalue: '20160' - display: 'Guided Pivot Threshold' name: pivot_threshold type: 1 required: true section: Connect additionalinfo: When a small set of domains share an attribute (e.g. registrar), that can often be pivoted on in order to find other similar domains of interest. DomainTools tracks how many domains share each attribute and can highlight it for further investigation when the number of domains is beneath the set threshold. defaultvalue: 500 - display: 'Enabled on Monitoring Domains by Iris Search Hash' name: monitor_iris_search_hash type: 15 required: false section: Collect defaultvalue: Import Indicators Only options: - Import Indicators Only - Create Incident and Import Indicators - display: 'Domaintools Iris Investigate Search Hash' name: domaintools_iris_search_hash required: false type: 12 additionalinfo: The DomainTools Iris Investigate Search hash section: Collect - display: 'Enabled on Monitoring Domains by Iris Tags' name: monitor_iris_tags type: 15 section: Collect defaultvalue: 'Import Indicators Only' required: false options: - Import Indicators Only - Create Incident and Import Indicators - display: Domaintools Iris Tags name: domaintools_iris_tags type: 12 section: Collect required: false additionalinfo: The DomainTools Iris Tags (Values should be a comma separated value. e.g. (tag1,tag2)) - display: Maximum number of incidents to fetch name: max_fetch type: 0 section: Collect defaultvalue: '2' required: false additionalinfo: This is a required field by XSOAR and should be set to 2, one for each possible feed type iris search hash and iris tags. - display: Incident type name: incidentType type: 13 section: Collect - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: '1' required: false type: 19 section: Collect advanced: true - display: Fetch incidents name: isFetch type: 8 section: Collect - display: First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) defaultvalue: 7 days name: first_fetch required: false type: 0 additionalinfo: How far back in time to go when performing the first fetch. section: Collect description: Together, DomainTools and Cortex XSOAR automate and orchestrate the incident response process with essential domain profile, web crawl, SSL and infrastructure data. SOCs can create custom, automated workflows to trigger Indicator of Compromise (IoC) investigations, block threats based on connected infrastructure, and identify potentially malicious domains before weaponization. The DomainTools App for Cortex XSOAR is shipped with pre-built playbooks to enable automated enrichment, decision logic, ad-hoc investigations, and the ability to persist enriched intelligence. display: DomainTools Iris name: DomainTools Iris script: commands: - arguments: - default: true description: The domain to enrich. name: domain required: true isArray: false secret: false - name: bypass_auto_enrich description: Bypasses the Domain Auto-Enrich on Ingestion. default: false required: false isArray: false secret: false auto: PREDEFINED predefined: - "true" - "false" defaultValue: "false" description: Provides data enrichment for domains. name: domain outputs: - contextPath: Domain.Name description: The name of the domain. type: String - contextPath: Domain.DNS description: The DNS of the domain. type: String - contextPath: Domain.DomainStatus description: The status of the domain. type: Boolean - contextPath: Domain.CreationDate description: The creation date. type: Date - contextPath: Domain.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.NameServers description: The nameServers of the domain. type: String - contextPath: Domain.Registrant.Country description: The registrant country of the domain. type: String - contextPath: Domain.Registrant.Email description: The registrant email of the domain. type: String - contextPath: Domain.Registrant.Name description: The registrant name of the domain. type: String - contextPath: Domain.Registrant.Phone description: The registrant phone number of the domain. type: String - contextPath: Domain.Malicious.Vendor description: The vendor who classified the domain as malicious. type: String - contextPath: Domain.Malicious.Description description: The description as to why the domain was found to be malicious. type: String - contextPath: DomainTools.Name description: The domain name in DomainTools. type: String - contextPath: DomainTools.LastEnriched description: The last Time DomainTools enriched domain data. type: Date - contextPath: DomainTools.Analytics.OverallRiskScore description: The Overall Risk Score in DomainTools. type: Number - contextPath: DomainTools.Analytics.ProximityRiskScore description: The Proximity Risk Score in DomainTools. type: Number - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.RiskScore description: The Threat Profile Risk Score in DomainTools. type: Number - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.Threats description: The threats of the Threat Profile Risk Score in DomainTools. type: String - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.Evidence description: The Threat Profile Risk Score Evidence in DomainTools. type: String - contextPath: DomainTools.Analytics.WebsiteResponseCode description: The Website Response Code in DomainTools. type: Number - contextPath: DomainTools.Analytics.Tags description: The Tags in DomainTools. type: String - contextPath: DomainTools.Identity.RegistrantName description: The name of the registrant. type: String - contextPath: DomainTools.Identity.RegistrantOrg description: The organization of the registrant. type: String - contextPath: DomainTools.Identity.RegistrantContact.Country.value description: The country value of the registrant contact. type: String - contextPath: DomainTools.Identity.RegistrantContact.Country.count description: The count of the registrant contact country. type: Number - contextPath: DomainTools.Identity.RegistrantContact.Email.value description: The Email value of the registrant contact. type: String - contextPath: DomainTools.Identity.RegistrantContact.Email.count description: The Email count of the registrant contact. type: Number - contextPath: DomainTools.Identity.RegistrantContact.Name.value description: The name value of the registrant contact. type: String - contextPath: DomainTools.Identity.RegistrantContact.Name.count description: The name count of the registrant contact. type: Number - contextPath: DomainTools.Identity.RegistrantContact.Phone.value description: The phone value of the registrant contact. type: String - contextPath: DomainTools.Identity.RegistrantContact.Phone.count description: The phone count of the registrant contact. type: Number - contextPath: DomainTools.Identity.SOAEmail description: The SOA record of the Email. type: String - contextPath: DomainTools.Identity.SSLCertificateEmail description: The Email of the SSL certificate. type: String - contextPath: DomainTools.Identity.AdminContact.Country.value description: The country value of the administrator contact. type: String - contextPath: DomainTools.Identity.AdminContact.Country.count description: The country count of the administrator contact. type: Number - contextPath: DomainTools.Identity.AdminContact.Email.value description: The Email value of the administrator contact. type: String - contextPath: DomainTools.Identity.AdminContact.Email.count description: The Email count of the administrator contact. type: Number - contextPath: DomainTools.Identity.AdminContact.Name.value description: The name value of the administrator contact. type: String - contextPath: DomainTools.Identity.AdminContact.Name.count description: The name count of the administrator contact. type: Number - contextPath: DomainTools.Identity.AdminContact.Phone.value description: The phone value of the administrator contact. type: String - contextPath: DomainTools.Identity.AdminContact.Phone.count description: The phone count of the administrator contact. type: Number - contextPath: DomainTools.Identity.TechnicalContact.Country.value description: The country value of the technical contact. type: String - contextPath: DomainTools.Identity.TechnicalContact.Country.count description: The country count of the technical contact. type: Number - contextPath: DomainTools.Identity.TechnicalContact.Email.value description: The Email value of the technical contact. type: String - contextPath: DomainTools.Identity.TechnicalContact.Email.count description: The Email count of the technical contact. type: Number - contextPath: DomainTools.Identity.TechnicalContact.Name.value description: The name value of the technical Contact. type: String - contextPath: DomainTools.Identity.TechnicalContact.Name.count description: The name count of the technical contact. type: Number - contextPath: DomainTools.Identity.TechnicalContact.Phone.value description: The phone value of the technical contact. type: String - contextPath: DomainTools.Identity.TechnicalContact.Phone.count description: The phone count of the technical contact. type: Number - contextPath: DomainTools.Identity.BillingContact.Country.value description: The country value of the billing contact. type: String - contextPath: DomainTools.Identity.BillingContact.Country.count description: The country count of the billing contact. type: Number - contextPath: DomainTools.Identity.BillingContact.Email.value description: The Email value of the billing contact. type: String - contextPath: DomainTools.Identity.BillingContact.Email.count description: The Email count of the billing contact. type: Number - contextPath: DomainTools.Identity.BillingContact.Name.value description: The name value of the billing contact. type: String - contextPath: DomainTools.Identity.BillingContact.Name.count description: The name count of the billing contact. type: Number - contextPath: DomainTools.Identity.BillingContact.Phone.value description: The phone value of the billing contact. type: String - contextPath: DomainTools.Identity.BillingContact.Phone.count description: The phone count of the billing contact. type: Number - contextPath: DomainTools.Identity.EmailDomains description: The Email Domains. type: String - contextPath: DomainTools.Identity.AdditionalWhoisEmails.value description: The value of the Additional Whois Emails record. type: String - contextPath: DomainTools.Identity.AdditionalWhoisEmails.count description: The count of the Additional Whois Emails record. type: Number - contextPath: DomainTools.Registration.DomainRegistrant description: The registrant of the domain. type: String - contextPath: DomainTools.Registration.RegistrarStatus description: The status of the registrar. type: String - contextPath: DomainTools.Registration.DomainStatus description: The active status of the domain. type: Boolean - contextPath: DomainTools.Registration.CreateDate description: The date the domain was created. type: Date - contextPath: DomainTools.Registration.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: DomainTools.Hosting.IPAddresses.address.value description: The address value of IP addresses. type: String - contextPath: DomainTools.Hosting.IPAddresses.address.count description: The address count of IP addresses. type: Number - contextPath: DomainTools.Hosting.IPAddresses.asn.value description: The ASN value of IP addresses. type: String - contextPath: DomainTools.Hosting.IPAddresses.asn.count description: The ASN count of IP addresses. type: Number - contextPath: DomainTools.Hosting.IPAddresses.country_code.value description: The country code value of IP addresses. type: String - contextPath: DomainTools.Hosting.IPAddresses.country_code.count description: The country code count of IP addresses. type: Number - contextPath: DomainTools.Hosting.IPAddresses.isp.value description: The ISP value of IP addresses. type: String - contextPath: DomainTools.Hosting.IPAddresses.isp.count description: The ISP count of IP addresses. type: Number - contextPath: DomainTools.Hosting.IPCountryCode description: The country code of the IP address. type: String - contextPath: DomainTools.Hosting.MailServers.domain.value description: The domain value of the Mail Servers. type: String - contextPath: DomainTools.Hosting.MailServers.domain.count description: The domain count of the Mail Servers. type: Number - contextPath: DomainTools.Hosting.MailServers.host.value description: The host value of the Mail Servers. type: String - contextPath: DomainTools.Hosting.MailServers.host.count description: The host count of the Mail Servers. type: Number - contextPath: DomainTools.Hosting.MailServers.ip.value description: The IP value of the Mail Servers. type: String - contextPath: DomainTools.Hosting.MailServers.ip.count description: The IP count of the Mail Servers. type: Number - contextPath: DomainTools.Hosting.SPFRecord description: The SPF Record. type: String - contextPath: DomainTools.Hosting.NameServers.domain.value description: The domain value of the domain NameServers. type: String - contextPath: DomainTools.Hosting.NameServers.domain.count description: The domain count of the domain NameServers. type: Number - contextPath: DomainTools.Hosting.NameServers.host.value description: The host value of the domain NameServers. type: String - contextPath: DomainTools.Hosting.NameServers.host.count description: The host count of the domain NameServers. type: Number - contextPath: DomainTools.Hosting.NameServers.ip.value description: The IP value of the domain NameServers. type: String - contextPath: DomainTools.Hosting.NameServers.ip.count description: The IP count of domain NameServers. type: Number - contextPath: DomainTools.Hosting.SSLCertificate.hash.value description: The hash value of the SSL certificate. type: String - contextPath: DomainTools.Hosting.SSLCertificate.hash.count description: The hash count of the SSL certificate. type: Number - contextPath: DomainTools.Hosting.SSLCertificate.organization.value description: The organization value of the SSL certificate. type: String - contextPath: DomainTools.Hosting.SSLCertificate.organization.count description: The organization count of the SSL certificate information. type: Number - contextPath: DomainTools.Hosting.SSLCertificate.subject.value description: The subject value of the SSL certificate information. type: String - contextPath: DomainTools.Hosting.SSLCertificate.subject.count description: The subject count of the SSL certificate information. type: Number - contextPath: DomainTools.Hosting.RedirectsTo.value description: The Redirects To Value of the domain. type: String - contextPath: DomainTools.Hosting.RedirectsTo.count description: The Redirects To Count of the domain. type: Number - contextPath: DomainTools.Analytics.GoogleAdsenseTrackingCode description: The tracking code of Google Adsense. type: Number - contextPath: DomainTools.Analytics.GoogleAnalyticTrackingCode description: The tracking code of Google Analytics. type: Number - contextPath: DomainTools.Domains.Analytics.GA4TrackingCode description: The tracking code of ga4. type: Number - contextPath: DomainTools.Domains.Analytics.GTMTrackingCode description: The tracking code of gtm. type: Number - contextPath: DomainTools.Domains.Analytics.FBTrackingCode description: The tracking code of fb. type: Number - contextPath: DomainTools.Domains.Analytics.HotJarTrackingCode description: The tracking code of Hot Jar. type: Number - contextPath: DomainTools.Domains.Analytics.BaiduTrackingCode description: The tracking code of Baidu. type: Number - contextPath: DomainTools.Domains.Analytics.YandexTrackingCode description: The tracking code of Yandex. type: Number - contextPath: DomainTools.Domains.Analytics.MatomoTrackingCode description: The tracking code of Matomo. type: Number - contextPath: DomainTools.Domains.Analytics.StatcounterProjectTrackingCode description: The tracking code of Stat Counter Project. type: Number - contextPath: DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode description: The tracking code of Stat Counter Security. type: Number - contextPath: DomainTools.WebsiteTitle description: The website title. type: Number - contextPath: DomainTools.FirstSeen description: The date the domain was first seen. type: Number - contextPath: DomainTools.ServerType description: The server type. type: Number - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number deprecated: false execution: false - arguments: - description: Specify the domain (e.g., mycompany.com). name: domain required: true default: true isArray: false secret: false description: Returns the most recent Domain-RDAP registration record. name: domainRdap deprecated: false execution: false - arguments: - description: The domain name (SLD.TLD) to Investigate. Supports up to 1,000 comma-separated domains. name: domain required: true default: true isArray: false secret: false - default: false description: Include the investigate results in Context Data. Defaults to true. isArray: false name: include_context required: false secret: false type: String predefined: - "true" - "false" auto: PREDEFINED defaultValue: "true" description: Returns a complete profile of the domain (SLD.TLD) using Iris Investigate. If parsing of FQDNs is desired, see domainExtractAndInvestigate. name: domaintoolsiris-investigate outputs: - contextPath: Domain.Name description: The name of the domain. type: String - contextPath: Domain.DNS description: The DNS of the domain. type: String - contextPath: Domain.DomainStatus description: The status of the domain. type: Boolean - contextPath: Domain.CreationDate description: The creation date. type: Date - contextPath: Domain.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.NameServers description: The nameServers of the domain. type: String - contextPath: Domain.Registrant.Country description: The registrant country of the domain. type: String - contextPath: Domain.Registrant.Email description: The registrant email of the domain. type: String - contextPath: Domain.Registrant.Name description: The registrant name of the domain. type: String - contextPath: Domain.Registrant.Phone description: The registrant phone number of the domain. type: String - contextPath: Domain.Malicious.Vendor description: The vendor who classified the domain as malicious. type: String - contextPath: Domain.Malicious.Description description: The description as to why the domain was found to be malicious. type: String - contextPath: DomainTools.Name description: The domain name in DomainTools. type: String - contextPath: DomainTools.LastEnriched description: The last Time DomainTools enriched domain data. type: Date - contextPath: DomainTools.Analytics.OverallRiskScore description: The Overall Risk Score in DomainTools. type: Number - contextPath: DomainTools.Analytics.ProximityRiskScore description: The Proximity Risk Score in DomainTools. type: Number - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.RiskScore description: The Threat Profile Risk Score in DomainTools. type: Number - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.Threats description: The threats of the Threat Profile Risk Score in DomainTools. type: String - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.Evidence description: The Threat Profile Risk Score Evidence in DomainTools. type: String - contextPath: DomainTools.Analytics.WebsiteResponseCode description: The Website Response Code in DomainTools. type: Number - contextPath: DomainTools.Analytics.Tags description: The Tags in DomainTools. type: String - contextPath: DomainTools.Identity.RegistrantName description: The name of the registrant. type: String - contextPath: DomainTools.Identity.RegistrantOrg description: The organization of the registrant. type: String - contextPath: DomainTools.Identity.RegistrantContact.Country.value description: The country value of the registrant contact. type: String - contextPath: DomainTools.Identity.RegistrantContact.Country.count description: The count of the registrant contact country. type: Number - contextPath: DomainTools.Identity.RegistrantContact.Email.value description: The Email value of the registrant contact. type: String - contextPath: DomainTools.Identity.RegistrantContact.Email.count description: The Email count of the registrant contact. type: Number - contextPath: DomainTools.Identity.RegistrantContact.Name.value description: The name value of the registrant contact. type: String - contextPath: DomainTools.Identity.RegistrantContact.Name.count description: The name count of the registrant contact. type: Number - contextPath: DomainTools.Identity.RegistrantContact.Phone.value description: The phone value of the registrant contact. type: String - contextPath: DomainTools.Identity.RegistrantContact.Phone.count description: The phone count of the registrant contact. type: Number - contextPath: DomainTools.Identity.SOAEmail description: The SOA record of the Email. type: String - contextPath: DomainTools.Identity.SSLCertificateEmail description: The Email of the SSL certificate. type: String - contextPath: DomainTools.Identity.AdminContact.Country.value description: The country value of the administrator contact. type: String - contextPath: DomainTools.Identity.AdminContact.Country.count description: The country count of the administrator contact. type: Number - contextPath: DomainTools.Identity.AdminContact.Email.value description: The Email value of the administrator contact. type: String - contextPath: DomainTools.Identity.AdminContact.Email.count description: The Email count of the administrator contact. type: Number - contextPath: DomainTools.Identity.AdminContact.Name.value description: The name value of the administrator contact. type: String - contextPath: DomainTools.Identity.AdminContact.Name.count description: The name count of the administrator contact. type: Number - contextPath: DomainTools.Identity.AdminContact.Phone.value description: The phone value of the administrator contact. type: String - contextPath: DomainTools.Identity.AdminContact.Phone.count description: The phone count of the administrator contact. type: Number - contextPath: DomainTools.Identity.TechnicalContact.Country.value description: The country value of the technical contact. type: String - contextPath: DomainTools.Identity.TechnicalContact.Country.count description: The country count of the technical contact. type: Number - contextPath: DomainTools.Identity.TechnicalContact.Email.value description: The Email value of the technical contact. type: String - contextPath: DomainTools.Identity.TechnicalContact.Email.count description: The Email count of the technical contact. type: Number - contextPath: DomainTools.Identity.TechnicalContact.Name.value description: The name value of the technical Contact. type: String - contextPath: DomainTools.Identity.TechnicalContact.Name.count description: The name count of the technical contact. type: Number - contextPath: DomainTools.Identity.TechnicalContact.Phone.value description: The phone value of the technical contact. type: String - contextPath: DomainTools.Identity.TechnicalContact.Phone.count description: The phone count of the technical contact. type: Number - contextPath: DomainTools.Identity.BillingContact.Country.value description: The country value of the billing contact. type: String - contextPath: DomainTools.Identity.BillingContact.Country.count description: The country count of the billing contact. type: Number - contextPath: DomainTools.Identity.BillingContact.Email.value description: The Email value of the billing contact. type: String - contextPath: DomainTools.Identity.BillingContact.Email.count description: The Email count of the billing contact. type: Number - contextPath: DomainTools.Identity.BillingContact.Name.value description: The name value of the billing contact. type: String - contextPath: DomainTools.Identity.BillingContact.Name.count description: The name count of the billing contact. type: Number - contextPath: DomainTools.Identity.BillingContact.Phone.value description: The phone value of the billing contact. type: String - contextPath: DomainTools.Identity.BillingContact.Phone.count description: The phone count of the billing contact. type: Number - contextPath: DomainTools.Identity.EmailDomains description: The Email Domains. type: String - contextPath: DomainTools.Identity.AdditionalWhoisEmails.value description: The value of the Additional Whois Emails record. type: String - contextPath: DomainTools.Identity.AdditionalWhoisEmails.count description: The count of the Additional Whois Emails record. type: Number - contextPath: DomainTools.Registration.DomainRegistrant description: The registrant of the domain. type: String - contextPath: DomainTools.Registration.RegistrarStatus description: The status of the registrar. type: String - contextPath: DomainTools.Registration.DomainStatus description: The active status of the domain. type: Boolean - contextPath: DomainTools.Registration.CreateDate description: The date the domain was created. type: Date - contextPath: DomainTools.Registration.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: DomainTools.Hosting.IPAddresses.address.value description: The address value of IP addresses. type: String - contextPath: DomainTools.Hosting.IPAddresses.address.count description: The address count of IP addresses. type: Number - contextPath: DomainTools.Hosting.IPAddresses.asn.value description: The ASN value of IP addresses. type: String - contextPath: DomainTools.Hosting.IPAddresses.asn.count description: The ASN count of IP addresses. type: Number - contextPath: DomainTools.Hosting.IPAddresses.country_code.value description: The country code value of IP addresses. type: String - contextPath: DomainTools.Hosting.IPAddresses.country_code.count description: The country code count of IP addresses. type: Number - contextPath: DomainTools.Hosting.IPAddresses.isp.value description: The ISP value of IP addresses. type: String - contextPath: DomainTools.Hosting.IPAddresses.isp.count description: The ISP count of IP addresses. type: Number - contextPath: DomainTools.Hosting.IPCountryCode description: The country code of the IP address. type: String - contextPath: DomainTools.Hosting.MailServers.domain.value description: The domain value of the Mail Servers. type: String - contextPath: DomainTools.Hosting.MailServers.domain.count description: The domain count of the Mail Servers. type: Number - contextPath: DomainTools.Hosting.MailServers.host.value description: The host value of the Mail Servers. type: String - contextPath: DomainTools.Hosting.MailServers.host.count description: The host count of the Mail Servers. type: Number - contextPath: DomainTools.Hosting.MailServers.ip.value description: The IP value of the Mail Servers. type: String - contextPath: DomainTools.Hosting.MailServers.ip.count description: The IP count of the Mail Servers. type: Number - contextPath: DomainTools.Hosting.SPFRecord description: The SPF Record. type: String - contextPath: DomainTools.Hosting.NameServers.domain.value description: The domain value of the domain NameServers. type: String - contextPath: DomainTools.Hosting.NameServers.domain.count description: The domain count of the domain NameServers. type: Number - contextPath: DomainTools.Hosting.NameServers.host.value description: The host value of the domain NameServers. type: String - contextPath: DomainTools.Hosting.NameServers.host.count description: The host count of the domain NameServers. type: Number - contextPath: DomainTools.Hosting.NameServers.ip.value description: The IP value of the domain NameServers. type: String - contextPath: DomainTools.Hosting.NameServers.ip.count description: The IP count of domain NameServers. type: Number - contextPath: DomainTools.Hosting.SSLCertificate.hash.value description: The hash value of the SSL certificate. type: String - contextPath: DomainTools.Hosting.SSLCertificate.hash.count description: The hash count of the SSL certificate. type: Number - contextPath: DomainTools.Hosting.SSLCertificate.organization.value description: The organization value of the SSL certificate. type: String - contextPath: DomainTools.Hosting.SSLCertificate.organization.count description: The organization count of the SSL certificate information. type: Number - contextPath: DomainTools.Hosting.SSLCertificate.subject.value description: The subject value of the SSL certificate information. type: String - contextPath: DomainTools.Hosting.SSLCertificate.subject.count description: The subject count of the SSL certificate information. type: Number - contextPath: DomainTools.Hosting.RedirectsTo.value description: The Redirects To Value of the domain. type: String - contextPath: DomainTools.Hosting.RedirectsTo.count description: The Redirects To Count of the domain. type: Number - contextPath: DomainTools.Analytics.GoogleAdsenseTrackingCode description: The tracking code of Google Adsense. type: Number - contextPath: DomainTools.Analytics.GoogleAnalyticTrackingCode description: The tracking code of Google Analytics. type: Number - contextPath: DomainTools.Domains.Analytics.GA4TrackingCode description: The tracking code of ga4. type: Number - contextPath: DomainTools.Domains.Analytics.GTMTrackingCode description: The tracking code of gtm. type: Number - contextPath: DomainTools.Domains.Analytics.FBTrackingCode description: The tracking code of fb. type: Number - contextPath: DomainTools.Domains.Analytics.HotJarTrackingCode description: The tracking code of Hot Jar. type: Number - contextPath: DomainTools.Domains.Analytics.BaiduTrackingCode description: The tracking code of Baidu. type: Number - contextPath: DomainTools.Domains.Analytics.YandexTrackingCode description: The tracking code of Yandex. type: Number - contextPath: DomainTools.Domains.Analytics.MatomoTrackingCode description: The tracking code of Matomo. type: Number - contextPath: DomainTools.Domains.Analytics.StatcounterProjectTrackingCode description: The tracking code of Stat Counter Project. type: Number - contextPath: DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode description: The tracking code of Stat Counter Security. type: Number - contextPath: DomainTools.WebsiteTitle description: The website title. type: Number - contextPath: DomainTools.FirstSeen description: The date the domain was first seen. type: Number - contextPath: DomainTools.ServerType description: The server type. type: Number - contextPath: DBotScore.Indicator description: The indicator of the DBotScore. type: String - contextPath: DBotScore.Type description: The indicator type of the DBotScore. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number deprecated: false execution: false - arguments: - default: true description: The domain name (SLD.TLD), or a comma-separated list of up to 6,000 domains. name: domain required: true isArray: false secret: false - description: Include the investigate results in Context Data. Defaults to true. name: include_context default: false isArray: false required: false secret: false type: String predefined: - "true" - "false" auto: PREDEFINED defaultValue: "true" description: Returns a complete profile of the domain (SLD.TLD) using Iris Enrich. If parsing of URLs or FQDNs is desired, see domainExtractAndEnrich. name: domaintoolsiris-enrich outputs: - contextPath: Domain.Name description: The name of the domain. type: String - contextPath: Domain.DNS description: The DNS of the domain. type: String - contextPath: Domain.DomainStatus description: The status of the domain. type: Boolean - contextPath: Domain.CreationDate description: The creation date. type: Date - contextPath: Domain.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.NameServers description: The nameServers of the domain. type: String - contextPath: Domain.Registrant.Country description: The registrant country of the domain. type: String - contextPath: Domain.Registrant.Email description: The registrant email of the domain. type: String - contextPath: Domain.Registrant.Name description: The registrant name of the domain. type: String - contextPath: Domain.Registrant.Phone description: The registrant phone number of the domain. type: String - contextPath: Domain.Malicious.Vendor description: The vendor who classified the domain as malicious. type: String - contextPath: Domain.Malicious.Description description: The description as to why the domain was found to be malicious. type: String - contextPath: DomainTools.Name description: The domain name in DomainTools. type: String - contextPath: DomainTools.LastEnriched description: The last Time DomainTools enriched domain data. type: Date - contextPath: DomainTools.Analytics.OverallRiskScore description: The Overall Risk Score in DomainTools. type: Number - contextPath: DomainTools.Analytics.ProximityRiskScore description: The Proximity Risk Score in DomainTools. type: Number - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.RiskScore description: The Threat Profile Risk Score in DomainTools. type: Number - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.Threats description: The threats of the Threat Profile Risk Score in DomainTools. type: String - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.Evidence description: The Threat Profile Risk Score Evidence in DomainTools. type: String - contextPath: DomainTools.Analytics.WebsiteResponseCode description: The Website Response Code in DomainTools. type: Number - contextPath: DomainTools.Analytics.Tags description: The Tags in DomainTools. type: String - contextPath: DomainTools.Identity.RegistrantName description: The name of the registrant. type: String - contextPath: DomainTools.Identity.RegistrantOrg description: The organization of the registrant. type: String - contextPath: DomainTools.Identity.RegistrantContact.Country.value description: The country value of the registrant contact. type: String - contextPath: DomainTools.Identity.RegistrantContact.Country.count description: The count of the registrant contact country. type: Number - contextPath: DomainTools.Identity.RegistrantContact.Email.value description: The Email value of the registrant contact. type: String - contextPath: DomainTools.Identity.RegistrantContact.Email.count description: The Email count of the registrant contact. type: Number - contextPath: DomainTools.Identity.RegistrantContact.Name.value description: The name value of the registrant contact. type: String - contextPath: DomainTools.Identity.RegistrantContact.Name.count description: The name count of the registrant contact. type: Number - contextPath: DomainTools.Identity.RegistrantContact.Phone.value description: The phone value of the registrant contact. type: String - contextPath: DomainTools.Identity.RegistrantContact.Phone.count description: The phone count of the registrant contact. type: Number - contextPath: DomainTools.Identity.SOAEmail description: The SOA record of the Email. type: String - contextPath: DomainTools.Identity.SSLCertificateEmail description: The Email of the SSL certificate. type: String - contextPath: DomainTools.Identity.AdminContact.Country.value description: The country value of the administrator contact. type: String - contextPath: DomainTools.Identity.AdminContact.Country.count description: The country count of the administrator contact. type: Number - contextPath: DomainTools.Identity.AdminContact.Email.value description: The Email value of the administrator contact. type: String - contextPath: DomainTools.Identity.AdminContact.Email.count description: The Email count of the administrator contact. type: Number - contextPath: DomainTools.Identity.AdminContact.Name.value description: The name value of the administrator contact. type: String - contextPath: DomainTools.Identity.AdminContact.Name.count description: The name count of the administrator contact. type: Number - contextPath: DomainTools.Identity.AdminContact.Phone.value description: The phone value of the administrator contact. type: String - contextPath: DomainTools.Identity.AdminContact.Phone.count description: The phone count of the administrator contact. type: Number - contextPath: DomainTools.Identity.TechnicalContact.Country.value description: The country value of the technical contact. type: String - contextPath: DomainTools.Identity.TechnicalContact.Country.count description: The country count of the technical contact. type: Number - contextPath: DomainTools.Identity.TechnicalContact.Email.value description: The Email value of the technical contact. type: String - contextPath: DomainTools.Identity.TechnicalContact.Email.count description: The Email count of the technical contact. type: Number - contextPath: DomainTools.Identity.TechnicalContact.Name.value description: The name value of the technical Contact. type: String - contextPath: DomainTools.Identity.TechnicalContact.Name.count description: The name count of the technical contact. type: Number - contextPath: DomainTools.Identity.TechnicalContact.Phone.value description: The phone value of the technical contact. type: String - contextPath: DomainTools.Identity.TechnicalContact.Phone.count description: The phone count of the technical contact. type: Number - contextPath: DomainTools.Identity.BillingContact.Country.value description: The country value of the billing contact. type: String - contextPath: DomainTools.Identity.BillingContact.Country.count description: The country count of the billing contact. type: Number - contextPath: DomainTools.Identity.BillingContact.Email.value description: The Email value of the billing contact. type: String - contextPath: DomainTools.Identity.BillingContact.Email.count description: The Email count of the billing contact. type: Number - contextPath: DomainTools.Identity.BillingContact.Name.value description: The name value of the billing contact. type: String - contextPath: DomainTools.Identity.BillingContact.Name.count description: The name count of the billing contact. type: Number - contextPath: DomainTools.Identity.BillingContact.Phone.value description: The phone value of the billing contact. type: String - contextPath: DomainTools.Identity.BillingContact.Phone.count description: The phone count of the billing contact. type: Number - contextPath: DomainTools.Identity.EmailDomains description: The Email Domains. type: String - contextPath: DomainTools.Identity.AdditionalWhoisEmails.value description: The value of the Additional Whois Emails record. type: String - contextPath: DomainTools.Identity.AdditionalWhoisEmails.count description: The count of the Additional Whois Emails record. type: Number - contextPath: DomainTools.Registration.DomainRegistrant description: The registrant of the domain. type: String - contextPath: DomainTools.Registration.RegistrarStatus description: The status of the registrar. type: String - contextPath: DomainTools.Registration.DomainStatus description: The active status of the domain. type: Boolean - contextPath: DomainTools.Registration.CreateDate description: The date the domain was created. type: Date - contextPath: DomainTools.Registration.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: DomainTools.Hosting.IPAddresses.address.value description: The address value of IP addresses. type: String - contextPath: DomainTools.Hosting.IPAddresses.address.count description: The address count of IP addresses. type: Number - contextPath: DomainTools.Hosting.IPAddresses.asn.value description: The ASN value of IP addresses. type: String - contextPath: DomainTools.Hosting.IPAddresses.asn.count description: The ASN count of IP addresses. type: Number - contextPath: DomainTools.Hosting.IPAddresses.country_code.value description: The country code value of IP addresses. type: String - contextPath: DomainTools.Hosting.IPAddresses.country_code.count description: The country code count of IP addresses. type: Number - contextPath: DomainTools.Hosting.IPAddresses.isp.value description: The ISP value of IP addresses. type: String - contextPath: DomainTools.Hosting.IPAddresses.isp.count description: The ISP count of IP addresses. type: Number - contextPath: DomainTools.Hosting.IPCountryCode description: The country code of the IP address. type: String - contextPath: DomainTools.Hosting.MailServers.domain.value description: The domain value of the Mail Servers. type: String - contextPath: DomainTools.Hosting.MailServers.domain.count description: The domain count of the Mail Servers. type: Number - contextPath: DomainTools.Hosting.MailServers.host.value description: The host value of the Mail Servers. type: String - contextPath: DomainTools.Hosting.MailServers.host.count description: The host count of the Mail Servers. type: Number - contextPath: DomainTools.Hosting.MailServers.ip.value description: The IP value of the Mail Servers. type: String - contextPath: DomainTools.Hosting.MailServers.ip.count description: The IP count of the Mail Servers. type: Number - contextPath: DomainTools.Hosting.SPFRecord description: The SPF Record. type: String - contextPath: DomainTools.Hosting.NameServers.domain.value description: The domain value of the domain NameServers. type: String - contextPath: DomainTools.Hosting.NameServers.domain.count description: The domain count of the domain NameServers. type: Number - contextPath: DomainTools.Hosting.NameServers.host.value description: The host value of the domain NameServers. type: String - contextPath: DomainTools.Hosting.NameServers.host.count description: The host count of the domain NameServers. type: Number - contextPath: DomainTools.Hosting.NameServers.ip.value description: The IP value of the domain NameServers. type: String - contextPath: DomainTools.Hosting.NameServers.ip.count description: The IP count of domain NameServers. type: Number - contextPath: DomainTools.Hosting.SSLCertificate.hash.value description: The hash value of the SSL certificate. type: String - contextPath: DomainTools.Hosting.SSLCertificate.hash.count description: The hash count of the SSL certificate. type: Number - contextPath: DomainTools.Hosting.SSLCertificate.organization.value description: The organization value of the SSL certificate. type: String - contextPath: DomainTools.Hosting.SSLCertificate.organization.count description: The organization count of the SSL certificate information. type: Number - contextPath: DomainTools.Hosting.SSLCertificate.subject.value description: The subject value of the SSL certificate information. type: String - contextPath: DomainTools.Hosting.SSLCertificate.subject.count description: The subject count of the SSL certificate information. type: Number - contextPath: DomainTools.Hosting.RedirectsTo.value description: The Redirects To Value of the domain. type: String - contextPath: DomainTools.Hosting.RedirectsTo.count description: The Redirects To Count of the domain. type: Number - contextPath: DomainTools.Analytics.GoogleAdsenseTrackingCode description: The tracking code of Google Adsense. type: Number - contextPath: DomainTools.Analytics.GoogleAnalyticTrackingCode description: The tracking code of Google Analytics. type: Number - contextPath: DomainTools.Domains.Analytics.GA4TrackingCode description: The tracking code of ga4. type: Number - contextPath: DomainTools.Domains.Analytics.GTMTrackingCode description: The tracking code of gtm. type: Number - contextPath: DomainTools.Domains.Analytics.FBTrackingCode description: The tracking code of fb. type: Number - contextPath: DomainTools.Domains.Analytics.HotJarTrackingCode description: The tracking code of Hot Jar. type: Number - contextPath: DomainTools.Domains.Analytics.BaiduTrackingCode description: The tracking code of Baidu. type: Number - contextPath: DomainTools.Domains.Analytics.YandexTrackingCode description: The tracking code of Yandex. type: Number - contextPath: DomainTools.Domains.Analytics.MatomoTrackingCode description: The tracking code of Matomo. type: Number - contextPath: DomainTools.Domains.Analytics.StatcounterProjectTrackingCode description: The tracking code of Stat Counter Project. type: Number - contextPath: DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode description: The tracking code of Stat Counter Security. type: Number - contextPath: DomainTools.WebsiteTitle description: The website title. type: Number - contextPath: DomainTools.FirstSeen description: The date the domain was first seen. type: Number - contextPath: DomainTools.ServerType description: The server type. type: Number - contextPath: DBotScore.Indicator description: The indicator of the DBotScore. type: String - contextPath: DBotScore.Type description: The indicator type of the DBotScore. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number deprecated: false execution: false - arguments: - default: false description: The domain name to display. name: domain isArray: false required: true secret: false - description: Include the enrich results in Context Data. Defaults to true. name: include_context default: true isArray: false required: false secret: false type: String predefined: - "true" - "false" auto: PREDEFINED defaultValue: "true" description: Displays DomainTools Analytic data in a markdown format table. name: domaintoolsiris-analytics outputs: - contextPath: Domain.Name description: The name of the domain. type: String - contextPath: Domain.DNS description: The DNS of the domain. type: String - contextPath: Domain.DomainStatus description: The status of the domain. type: Boolean - contextPath: Domain.CreationDate description: The creation date of the domain. type: Date - contextPath: Domain.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.NameServers description: The NameServers of the domain. type: String - contextPath: Domain.Registrant.Country description: The registrant country of the domain. type: String - contextPath: Domain.Registrant.Email description: The registrant Email of the domain. type: String - contextPath: Domain.Registrant.Name description: The registrant name of the domain. type: String - contextPath: Domain.Registrant.Phone description: The registrant phone number of the domain. type: String - contextPath: Domain.Malicious.Vendor description: The vendor that classified the domain as malicious. type: String - contextPath: Domain.Malicious.Description description: The description as to why the domain was found malicious. type: String - contextPath: DomainTools.Domains.Name description: The domain name in DomainTools. type: String - contextPath: DomainTools.Domains.LastEnriched description: The last Time DomainTools enriched domain data. type: Date - contextPath: DomainTools.Domains.Analytics.OverallRiskScore description: The DomainTools Overall Risk Score. type: Number - contextPath: DomainTools.Domains.Analytics.ProximityRiskScore description: The DomainTools Proximity Risk Score. type: Number - contextPath: DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScore description: The DomainTools Threat Profile Risk Score. type: Number - contextPath: DomainTools.Domains.Analytics.ThreatProfileRiskScore.Threats description: The DomainTools Threat Profile Threats. type: String - contextPath: DomainTools.Domains.Analytics.ThreatProfileRiskScore.Evidence description: The DomainTools Threat Profile Evidence. type: String - contextPath: DomainTools.Domains.Analytics.WebsiteResponseCode description: The Website Response Code. type: Number - contextPath: DomainTools.Domains.Analytics.Tags description: The tags in DomainTools. type: String - contextPath: DomainTools.Domains.Identity.RegistrantName description: The name of the registrant. type: String - contextPath: DomainTools.Domains.Identity.RegistrantOrg description: The organization of the registrant. type: String - contextPath: DomainTools.Domains.Identity.RegistrantContact.Country.value description: The country value of the registrant contact. type: String - contextPath: DomainTools.Domains.Identity.RegistrantContact.Country.count description: The country count of the registrant contact. type: Number - contextPath: DomainTools.Domains.Identity.RegistrantContact.Email.value description: The Email value of the registrant contact. type: String - contextPath: DomainTools.Domains.Identity.RegistrantContact.Email.count description: The Email count of the registrant contact. type: Number - contextPath: DomainTools.Domains.Identity.RegistrantContact.Name.value description: The name value of the registrant contact. type: String - contextPath: DomainTools.Domains.Identity.RegistrantContact.Name.count description: The Name count of the registrant contact. type: Number - contextPath: DomainTools.Domains.Identity.RegistrantContact.Phone.value description: The phone value of the registrant contact. type: String - contextPath: DomainTools.Domains.Identity.RegistrantContact.Phone.count description: The phone count of the registrant contact. type: Number - contextPath: DomainTools.Domains.Identity.SOAEmail description: The SOA record Email. type: String - contextPath: DomainTools.Domains.Identity.SSLCertificateEmail description: The email of the SSL certificate. type: String - contextPath: DomainTools.Domains.Identity.AdminContact.Country.value description: The country value of the administrator contact. type: String - contextPath: DomainTools.Domains.Identity.AdminContact.Country.count description: The country count of the administrator contact. type: Number - contextPath: DomainTools.Domains.Identity.AdminContact.Email.value description: The Email value of the administrator contact. type: String - contextPath: DomainTools.Domains.Identity.AdminContact.Email.count description: The Email count of the administrator contact. type: Number - contextPath: DomainTools.Domains.Identity.AdminContact.Name.value description: The name value of the administrator contact. type: String - contextPath: DomainTools.Domains.Identity.AdminContact.Name.count description: The name count of administrator contact. type: Number - contextPath: DomainTools.Domains.Identity.AdminContact.Phone.value description: The phone value of the administrator contact. type: String - contextPath: DomainTools.Domains.Identity.AdminContact.Phone.count description: The phone count of the administrator contact. type: Number - contextPath: DomainTools.Domains.Identity.TechnicalContact.Country.value description: The country value of the technical contact. type: String - contextPath: DomainTools.Domains.Identity.TechnicalContact.Country.count description: The country count of the technical contact. type: Number - contextPath: DomainTools.Domains.Identity.TechnicalContact.Email.value description: The Email value of the technical contact. type: String - contextPath: DomainTools.Domains.Identity.TechnicalContact.Email.count description: The Email count of the technical contact. type: Number - contextPath: DomainTools.Domains.Identity.TechnicalContact.Name.value description: The name value of the technical contact. type: String - contextPath: DomainTools.Domains.Identity.TechnicalContact.Name.count description: The name count of the technical contact. type: Number - contextPath: DomainTools.Domains.Identity.TechnicalContact.Phone.value description: The phone value of the technical contact. type: String - contextPath: DomainTools.Domains.Identity.TechnicalContact.Phone.count description: The phone count of the technical contact. type: Number - contextPath: DomainTools.Domains.Identity.BillingContact.Country.value description: The country value of the billing contact. type: String - contextPath: DomainTools.Domains.Identity.BillingContact.Country.count description: The country count of the billing contact. type: Number - contextPath: DomainTools.Domains.Identity.BillingContact.Email.value description: The email value of the billing contact. type: String - contextPath: DomainTools.Domains.Identity.BillingContact.Email.count description: The email count of the billing contact. type: Number - contextPath: DomainTools.Domains.Identity.BillingContact.Name.value description: The name value of the billing contact. type: String - contextPath: DomainTools.Domains.Identity.BillingContact.Name.count description: The name count of the billing contact. type: Number - contextPath: DomainTools.Domains.Identity.BillingContact.Phone.value description: The phone value of the billing contact. type: String - contextPath: DomainTools.Domains.Identity.BillingContact.Phone.count description: The phone count of the billing contact. type: Number - contextPath: DomainTools.Domains.Identity.EmailDomains description: The domain of the Email. type: String - contextPath: DomainTools.Domains.Identity.AdditionalWhoisEmails.value description: The value of the Additional Whois Emails. type: String - contextPath: DomainTools.Domains.Identity.AdditionalWhoisEmails.count description: The count of the Additional Whois Emails. type: Number - contextPath: DomainTools.Domains.Registration.DomainRegistrant description: The registrant of the domain. type: String - contextPath: DomainTools.Domains.Registration.RegistrarStatus description: The status of the registrar. type: String - contextPath: DomainTools.Domains.Registration.DomainStatus description: The active status of the domain. type: Boolean - contextPath: DomainTools.Domains.Registration.CreateDate description: The date the domain was created. type: Date - contextPath: DomainTools.Domains.Registration.ExpirationDate description: The date the domain expires. type: Date - contextPath: DomainTools.Domains.Hosting.IPAddresses.address.value description: The address values of the IP addresses. type: String - contextPath: DomainTools.Domains.Hosting.IPAddresses.address.count description: The address counts of the IP addresses. type: Number - contextPath: DomainTools.Domains.Hosting.IPAddresses.asn.value description: The ASN values of the IP addresses. type: String - contextPath: DomainTools.Domains.Hosting.IPAddresses.asn.count description: The ASN counts of the IP addresses. type: Number - contextPath: DomainTools.Domains.Hosting.IPAddresses.country_code.value description: The country code values of the IP addresses. type: String - contextPath: DomainTools.Domains.Hosting.IPAddresses.country_code.count description: The country code counts of the IP addresses. type: Number - contextPath: DomainTools.Domains.Hosting.IPAddresses.isp.value description: IP Addresses Info isp value. type: String - contextPath: DomainTools.Domains.Hosting.IPAddresses.isp.count description: IP Addresses Info isp count. type: Number - contextPath: DomainTools.Domains.Hosting.IPCountryCode description: IP Country Code. type: String - contextPath: DomainTools.Domains.Hosting.MailServers.domain.value description: Mail Servers Info domain value. type: String - contextPath: DomainTools.Domains.Hosting.MailServers.domain.count description: Mail Servers Info domain count. type: Number - contextPath: DomainTools.Domains.Hosting.MailServers.host.value description: Mail Servers Info host value. type: String - contextPath: DomainTools.Domains.Hosting.MailServers.host.count description: Mail Servers Info host count. type: Number - contextPath: DomainTools.Domains.Hosting.MailServers.ip.value description: Mail Servers Info ip value. type: String - contextPath: DomainTools.Domains.Hosting.MailServers.ip.count description: Mail Servers Info ip count. type: Number - contextPath: DomainTools.Domains.Hosting.SPFRecord description: The SPF record. type: String - contextPath: DomainTools.Domains.Hosting.NameServers.domain.value description: The domain value of the DomainTools Domains NameServers. type: String - contextPath: DomainTools.Domains.Hosting.NameServers.domain.count description: The domain count of the DomainTools Domains NameServers. type: Number - contextPath: DomainTools.Domains.Hosting.NameServers.host.value description: The host value of the DomainTools Domains NameServers. type: String - contextPath: DomainTools.Domains.Hosting.NameServers.host.count description: The host count of the DomainTools Domains NameServers. type: Number - contextPath: DomainTools.Domains.Hosting.NameServers.ip.value description: The IP value of the DomainTools Domains NameServers. type: String - contextPath: DomainTools.Domains.Hosting.NameServers.ip.count description: The IP count of the DomainTools Domains NameServers. type: Number - contextPath: DomainTools.Domains.Hosting.SSLCertificate.hash.value description: The hash value of the SSL certificate. type: String - contextPath: DomainTools.Domains.Hosting.SSLCertificate.hash.count description: The hash count of the SSL certificate. type: Number - contextPath: DomainTools.Domains.Hosting.SSLCertificate.organization.value description: The organization value of the SSL certificate. type: String - contextPath: DomainTools.Domains.Hosting.SSLCertificate.organization.count description: The organization count of the SSL certificate. type: Number - contextPath: DomainTools.Domains.Hosting.SSLCertificate.subject.value description: The subject value of the SSL certificate. type: String - contextPath: DomainTools.Domains.Hosting.SSLCertificate.subject.count description: The subject count of the SSL certificate. type: Number - contextPath: DomainTools.Domains.Hosting.RedirectsTo.value description: The Redirects To value of the domain. type: String - contextPath: DomainTools.Domains.Hosting.RedirectsTo.count description: The Redirects To count of the domain. type: Number - contextPath: DomainTools.Domains.Analytics.GoogleAdsenseTrackingCode description: The tracking code of Google Adsense. type: Number - contextPath: DomainTools.Analytics.GoogleAnalyticTrackingCode description: The tracking code of Google Analytics. type: Number - contextPath: DomainTools.Domains.Analytics.GA4TrackingCode description: The tracking code of ga4. type: Number - contextPath: DomainTools.Domains.Analytics.GTMTrackingCode description: The tracking code of gtm. type: Number - contextPath: DomainTools.Domains.Analytics.FBTrackingCode description: The tracking code of fb. type: Number - contextPath: DomainTools.Domains.Analytics.HotJarTrackingCode description: The tracking code of Hot Jar. type: Number - contextPath: DomainTools.Domains.Analytics.BaiduTrackingCode description: The tracking code of Baidu. type: Number - contextPath: DomainTools.Domains.Analytics.YandexTrackingCode description: The tracking code of Yandex. type: Number - contextPath: DomainTools.Domains.Analytics.MatomoTrackingCode description: The tracking code of Matomo. type: Number - contextPath: DomainTools.Domains.Analytics.StatcounterProjectTrackingCode description: The tracking code of Stat Counter Project. type: Number - contextPath: DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode description: The tracking code of Stat Counter Security. type: Number - contextPath: DBotScore.Indicator description: The DBotScore indicator. type: String - contextPath: DBotScore.Type description: The indicator type of the DBotScore. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number deprecated: false execution: false - arguments: - default: false description: The domain name. isArray: false name: domain required: true secret: false deprecated: false description: Displays DomainTools Threat Profile data in a markdown format table. execution: false name: domaintoolsiris-threat-profile outputs: - contextPath: Domain.Name description: The name of the domain. type: String - contextPath: Domain.DNS description: The DNS of the domain. type: String - contextPath: Domain.DomainStatus description: The status of the domain. type: Boolean - contextPath: Domain.CreationDate description: The creation date of the domain. type: Date - contextPath: Domain.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.NameServers description: The NameServers of the domain. type: String - contextPath: Domain.Registrant.Country description: The registrant country of the domain. type: String - contextPath: Domain.Registrant.Email description: The Email of the registrant domain. type: String - contextPath: Domain.Registrant.Name description: The registrant name of the domain. type: String - contextPath: Domain.Registrant.Phone description: The phone value of the registrant domain. type: String - contextPath: Domain.Malicious.Vendor description: Vendor that classified the domain as malicious. type: String - contextPath: Domain.Malicious.Description description: The description as to why the domain was found to be malicious. type: String - contextPath: DomainTools.Domains.Name description: The DomainTools domain name. type: String - contextPath: DomainTools.Domains.LastEnriched description: The last time DomainTools enriched the domain data. type: Date - contextPath: DomainTools.Domains.Analytics.OverallRiskScore description: The DomainTools Overall Risk Score. type: Number - contextPath: DomainTools.Domains.Analytics.ProximityRiskScore description: The DomainTools Proximity Risk Score. type: Number - contextPath: DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScore description: The DomainTools Threat Profile Risk Score. type: Number - contextPath: DomainTools.Domains.Analytics.ThreatProfileRiskScore.Threats description: The DomainTools Threat Profile Threats. type: String - contextPath: DomainTools.Domains.Analytics.ThreatProfileRiskScore.Evidence description: The DomainTools Threat Profile Evidence. type: String - contextPath: DomainTools.Domains.Analytics.WebsiteResponseCode description: The response code of the Website. type: Number - contextPath: DomainTools.Domains.Analytics.Tags description: The DomainTools Tags. type: String - contextPath: DomainTools.Domains.Identity.RegistrantName description: The name of the registrant. type: String - contextPath: DomainTools.Domains.Identity.RegistrantOrg description: The organization of the registrant. type: String - contextPath: DomainTools.Domains.Identity.RegistrantContact.Country.value description: The country value of the registrant contact. type: String - contextPath: DomainTools.Domains.Identity.RegistrantContact.Country.count description: The county count of the registrant contact. type: Number - contextPath: DomainTools.Domains.Identity.RegistrantContact.Email.value description: The Email value of the registrant contact. type: String - contextPath: DomainTools.Domains.Identity.RegistrantContact.Email.count description: The Email count of the registrant contact. type: Number - contextPath: DomainTools.Domains.Identity.RegistrantContact.Name.value description: The name value of the registrant contact. type: String - contextPath: DomainTools.Domains.Identity.RegistrantContact.Name.count description: The name count of the registrant contact. type: Number - contextPath: DomainTools.Domains.Identity.RegistrantContact.Phone.value description: The phone value of the registrant contact. type: String - contextPath: DomainTools.Domains.Identity.RegistrantContact.Phone.count description: The phone count of the registrant contact. type: Number - contextPath: DomainTools.Domains.Identity.SOAEmail description: The SOA record Email. type: String - contextPath: DomainTools.Domains.Identity.SSLCertificateEmail description: The SSL certificate Email. type: String - contextPath: DomainTools.Domains.Identity.AdminContact.Country.value description: The country value of the administrator contact. type: String - contextPath: DomainTools.Domains.Identity.AdminContact.Country.count description: The country count of the administrator contact. type: Number - contextPath: DomainTools.Domains.Identity.AdminContact.Email.value description: The Email value of the administrator contact. type: String - contextPath: DomainTools.Domains.Identity.AdminContact.Email.count description: The Email count of the administrator contact. type: Number - contextPath: DomainTools.Domains.Identity.AdminContact.Name.value description: The name value of the administrator contact. type: String - contextPath: DomainTools.Domains.Identity.AdminContact.Name.count description: The name count of the administrator contact. type: Number - contextPath: DomainTools.Domains.Identity.AdminContact.Phone.value description: The phone value of the administrator contact. type: String - contextPath: DomainTools.Domains.Identity.AdminContact.Phone.count description: The phone count of the administrator contact. type: Number - contextPath: DomainTools.Domains.Identity.TechnicalContact.Country.value description: The country value of the technical contact. type: String - contextPath: DomainTools.Domains.Identity.TechnicalContact.Country.count description: The country count of the technical contact. type: Number - contextPath: DomainTools.Domains.Identity.TechnicalContact.Email.value description: The Email value of the technical contact. type: String - contextPath: DomainTools.Domains.Identity.TechnicalContact.Email.count description: The Email count of the technical contact. type: Number - contextPath: DomainTools.Domains.Identity.TechnicalContact.Name.value description: The name value of the technical contact. type: String - contextPath: DomainTools.Domains.Identity.TechnicalContact.Name.count description: The name count of the technical contact. type: Number - contextPath: DomainTools.Domains.Identity.TechnicalContact.Phone.value description: The phone value of the technical contact. type: String - contextPath: DomainTools.Domains.Identity.TechnicalContact.Phone.count description: The phone count of the technical contact. type: Number - contextPath: DomainTools.Domains.Identity.BillingContact.Country.value description: The country value of the billing contact. type: String - contextPath: DomainTools.Domains.Identity.BillingContact.Country.count description: The country count of the billing contact. type: Number - contextPath: DomainTools.Domains.Identity.BillingContact.Email.value description: The Email value of the billing contact. type: String - contextPath: DomainTools.Domains.Identity.BillingContact.Email.count description: The Email count of the billing contact. type: Number - contextPath: DomainTools.Domains.Identity.BillingContact.Name.value description: The name value of the billing contact. type: String - contextPath: DomainTools.Domains.Identity.BillingContact.Name.count description: The name count of the billing contact. type: Number - contextPath: DomainTools.Domains.Identity.BillingContact.Phone.value description: The phone value of the billing contact. type: String - contextPath: DomainTools.Domains.Identity.BillingContact.Phone.count description: The phone count of the billing contact. type: Number - contextPath: DomainTools.Domains.Identity.EmailDomains description: The Email domains. type: String - contextPath: DomainTools.Domains.Identity.AdditionalWhoisEmails.value description: The value of the Additional Whois Emails. type: String - contextPath: DomainTools.Domains.Identity.AdditionalWhoisEmails.count description: The count of the Additional Whois Emails. type: Number - contextPath: DomainTools.Domains.Registration.DomainRegistrant description: The registrant of the domain. type: String - contextPath: DomainTools.Domains.Registration.RegistrarStatus description: The status of the registrar. type: String - contextPath: DomainTools.Domains.Registration.DomainStatus description: The active status of the domain. type: Boolean - contextPath: DomainTools.Domains.Registration.CreateDate description: The date the domain was created. type: Date - contextPath: DomainTools.Domains.Registration.ExpirationDate description: The expiry date of the domain. type: Date - contextPath: DomainTools.Domains.Hosting.IPAddresses.address.value description: The address value of the IP Addresses. type: String - contextPath: DomainTools.Domains.Hosting.IPAddresses.address.count description: The address count of the IP Addresses. type: Number - contextPath: DomainTools.Domains.Hosting.IPAddresses.asn.value description: The ASN value of the IP Addresses. type: String - contextPath: DomainTools.Domains.Hosting.IPAddresses.asn.count description: The ASN count of the IP Addresses. type: Number - contextPath: DomainTools.Domains.Hosting.IPAddresses.country_code.value description: The country code of the IP Addresses. type: String - contextPath: DomainTools.Domains.Hosting.IPAddresses.country_code.count description: The country code count of the IP Addresses. type: Number - contextPath: DomainTools.Domains.Hosting.IPAddresses.isp.value description: ISP value of the IP Addresses. type: String - contextPath: DomainTools.Domains.Hosting.IPAddresses.isp.count description: The ISP count of the IP Addresses. type: Number - contextPath: DomainTools.Domains.Hosting.IPCountryCode description: The country code of the IP address. type: String - contextPath: DomainTools.Domains.Hosting.MailServers.domain.value description: The domain value of the Mail Servers. type: String - contextPath: DomainTools.Domains.Hosting.MailServers.domain.count description: The domain count of the Mail Servers. type: Number - contextPath: DomainTools.Domains.Hosting.MailServers.host.value description: The host value of the Mail Servers. type: String - contextPath: DomainTools.Domains.Hosting.MailServers.host.count description: The host count of the Mail Servers. type: Number - contextPath: DomainTools.Domains.Hosting.MailServers.ip.value description: The IP value of the Mail Servers. type: String - contextPath: DomainTools.Domains.Hosting.MailServers.ip.count description: The IP count of the Mail Servers. type: Number - contextPath: DomainTools.Domains.Hosting.SPFRecord description: The SPF Record. type: String - contextPath: DomainTools.Domains.Hosting.NameServers.domain.value description: The domain value of the DomainTools Domains NameServers. type: String - contextPath: DomainTools.Domains.Hosting.NameServers.domain.count description: The domain count of the DomainTools Domains NameServers. type: Number - contextPath: DomainTools.Domains.Hosting.NameServers.host.value description: The host value of the DomainTools Domains NameServers. type: String - contextPath: DomainTools.Domains.Hosting.NameServers.host.count description: The host count of the DomainTools Domains NameServers. type: Number - contextPath: DomainTools.Domains.Hosting.NameServers.ip.value description: The IP value of the DomainTools Domains NameServers. type: String - contextPath: DomainTools.Domains.Hosting.NameServers.ip.count description: The IP count of the DomainTools Domains NameServers. type: Number - contextPath: DomainTools.Domains.Hosting.SSLCertificate.hash.value description: The hash value of the SSL certificate. type: String - contextPath: DomainTools.Domains.Hosting.SSLCertificate.hash.count description: The hash count of the SSL certificate. type: Number - contextPath: DomainTools.Domains.Hosting.SSLCertificate.organization.value description: The organization value of the SSL certificate. type: String - contextPath: DomainTools.Domains.Hosting.SSLCertificate.organization.count description: The organization count of the SSL certificate. type: Number - contextPath: DomainTools.Domains.Hosting.SSLCertificate.subject.value description: The subject value of the SSL certificate. type: String - contextPath: DomainTools.Domains.Hosting.SSLCertificate.subject.count description: The subject count of the SSL certificate. type: Number - contextPath: DomainTools.Domains.Hosting.RedirectsTo.value description: The Redirects To value of the domain. type: String - contextPath: DomainTools.Domains.Hosting.RedirectsTo.count description: The Redirects To count of the domain. type: Number - contextPath: DomainTools.Domains.Analytics.GoogleAdsenseTrackingCode description: The tracking code of Google Adsense. type: Number - contextPath: DomainTools.Analytics.GoogleAnalyticTrackingCode description: The tracking code of Google Analytics. type: Number - contextPath: DomainTools.Domains.Analytics.GA4TrackingCode description: The tracking code of ga4. type: Number - contextPath: DomainTools.Domains.Analytics.GTMTrackingCode description: The tracking code of gtm. type: Number - contextPath: DomainTools.Domains.Analytics.FBTrackingCode description: The tracking code of fb. type: Number - contextPath: DomainTools.Domains.Analytics.HotJarTrackingCode description: The tracking code of Hot Jar. type: Number - contextPath: DomainTools.Domains.Analytics.BaiduTrackingCode description: The tracking code of Baidu. type: Number - contextPath: DomainTools.Domains.Analytics.YandexTrackingCode description: The tracking code of Yandex. type: Number - contextPath: DomainTools.Domains.Analytics.MatomoTrackingCode description: The tracking code of Matomo. type: Number - contextPath: DomainTools.Domains.Analytics.StatcounterProjectTrackingCode description: The tracking code of Stat Counter Project. type: Number - contextPath: DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode description: The tracking code of Stat Counter Security. type: Number - contextPath: DBotScore.Indicator description: The DBotScore indicator. type: String - contextPath: DBotScore.Type description: The indicator type of the DBotScore. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - arguments: - default: false description: The IP Address. isArray: false name: ip required: false secret: false - default: false description: "The Email Address." isArray: false name: email required: false secret: false - default: false description: "The Name Server IP Address." isArray: false name: nameserver_ip required: false secret: false - default: false description: "The hash of the SSL." isArray: false name: ssl_hash required: false secret: false - default: false description: "The fully-qualified host name of the name server. For example, ns1.domaintools.net." isArray: false name: nameserver_host required: false secret: false - default: false description: The fully-qualified host name of the mail server. For example, mx.domaintools.net. isArray: false name: mailserver_host required: false secret: false - default: false description: Only the domain portion of a Whois or DNS SOA email address. isArray: false name: email_domain required: false secret: false - default: false description: Registered domain portion of the name server. isArray: false name: nameserver_domain required: false secret: false - default: false description: Exact match to the Whois registrar field. isArray: false name: registrar required: false secret: false - default: false description: Exact match to the Whois registrant field. isArray: false name: registrant required: false secret: false - default: false description: Exact match to the Whois registrant organization field. isArray: false name: registrant_org required: false secret: false - default: false description: Comma-separated list of Iris Investigate tags. Returns domains tagged with any of the tags in a list. isArray: false name: tagged_with_any required: false secret: false - default: false description: Comma-separated list of tags. Only returns domains tagged with the full list of tags. isArray: false name: tagged_with_all required: false secret: false - default: false description: Only the registered domain portion of the mail server (domaintools.net). isArray: false name: mailserver_domain required: false secret: false - default: false description: IP address of the mail server. isArray: false name: mailserver_ip required: false secret: false - default: false description: Find domains observed to redirect to another domain name. isArray: false name: redirect_domain required: false secret: false - default: false description: Exact match to the organization name on the SSL certificate. isArray: false name: ssl_org required: false secret: false - default: false description: Subject field from the SSL certificate. isArray: false name: ssl_subject required: false secret: false - default: false description: Email address from the SSL certificate. isArray: false name: ssl_email required: false secret: false - default: false description: Domains with a Google Analytics tracking code. isArray: false name: google_analytics required: false secret: false - default: false description: Domains with a Google AdSense tracking code. isArray: false name: adsense required: false secret: false - default: false description: Encoded search from the Iris UI. isArray: false name: search_hash required: false secret: false - default: false description: Include the results of the pivot in Context Data. Defaults to true. isArray: false name: include_context required: false secret: false type: String predefined: - "true" - "false" auto: PREDEFINED defaultValue: "true" deprecated: false description: Pivot on connected infrastructure (IP, email, SSL), or import domains from Iris Investigate using a search hash. Retrieves up to 5000 domains at a time. Optionally exclude results from context with include_context=false. execution: false name: domaintoolsiris-pivot outputs: - contextPath: DomainTools.Pivots.PivotedDomains.Name description: The DomainTools Domain Name. type: String - contextPath: DomainTools.Pivots.PivotedDomains.LastEnriched description: The last time DomainTools enriched the domain data. type: Date - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.OverallRiskScore description: The DomainTools Overall Risk Score. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.ProximityRiskScore description: The DomainTools Proximity Risk Score. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.ThreatProfileRiskScore.RiskScore description: The DomainTools Threat Profile Risk Score. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.ThreatProfileRiskScore.Threats description: The DomainTools Threat Profile Threats. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.ThreatProfileRiskScore.Evidence description: The DomainTools Threat Profile Evidence. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.WebsiteResponseCode description: The response code of the website. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.Tags description: The DomainTools tags. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantName description: The name of the registrant. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantOrg description: The organization of the registrant. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Country.value description: The country value of the registrant contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Country.count description: The country count of the registrant contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Email.value description: The Email value of the registrant contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Email.count description: The Email count of the registrant contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Name.value description: The name value of the registrant contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Name.count description: The name count of the registrant contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Phone.value description: The phone value of of the registrant contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Phone.count description: The phone count of the registrant contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.SOAEmail description: The SOA record Email. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.SSLCertificateEmail description: The SSL certificate Email. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Country.value description: The country value of the administrator contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Country.count description: The country count of the administrator contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Email.value description: The Email value of the administrator contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Email.count description: The Email count of the administrator contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Name.value description: The name value of the administrator contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Name.count description: The name count of the administrator contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Phone.value description: The phone value of the administrator contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Phone.count description: The phone count of the administrator contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Country.value description: The country value of the technical contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Country.count description: The country count of the technical contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Email.value description: The Email value of the technical contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Email.count description: The Email count of the technical contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Name.value description: The name value of the technical contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Name.count description: The name count of the technical contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Phone.value description: The phone value of the technical contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Phone.count description: The phone count of the technical contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Country.value description: The country value of the billing contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Country.count description: The country count of the billing contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Email.value description: The Email value of the billing contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Email.count description: The Email count of the billing contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Name.value description: The Name value of the billing contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Name.count description: The Name count of the billing contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Phone.value description: The phone value of the billing contact. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Phone.count description: The phone count of the billing contact. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Identity.EmailDomains description: The Email domains. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdditionalWhoisEmails.value description: The value of the Additional Whois Emails. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdditionalWhoisEmails.count description: The count of the Additional Whois Emails. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Registration.DomainRegistrant description: The Registrant of the domain. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Registration.RegistrarStatus description: The status of the registrar. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Registration.DomainStatus description: The active status of the registrar. type: Boolean - contextPath: DomainTools.Pivots.PivotedDomains.Registration.CreateDate description: The date the domain was created. type: Date - contextPath: DomainTools.Pivots.PivotedDomains.Registration.ExpirationDate description: The Expiry date of the domain. type: Date - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.address.value description: The address value of IP addresses. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.address.count description: The address count of IP addresses. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.asn.value description: The ASN value of IP addresses. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.asn.count description: The ASN count of IP addresses. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.country_code.value description: The country code value of IP addresses. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.country_code.count description: The country code count of IP addresses. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.isp.value description: The ISP value of IP addresses. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.isp.count description: The ISP count of IP addresses. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPCountryCode description: The country code of the IP address. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.MailServers.domain.value description: The domain value of the Mail Servers. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.MailServers.domain.count description: The domain count of the Mail Servers. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.MailServers.host.value description: The host value of the Mail Servers. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.MailServers.host.count description: The host count of the Mail Servers. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.MailServers.ip.value description: The IP address value of the Mail Servers. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.MailServers.ip.count description: The IP address count of the Mail Servers. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SPFRecord description: The SPF record Information. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.NameServers.domain.value description: The domain value of DomainTools Domains NameServers. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.NameServers.domain.count description: The domain count of DomainTools Domains NameServers. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.NameServers.host.value description: The host value of DomainTools Domains NameServers. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.NameServers.host.count description: The host count of DomainTools Domains NameServers. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.NameServers.ip.value description: The IP address value of DomainTools Domains NameServers. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.NameServers.ip.count description: The IP address count of DomainTools Domains NameServers. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.hash.value description: The hash value of the SSL certificate. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.hash.count description: The hash count of the SSL certificate. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.organization.value description: The organization value of the SSL certificate. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.organization.count description: The organization count of the SSL certificate. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.subject.value description: The subject value of the SSL certificate. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.subject.count description: The subject count of the SSL certificate. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.RedirectsTo.value description: The Redirects To value of the domain. type: String - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.RedirectsTo.count description: The Redirects To count of the domain. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.GoogleAdsenseTrackingCode description: The tracking code of Google Adsense. type: Number - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.GoogleAnalyticTrackingCode description: The tracking code Google Analytics. type: Number - arguments: - default: true description: A domain name to query (e.g. example.com). isArray: false name: domain required: true secret: false - default: false description: "options: list, count, check_existence. list: (default), return whois records. count: return how many total records are available. check_existence: return if any records exist. Default: list." isArray: false name: mode required: false secret: false type: String predefined: - "list" - "count" - "check_existence" auto: PREDEFINED defaultValue: "list" - default: false description: "numeric, the index from which to begin retrieving results. Default: 0." isArray: false name: offset required: false secret: false type: Number defaultValue: "0" - default: false description: "numeric, default: 100, max: 100, the total number of records to return. Default: 100." isArray: false name: limit required: false secret: false type: Number auto: PREDEFINED defaultValue: "100" - default: false description: "options: date_desc, date_asc. date_desc: (default), order records from newest to oldest. date_asc: sort order records from oldest to newest. Default: date_desc." isArray: false name: sort required: false secret: false auto: PREDEFINED defaultValue: "date_desc" predefined: - "date_desc" - "date_asc" deprecated: false description: The DomainTools Whois History API endpoint returns up to 100 historical Whois records associated with a domain name. execution: false name: domaintools-whois-history outputs: - contextPath: DomainTools.History.Value description: Name of domain. - contextPath: DomainTools.History.WhoisHistory description: Domain Whois history data. - arguments: - default: true description: A domain name to query (e.g. example.com). name: domain required: true isArray: false secret: false description: Hosting History will list IP address, name server and registrar history. name: domaintools-hosting-history outputs: - contextPath: DomainTools.History.Value description: Name of domain. - contextPath: DomainTools.History.IPHistory description: Domain IP history data. - contextPath: DomainTools.History.NameserverHistory description: Domain Nameserver history data. - contextPath: DomainTools.History.RegistrarHistory description: Domain Registrar history data. deprecated: false execution: false - arguments: - default: true description: (default) List of one or more terms to search for in the Whois record, separated with the pipe character ( | ). name: terms required: true - description: Domain names with Whois records that match these terms will be excluded from the result set. Separate multiple terms with the pipe character ( | ). name: exclude - auto: PREDEFINED defaultValue: "false" description: Show only historic records. name: onlyHistoricScope predefined: - "true" - "false" description: The DomainTools Reverse Whois API provides a list of domain names that share the same Registrant Information. You can enter terms that describe a domain owner, like an email address or a company name, and you’ll get a list of domain names that have your search terms listed in the Whois record. name: domaintools-reverse-whois outputs: - contextPath: DomainTools.ReverseWhois.Value description: Search term to reverse whois lookup on. - contextPath: DomainTools.ReverseWhois.Results description: List of results for reverse whois lookup. - name: domaintools-whois arguments: - default: true description: A domain name or IP address (e.g. example.com or 192.168.1.1). name: query required: true description: The DomainTools Parsed Whois API provides parsed information extracted from the raw Whois record. The API is optimized to quickly retrieve the Whois record, group important data together and return a well-structured format. The Parsed Whois API is ideal for anyone wishing to search for, index, or cross-reference data from one or multiple Whois records. outputs: - contextPath: Domain.Name description: Requested domain name. - contextPath: Domain.Whois description: Parsed Whois data. - contextPath: Domain.WhoisRecords description: Full Whois record. - name: reverseIP arguments: - default: true name: ip description: Specify the IP address to query. - name: domain description: If a domain name is provided, DomainTools will respond with the list of other domains that share the same IP. - name: limit description: Limits the size of the domain list than can appear in a response. The limit is applied per-IP address, not for the entire request. defaultValue: 50 description: Reverse loopkup of an IP address or a domain. deprecated: false execution: false outputs: - contextPath: Domain.Name description: Domain name returned by the query. - contextPath: Domain.DNS.Address description: The IP address associated with the returned domains. - name: reverseNameServer arguments: - name: nameServer required: true description: Specify the name of the primary or secondary nameserver. - name: limit description: Limit the size of the domain list than can appear in a response. defaultValue: 50 deprecated: false execution: false description: Reverse nameserver lookup. outputs: - contextPath: Domain.Name description: Name of the domain returned by the query. dockerimage: demisto/vendors-sdk:1.0.0.10120494 runonce: false script: '-' type: python subtype: python3 isfetch: true longRunning: false longRunningPort: false tests: - No test - test 'DomainTools Iris - Test' was moved to NonCircleFolder fromversion: 5.0.0 sectionorder: - Connect - Collect