DomainTools Iris

Together, DomainTools and Cortex XSOAR automate and orchestrate the incident response process with essential domain profile, web crawl, SSL and infrastructure data. SOCs can create custom, automated workflows to trigger Indicator of Compromise (IoC) investigations, block threats based on connected infrastructure, and identify potentially malicious domains before weaponization. The DomainTools App for Cortex XSOAR is shipped with pre-built playbooks to enable automated enrichment, decision logic, ad-hoc investigations, and the ability to persist enriched intelligence.

Data Enrichment & Threat Intelligence · DomainTools Iris Investigate

Details

IDDomainTools Iris
ProviderDomainTools
CategoryData Enrichment & Threat Intelligence
From Version5.0.0
Docker Imagedemisto/vendors-sdk:1.0.0.10120494
Supported ModulesAgentix XSIAM

README

Together, DomainTools and Cortex XSOAR automate and orchestrate the incident response process with essential domain profile, web crawl, SSL and infrastructure data. SOCs can create custom, automated workflows to trigger Indicator of Compromise (IoC) investigations, block threats based on connected infrastructure, and identify potentially malicious domains before weaponization. The DomainTools App for Cortex XSOAR is shipped with pre-built playbooks to enable automated enrichment, decision logic, ad-hoc investigations, and the ability to persist enriched intelligence.
This integration was integrated and tested with version 1.0 of DomainTools Iris.

Configure DomainTools Iris in Cortex

Parameter Description Required
API Username   False
API Key   False
High-Risk Threshold   True
Young Domain Timeframe (within Days)   True
Trust any certificate (not secure)   False
Use system proxy settings   False
Domain Result Type Result type of the domain command: Iris returns full investigate results; Verdict returns only the domain risk score False
Source Reliability Reliability of the source providing the intelligence data. False
    False
    False
Guided Pivot Threshold When a small set of domains share an attribute (e.g. registrar), that can often be pivoted on in order to find other similar domains of interest. DomainTools tracks how many domains share each attribute and can highlight it for further investigation when the number of domains is beneath the set threshold. True
Enabled on Monitoring Domains by Iris Search Hash   False
Domaintools Iris Investigate Search Hash The DomainTools Iris Investigate Search hash False
Enabled on Monitoring Domains by Iris Tags   False
Domaintools Iris Tags The DomainTools Iris Tags (Values should be a comma separated value. e.g. (tag1,tag2)) False
Maximum number of incidents to fetch This is a required field by XSOAR and should be set to 2, one for each possible feed type iris search hash and iris tags. False
Incident type    
Fetch incidents    
First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) This is a required field by XSOAR and should be set to 2, one for each possible feed type iris search hash and iris tags. False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

domain


Provides data enrichment for domains.

Base Command

domain

Input

Argument Name Description Required
domain The domain to enrich. Required

Context Output

Path Type Description
Domain.Name String The name of the domain.
Domain.DNS String The DNS of the domain.
Domain.DomainStatus Boolean The status of the domain.
Domain.CreationDate Date The creation date.
Domain.ExpirationDate Date The expiration date of the domain.
Domain.NameServers String The nameServers of the domain.
Domain.Registrant.Country String The registrant country of the domain.
Domain.Registrant.Email String The registrant email of the domain.
Domain.Registrant.Name String The registrant name of the domain.
Domain.Registrant.Phone String The registrant phone number of the domain.
Domain.Malicious.Vendor String The vendor who classified the domain as malicious.
Domain.Malicious.Description String The description as to why the domain was found to be malicious.
DomainTools.Name String The domain name in DomainTools.
DomainTools.LastEnriched Date The last Time DomainTools enriched domain data.
DomainTools.Analytics.OverallRiskScore Number The Overall Risk Score in DomainTools.
DomainTools.Analytics.ProximityRiskScore Number The Proximity Risk Score in DomainTools.
DomainTools.Analytics.ThreatProfileRiskScore.RiskScore Number The Threat Profile Risk Score in DomainTools.
DomainTools.Analytics.ThreatProfileRiskScore.Threats String The threats of the Threat Profile Risk Score in DomainTools.
DomainTools.Analytics.ThreatProfileRiskScore.Evidence String The Threat Profile Risk Score Evidence in DomainTools.
DomainTools.Analytics.WebsiteResponseCode Number The Website Response Code in DomainTools.
DomainTools.Analytics.Tags String The Tags in DomainTools.
DomainTools.Identity.RegistrantName String The name of the registrant.
DomainTools.Identity.RegistrantOrg String The organization of the registrant.
DomainTools.Identity.RegistrantContact.Country.value String The country value of the registrant contact.
DomainTools.Identity.RegistrantContact.Country.count Number The count of the registrant contact country.
DomainTools.Identity.RegistrantContact.Email.value String The Email value of the registrant contact.
DomainTools.Identity.RegistrantContact.Email.count Number The Email count of the registrant contact.
DomainTools.Identity.RegistrantContact.Name.value String The name value of the registrant contact.
DomainTools.Identity.RegistrantContact.Name.count Number The name count of the registrant contact.
DomainTools.Identity.RegistrantContact.Phone.value String The phone value of the registrant contact.
DomainTools.Identity.RegistrantContact.Phone.count Number The phone count of the registrant contact.
DomainTools.Identity.SOAEmail String The SOA record of the Email.
DomainTools.Identity.SSLCertificateEmail String The Email of the SSL certificate.
DomainTools.Identity.AdminContact.Country.value String The country value of the administrator contact.
DomainTools.Identity.AdminContact.Country.count Number The country count of the administrator contact.
DomainTools.Identity.AdminContact.Email.value String The Email value of the administrator contact.
DomainTools.Identity.AdminContact.Email.count Number The Email count of the administrator contact.
DomainTools.Identity.AdminContact.Name.value String The name value of the administrator contact.
DomainTools.Identity.AdminContact.Name.count Number The name count of the administrator contact.
DomainTools.Identity.AdminContact.Phone.value String The phone value of the administrator contact.
DomainTools.Identity.AdminContact.Phone.count Number The phone count of the administrator contact.
DomainTools.Identity.TechnicalContact.Country.value String The country value of the technical contact.
DomainTools.Identity.TechnicalContact.Country.count Number The country count of the technical contact.
DomainTools.Identity.TechnicalContact.Email.value String The Email value of the technical contact.
DomainTools.Identity.TechnicalContact.Email.count Number The Email count of the technical contact.
DomainTools.Identity.TechnicalContact.Name.value String The name value of the technical Contact.
DomainTools.Identity.TechnicalContact.Name.count Number The name count of the technical contact.
DomainTools.Identity.TechnicalContact.Phone.value String The phone value of the technical contact.
DomainTools.Identity.TechnicalContact.Phone.count Number The phone count of the technical contact.
DomainTools.Identity.BillingContact.Country.value String The country value of the billing contact.
DomainTools.Identity.BillingContact.Country.count Number The country count of the billing contact.
DomainTools.Identity.BillingContact.Email.value String The Email value of the billing contact.
DomainTools.Identity.BillingContact.Email.count Number The Email count of the billing contact.
DomainTools.Identity.BillingContact.Name.value String The name value of the billing contact.
DomainTools.Identity.BillingContact.Name.count Number The name count of the billing contact.
DomainTools.Identity.BillingContact.Phone.value String The phone value of the billing contact.
DomainTools.Identity.BillingContact.Phone.count Number The phone count of the billing contact.
DomainTools.Identity.EmailDomains String The Email Domains.
DomainTools.Identity.AdditionalWhoisEmails.value String The value of the Additional Whois Emails record.
DomainTools.Identity.AdditionalWhoisEmails.count Number The count of the Additional Whois Emails record.
DomainTools.Registration.DomainRegistrant String The registrant of the domain.
DomainTools.Registration.RegistrarStatus String The status of the registrar.
DomainTools.Registration.DomainStatus Boolean The active status of the domain.
DomainTools.Registration.CreateDate Date The date the domain was created.
DomainTools.Registration.ExpirationDate Date The expiration date of the domain.
DomainTools.Hosting.IPAddresses.address.value String The address value of IP addresses.
DomainTools.Hosting.IPAddresses.address.count Number The address count of IP addresses.
DomainTools.Hosting.IPAddresses.asn.value String The ASN value of IP addresses.
DomainTools.Hosting.IPAddresses.asn.count Number The ASN count of IP addresses.
DomainTools.Hosting.IPAddresses.country_code.value String The country code value of IP addresses.
DomainTools.Hosting.IPAddresses.country_code.count Number The country code count of IP addresses.
DomainTools.Hosting.IPAddresses.isp.value String The ISP value of IP addresses.
DomainTools.Hosting.IPAddresses.isp.count Number The ISP count of IP addresses.
DomainTools.Hosting.IPCountryCode String The country code of the IP address.
DomainTools.Hosting.MailServers.domain.value String The domain value of the Mail Servers.
DomainTools.Hosting.MailServers.domain.count Number The domain count of the Mail Servers.
DomainTools.Hosting.MailServers.host.value String The host value of the Mail Servers.
DomainTools.Hosting.MailServers.host.count Number The host count of the Mail Servers.
DomainTools.Hosting.MailServers.ip.value String The IP value of the Mail Servers.
DomainTools.Hosting.MailServers.ip.count Number The IP count of the Mail Servers.
DomainTools.Hosting.SPFRecord String The SPF Record.
DomainTools.Hosting.NameServers.domain.value String The domain value of the domain NameServers.
DomainTools.Hosting.NameServers.domain.count Number The domain count of the domain NameServers.
DomainTools.Hosting.NameServers.host.value String The host value of the domain NameServers.
DomainTools.Hosting.NameServers.host.count Number The host count of the domain NameServers.
DomainTools.Hosting.NameServers.ip.value String The IP value of the domain NameServers.
DomainTools.Hosting.NameServers.ip.count Number The IP count of domain NameServers.
DomainTools.Hosting.SSLCertificate.hash.value String The hash value of the SSL certificate.
DomainTools.Hosting.SSLCertificate.hash.count Number The hash count of the SSL certificate.
DomainTools.Hosting.SSLCertificate.organization.value String The organization value of the SSL certificate.
DomainTools.Hosting.SSLCertificate.organization.count Number The organization count of the SSL certificate information.
DomainTools.Hosting.SSLCertificate.subject.value String The subject value of the SSL certificate information.
DomainTools.Hosting.SSLCertificate.subject.count Number The subject count of the SSL certificate information.
DomainTools.Hosting.RedirectsTo.value String The Redirects To Value of the domain.
DomainTools.Hosting.RedirectsTo.count Number The Redirects To Count of the domain.
DomainTools.Analytics.GoogleAdsenseTrackingCode Number The tracking code of Google Adsense.
DomainTools.Analytics.GoogleAnalyticTrackingCode Number The tracking code of Google Analytics.
DomainTools.Domains.Analytics.GA4TrackingCode Number The tracking code of ga4.
DomainTools.Domains.Analytics.GTMTrackingCode Number The tracking code of gtm.
DomainTools.Domains.Analytics.FBTrackingCode Number The tracking code of fb.
DomainTools.Domains.Analytics.HotJarTrackingCode Number The tracking code of Hot Jar.
DomainTools.Domains.Analytics.BaiduTrackingCode Number The tracking code of Baidu.
DomainTools.Domains.Analytics.YandexTrackingCode Number The tracking code of Yandex.
DomainTools.Domains.Analytics.MatomoTrackingCode Number The tracking code of Matomo.
DomainTools.Domains.Analytics.StatcounterProjectTrackingCode Number The tracking code of Stat Counter Project.
DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode Number The tracking code of Stat Counter Security.
DomainTools.WebsiteTitle Number The website title.
DomainTools.FirstSeen Number The date the domain was first seen.
DomainTools.ServerType Number The server type.
DBotScore.Indicator String The indicator that was tested.
DBotScore.Type String The indicator type of the DBotScore.
DBotScore.Vendor String The vendor used to calculate the score.
DBotScore.Score Number The actual score.

domaintoolsiris-investigate


Returns a complete profile of the domain (SLD.TLD) using Iris Investigate. If parsing of FQDNs is desired, see domainExtractAndInvestigate.

Base Command

domaintoolsiris-investigate

Input

Argument Name Description Required
domain The domain name (SLD.TLD) to Investigate. Supports up to 1,000 comma-separated domains. Required
include_context Include the investigate results in Context Data. Defaults to true. Possible values are: true, false. Default is true. Optional

Context Output

Path Type Description
Domain.Name String The name of the domain.
Domain.DNS String The DNS of the domain.
Domain.DomainStatus Boolean The status of the domain.
Domain.CreationDate Date The creation date.
Domain.ExpirationDate Date The expiration date of the domain.
Domain.NameServers String The nameServers of the domain.
Domain.Registrant.Country String The registrant country of the domain.
Domain.Registrant.Email String The registrant email of the domain.
Domain.Registrant.Name String The registrant name of the domain.
Domain.Registrant.Phone String The registrant phone number of the domain.
Domain.Malicious.Vendor String The vendor who classified the domain as malicious.
Domain.Malicious.Description String The description as to why the domain was found to be malicious.
DomainTools.Name String The domain name in DomainTools.
DomainTools.LastEnriched Date The last Time DomainTools enriched domain data.
DomainTools.Analytics.OverallRiskScore Number The Overall Risk Score in DomainTools.
DomainTools.Analytics.ProximityRiskScore Number The Proximity Risk Score in DomainTools.
DomainTools.Analytics.ThreatProfileRiskScore.RiskScore Number The Threat Profile Risk Score in DomainTools.
DomainTools.Analytics.ThreatProfileRiskScore.Threats String The threats of the Threat Profile Risk Score in DomainTools.
DomainTools.Analytics.ThreatProfileRiskScore.Evidence String The Threat Profile Risk Score Evidence in DomainTools.
DomainTools.Analytics.WebsiteResponseCode Number The Website Response Code in DomainTools.
DomainTools.Analytics.Tags String The Tags in DomainTools.
DomainTools.Identity.RegistrantName String The name of the registrant.
DomainTools.Identity.RegistrantOrg String The organization of the registrant.
DomainTools.Identity.RegistrantContact.Country.value String The country value of the registrant contact.
DomainTools.Identity.RegistrantContact.Country.count Number The count of the registrant contact country.
DomainTools.Identity.RegistrantContact.Email.value String The Email value of the registrant contact.
DomainTools.Identity.RegistrantContact.Email.count Number The Email count of the registrant contact.
DomainTools.Identity.RegistrantContact.Name.value String The name value of the registrant contact.
DomainTools.Identity.RegistrantContact.Name.count Number The name count of the registrant contact.
DomainTools.Identity.RegistrantContact.Phone.value String The phone value of the registrant contact.
DomainTools.Identity.RegistrantContact.Phone.count Number The phone count of the registrant contact.
DomainTools.Identity.SOAEmail String The SOA record of the Email.
DomainTools.Identity.SSLCertificateEmail String The Email of the SSL certificate.
DomainTools.Identity.AdminContact.Country.value String The country value of the administrator contact.
DomainTools.Identity.AdminContact.Country.count Number The country count of the administrator contact.
DomainTools.Identity.AdminContact.Email.value String The Email value of the administrator contact.
DomainTools.Identity.AdminContact.Email.count Number The Email count of the administrator contact.
DomainTools.Identity.AdminContact.Name.value String The name value of the administrator contact.
DomainTools.Identity.AdminContact.Name.count Number The name count of the administrator contact.
DomainTools.Identity.AdminContact.Phone.value String The phone value of the administrator contact.
DomainTools.Identity.AdminContact.Phone.count Number The phone count of the administrator contact.
DomainTools.Identity.TechnicalContact.Country.value String The country value of the technical contact.
DomainTools.Identity.TechnicalContact.Country.count Number The country count of the technical contact.
DomainTools.Identity.TechnicalContact.Email.value String The Email value of the technical contact.
DomainTools.Identity.TechnicalContact.Email.count Number The Email count of the technical contact.
DomainTools.Identity.TechnicalContact.Name.value String The name value of the technical Contact.
DomainTools.Identity.TechnicalContact.Name.count Number The name count of the technical contact.
DomainTools.Identity.TechnicalContact.Phone.value String The phone value of the technical contact.
DomainTools.Identity.TechnicalContact.Phone.count Number The phone count of the technical contact.
DomainTools.Identity.BillingContact.Country.value String The country value of the billing contact.
DomainTools.Identity.BillingContact.Country.count Number The country count of the billing contact.
DomainTools.Identity.BillingContact.Email.value String The Email value of the billing contact.
DomainTools.Identity.BillingContact.Email.count Number The Email count of the billing contact.
DomainTools.Identity.BillingContact.Name.value String The name value of the billing contact.
DomainTools.Identity.BillingContact.Name.count Number The name count of the billing contact.
DomainTools.Identity.BillingContact.Phone.value String The phone value of the billing contact.
DomainTools.Identity.BillingContact.Phone.count Number The phone count of the billing contact.
DomainTools.Identity.EmailDomains String The Email Domains.
DomainTools.Identity.AdditionalWhoisEmails.value String The value of the Additional Whois Emails record.
DomainTools.Identity.AdditionalWhoisEmails.count Number The count of the Additional Whois Emails record.
DomainTools.Registration.DomainRegistrant String The registrant of the domain.
DomainTools.Registration.RegistrarStatus String The status of the registrar.
DomainTools.Registration.DomainStatus Boolean The active status of the domain.
DomainTools.Registration.CreateDate Date The date the domain was created.
DomainTools.Registration.ExpirationDate Date The expiration date of the domain.
DomainTools.Hosting.IPAddresses.address.value String The address value of IP addresses.
DomainTools.Hosting.IPAddresses.address.count Number The address count of IP addresses.
DomainTools.Hosting.IPAddresses.asn.value String The ASN value of IP addresses.
DomainTools.Hosting.IPAddresses.asn.count Number The ASN count of IP addresses.
DomainTools.Hosting.IPAddresses.country_code.value String The country code value of IP addresses.
DomainTools.Hosting.IPAddresses.country_code.count Number The country code count of IP addresses.
DomainTools.Hosting.IPAddresses.isp.value String The ISP value of IP addresses.
DomainTools.Hosting.IPAddresses.isp.count Number The ISP count of IP addresses.
DomainTools.Hosting.IPCountryCode String The country code of the IP address.
DomainTools.Hosting.MailServers.domain.value String The domain value of the Mail Servers.
DomainTools.Hosting.MailServers.domain.count Number The domain count of the Mail Servers.
DomainTools.Hosting.MailServers.host.value String The host value of the Mail Servers.
DomainTools.Hosting.MailServers.host.count Number The host count of the Mail Servers.
DomainTools.Hosting.MailServers.ip.value String The IP value of the Mail Servers.
DomainTools.Hosting.MailServers.ip.count Number The IP count of the Mail Servers.
DomainTools.Hosting.SPFRecord String The SPF Record.
DomainTools.Hosting.NameServers.domain.value String The domain value of the domain NameServers.
DomainTools.Hosting.NameServers.domain.count Number The domain count of the domain NameServers.
DomainTools.Hosting.NameServers.host.value String The host value of the domain NameServers.
DomainTools.Hosting.NameServers.host.count Number The host count of the domain NameServers.
DomainTools.Hosting.NameServers.ip.value String The IP value of the domain NameServers.
DomainTools.Hosting.NameServers.ip.count Number The IP count of domain NameServers.
DomainTools.Hosting.SSLCertificate.hash.value String The hash value of the SSL certificate.
DomainTools.Hosting.SSLCertificate.hash.count Number The hash count of the SSL certificate.
DomainTools.Hosting.SSLCertificate.organization.value String The organization value of the SSL certificate.
DomainTools.Hosting.SSLCertificate.organization.count Number The organization count of the SSL certificate information.
DomainTools.Hosting.SSLCertificate.subject.value String The subject value of the SSL certificate information.
DomainTools.Hosting.SSLCertificate.subject.count Number The subject count of the SSL certificate information.
DomainTools.Hosting.RedirectsTo.value String The Redirects To Value of the domain.
DomainTools.Hosting.RedirectsTo.count Number The Redirects To Count of the domain.
DomainTools.Analytics.GoogleAdsenseTrackingCode Number The tracking code of Google Adsense.
DomainTools.Analytics.GoogleAnalyticTrackingCode Number The tracking code of Google Analytics.
DomainTools.Domains.Analytics.GA4TrackingCode Number The tracking code of ga4.
DomainTools.Domains.Analytics.GTMTrackingCode Number The tracking code of gtm.
DomainTools.Domains.Analytics.FBTrackingCode Number The tracking code of fb.
DomainTools.Domains.Analytics.HotJarTrackingCode Number The tracking code of Hot Jar.
DomainTools.Domains.Analytics.BaiduTrackingCode Number The tracking code of Baidu.
DomainTools.Domains.Analytics.YandexTrackingCode Number The tracking code of Yandex.
DomainTools.Domains.Analytics.MatomoTrackingCode Number The tracking code of Matomo.
DomainTools.Domains.Analytics.StatcounterProjectTrackingCode Number The tracking code of Stat Counter Project.
DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode Number The tracking code of Stat Counter Security.
DomainTools.WebsiteTitle Number The website title.
DomainTools.FirstSeen Number The date the domain was first seen.
DomainTools.ServerType Number The server type.
DBotScore.Indicator String The indicator of the DBotScore.
DBotScore.Type String The indicator type of the DBotScore.
DBotScore.Vendor String The vendor used to calculate the score.
DBotScore.Score Number The actual score.

domaintoolsiris-enrich


Returns a complete profile of the domain (SLD.TLD) using Iris Enrich. If parsing of URLs or FQDNs is desired, see domainExtractAndEnrich.

Base Command

domaintoolsiris-enrich

Input

Argument Name Description Required
domain The domain name (SLD.TLD), or a comma-separated list of up to 6,000 domains. Required
include_context Include the investigate results in Context Data. Defaults to true. Possible values are: true, false. Default is true. Optional

Context Output

Path Type Description
Domain.Name String The name of the domain.
Domain.DNS String The DNS of the domain.
Domain.DomainStatus Boolean The status of the domain.
Domain.CreationDate Date The creation date.
Domain.ExpirationDate Date The expiration date of the domain.
Domain.NameServers String The nameServers of the domain.
Domain.Registrant.Country String The registrant country of the domain.
Domain.Registrant.Email String The registrant email of the domain.
Domain.Registrant.Name String The registrant name of the domain.
Domain.Registrant.Phone String The registrant phone number of the domain.
Domain.Malicious.Vendor String The vendor who classified the domain as malicious.
Domain.Malicious.Description String The description as to why the domain was found to be malicious.
DomainTools.Name String The domain name in DomainTools.
DomainTools.LastEnriched Date The last Time DomainTools enriched domain data.
DomainTools.Analytics.OverallRiskScore Number The Overall Risk Score in DomainTools.
DomainTools.Analytics.ProximityRiskScore Number The Proximity Risk Score in DomainTools.
DomainTools.Analytics.ThreatProfileRiskScore.RiskScore Number The Threat Profile Risk Score in DomainTools.
DomainTools.Analytics.ThreatProfileRiskScore.Threats String The threats of the Threat Profile Risk Score in DomainTools.
DomainTools.Analytics.ThreatProfileRiskScore.Evidence String The Threat Profile Risk Score Evidence in DomainTools.
DomainTools.Analytics.WebsiteResponseCode Number The Website Response Code in DomainTools.
DomainTools.Analytics.Tags String The Tags in DomainTools.
DomainTools.Identity.RegistrantName String The name of the registrant.
DomainTools.Identity.RegistrantOrg String The organization of the registrant.
DomainTools.Identity.RegistrantContact.Country.value String The country value of the registrant contact.
DomainTools.Identity.RegistrantContact.Country.count Number The count of the registrant contact country.
DomainTools.Identity.RegistrantContact.Email.value String The Email value of the registrant contact.
DomainTools.Identity.RegistrantContact.Email.count Number The Email count of the registrant contact.
DomainTools.Identity.RegistrantContact.Name.value String The name value of the registrant contact.
DomainTools.Identity.RegistrantContact.Name.count Number The name count of the registrant contact.
DomainTools.Identity.RegistrantContact.Phone.value String The phone value of the registrant contact.
DomainTools.Identity.RegistrantContact.Phone.count Number The phone count of the registrant contact.
DomainTools.Identity.SOAEmail String The SOA record of the Email.
DomainTools.Identity.SSLCertificateEmail String The Email of the SSL certificate.
DomainTools.Identity.AdminContact.Country.value String The country value of the administrator contact.
DomainTools.Identity.AdminContact.Country.count Number The country count of the administrator contact.
DomainTools.Identity.AdminContact.Email.value String The Email value of the administrator contact.
DomainTools.Identity.AdminContact.Email.count Number The Email count of the administrator contact.
DomainTools.Identity.AdminContact.Name.value String The name value of the administrator contact.
DomainTools.Identity.AdminContact.Name.count Number The name count of the administrator contact.
DomainTools.Identity.AdminContact.Phone.value String The phone value of the administrator contact.
DomainTools.Identity.AdminContact.Phone.count Number The phone count of the administrator contact.
DomainTools.Identity.TechnicalContact.Country.value String The country value of the technical contact.
DomainTools.Identity.TechnicalContact.Country.count Number The country count of the technical contact.
DomainTools.Identity.TechnicalContact.Email.value String The Email value of the technical contact.
DomainTools.Identity.TechnicalContact.Email.count Number The Email count of the technical contact.
DomainTools.Identity.TechnicalContact.Name.value String The name value of the technical Contact.
DomainTools.Identity.TechnicalContact.Name.count Number The name count of the technical contact.
DomainTools.Identity.TechnicalContact.Phone.value String The phone value of the technical contact.
DomainTools.Identity.TechnicalContact.Phone.count Number The phone count of the technical contact.
DomainTools.Identity.BillingContact.Country.value String The country value of the billing contact.
DomainTools.Identity.BillingContact.Country.count Number The country count of the billing contact.
DomainTools.Identity.BillingContact.Email.value String The Email value of the billing contact.
DomainTools.Identity.BillingContact.Email.count Number The Email count of the billing contact.
DomainTools.Identity.BillingContact.Name.value String The name value of the billing contact.
DomainTools.Identity.BillingContact.Name.count Number The name count of the billing contact.
DomainTools.Identity.BillingContact.Phone.value String The phone value of the billing contact.
DomainTools.Identity.BillingContact.Phone.count Number The phone count of the billing contact.
DomainTools.Identity.EmailDomains String The Email Domains.
DomainTools.Identity.AdditionalWhoisEmails.value String The value of the Additional Whois Emails record.
DomainTools.Identity.AdditionalWhoisEmails.count Number The count of the Additional Whois Emails record.
DomainTools.Registration.DomainRegistrant String The registrant of the domain.
DomainTools.Registration.RegistrarStatus String The status of the registrar.
DomainTools.Registration.DomainStatus Boolean The active status of the domain.
DomainTools.Registration.CreateDate Date The date the domain was created.
DomainTools.Registration.ExpirationDate Date The expiration date of the domain.
DomainTools.Hosting.IPAddresses.address.value String The address value of IP addresses.
DomainTools.Hosting.IPAddresses.address.count Number The address count of IP addresses.
DomainTools.Hosting.IPAddresses.asn.value String The ASN value of IP addresses.
DomainTools.Hosting.IPAddresses.asn.count Number The ASN count of IP addresses.
DomainTools.Hosting.IPAddresses.country_code.value String The country code value of IP addresses.
DomainTools.Hosting.IPAddresses.country_code.count Number The country code count of IP addresses.
DomainTools.Hosting.IPAddresses.isp.value String The ISP value of IP addresses.
DomainTools.Hosting.IPAddresses.isp.count Number The ISP count of IP addresses.
DomainTools.Hosting.IPCountryCode String The country code of the IP address.
DomainTools.Hosting.MailServers.domain.value String The domain value of the Mail Servers.
DomainTools.Hosting.MailServers.domain.count Number The domain count of the Mail Servers.
DomainTools.Hosting.MailServers.host.value String The host value of the Mail Servers.
DomainTools.Hosting.MailServers.host.count Number The host count of the Mail Servers.
DomainTools.Hosting.MailServers.ip.value String The IP value of the Mail Servers.
DomainTools.Hosting.MailServers.ip.count Number The IP count of the Mail Servers.
DomainTools.Hosting.SPFRecord String The SPF Record.
DomainTools.Hosting.NameServers.domain.value String The domain value of the domain NameServers.
DomainTools.Hosting.NameServers.domain.count Number The domain count of the domain NameServers.
DomainTools.Hosting.NameServers.host.value String The host value of the domain NameServers.
DomainTools.Hosting.NameServers.host.count Number The host count of the domain NameServers.
DomainTools.Hosting.NameServers.ip.value String The IP value of the domain NameServers.
DomainTools.Hosting.NameServers.ip.count Number The IP count of domain NameServers.
DomainTools.Hosting.SSLCertificate.hash.value String The hash value of the SSL certificate.
DomainTools.Hosting.SSLCertificate.hash.count Number The hash count of the SSL certificate.
DomainTools.Hosting.SSLCertificate.organization.value String The organization value of the SSL certificate.
DomainTools.Hosting.SSLCertificate.organization.count Number The organization count of the SSL certificate information.
DomainTools.Hosting.SSLCertificate.subject.value String The subject value of the SSL certificate information.
DomainTools.Hosting.SSLCertificate.subject.count Number The subject count of the SSL certificate information.
DomainTools.Hosting.RedirectsTo.value String The Redirects To Value of the domain.
DomainTools.Hosting.RedirectsTo.count Number The Redirects To Count of the domain.
DomainTools.Analytics.GoogleAdsenseTrackingCode Number The tracking code of Google Adsense.
DomainTools.Analytics.GoogleAnalyticTrackingCode Number The tracking code of Google Analytics.
DomainTools.Domains.Analytics.GA4TrackingCode Number The tracking code of ga4.
DomainTools.Domains.Analytics.GTMTrackingCode Number The tracking code of gtm.
DomainTools.Domains.Analytics.FBTrackingCode Number The tracking code of fb.
DomainTools.Domains.Analytics.HotJarTrackingCode Number The tracking code of Hot Jar.
DomainTools.Domains.Analytics.BaiduTrackingCode Number The tracking code of Baidu.
DomainTools.Domains.Analytics.YandexTrackingCode Number The tracking code of Yandex.
DomainTools.Domains.Analytics.MatomoTrackingCode Number The tracking code of Matomo.
DomainTools.Domains.Analytics.StatcounterProjectTrackingCode Number The tracking code of Stat Counter Project.
DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode Number The tracking code of Stat Counter Security.
DomainTools.WebsiteTitle Number The website title.
DomainTools.FirstSeen Number The date the domain was first seen.
DomainTools.ServerType Number The server type.
DBotScore.Indicator String The indicator of the DBotScore.
DBotScore.Type String The indicator type of the DBotScore.
DBotScore.Vendor String The vendor used to calculate the score.
DBotScore.Score Number The actual score.

domaintoolsiris-analytics


Displays DomainTools Analytic data in a markdown format table.

Base Command

domaintoolsiris-analytics

Input

Argument Name Description Required
domain The domain name to display. Required
include_context Include the enrich results in Context Data. Defaults to true. Possible values are: true, false. Default is true. Optional

Context Output

Path Type Description
Domain.Name String The name of the domain.
Domain.DNS String The DNS of the domain.
Domain.DomainStatus Boolean The status of the domain.
Domain.CreationDate Date The creation date of the domain.
Domain.ExpirationDate Date The expiration date of the domain.
Domain.NameServers String The NameServers of the domain.
Domain.Registrant.Country String The registrant country of the domain.
Domain.Registrant.Email String The registrant Email of the domain.
Domain.Registrant.Name String The registrant name of the domain.
Domain.Registrant.Phone String The registrant phone number of the domain.
Domain.Malicious.Vendor String The vendor that classified the domain as malicious.
Domain.Malicious.Description String The description as to why the domain was found malicious.
DomainTools.Domains.Name String The domain name in DomainTools.
DomainTools.Domains.LastEnriched Date The last Time DomainTools enriched domain data.
DomainTools.Domains.Analytics.OverallRiskScore Number The DomainTools Overall Risk Score.
DomainTools.Domains.Analytics.ProximityRiskScore Number The DomainTools Proximity Risk Score.
DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScore Number The DomainTools Threat Profile Risk Score.
DomainTools.Domains.Analytics.ThreatProfileRiskScore.Threats String The DomainTools Threat Profile Threats.
DomainTools.Domains.Analytics.ThreatProfileRiskScore.Evidence String The DomainTools Threat Profile Evidence.
DomainTools.Domains.Analytics.WebsiteResponseCode Number The Website Response Code.
DomainTools.Domains.Analytics.Tags String The tags in DomainTools.
DomainTools.Domains.Identity.RegistrantName String The name of the registrant.
DomainTools.Domains.Identity.RegistrantOrg String The organization of the registrant.
DomainTools.Domains.Identity.RegistrantContact.Country.value String The country value of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Country.count Number The country count of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Email.value String The Email value of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Email.count Number The Email count of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Name.value String The name value of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Name.count Number The Name count of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Phone.value String The phone value of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Phone.count Number The phone count of the registrant contact.
DomainTools.Domains.Identity.SOAEmail String The SOA record Email.
DomainTools.Domains.Identity.SSLCertificateEmail String The email of the SSL certificate.
DomainTools.Domains.Identity.AdminContact.Country.value String The country value of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Country.count Number The country count of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Email.value String The Email value of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Email.count Number The Email count of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Name.value String The name value of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Name.count Number The name count of administrator contact.
DomainTools.Domains.Identity.AdminContact.Phone.value String The phone value of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Phone.count Number The phone count of the administrator contact.
DomainTools.Domains.Identity.TechnicalContact.Country.value String The country value of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Country.count Number The country count of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Email.value String The Email value of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Email.count Number The Email count of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Name.value String The name value of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Name.count Number The name count of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Phone.value String The phone value of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Phone.count Number The phone count of the technical contact.
DomainTools.Domains.Identity.BillingContact.Country.value String The country value of the billing contact.
DomainTools.Domains.Identity.BillingContact.Country.count Number The country count of the billing contact.
DomainTools.Domains.Identity.BillingContact.Email.value String The email value of the billing contact.
DomainTools.Domains.Identity.BillingContact.Email.count Number The email count of the billing contact.
DomainTools.Domains.Identity.BillingContact.Name.value String The name value of the billing contact.
DomainTools.Domains.Identity.BillingContact.Name.count Number The name count of the billing contact.
DomainTools.Domains.Identity.BillingContact.Phone.value String The phone value of the billing contact.
DomainTools.Domains.Identity.BillingContact.Phone.count Number The phone count of the billing contact.
DomainTools.Domains.Identity.EmailDomains String The domain of the Email.
DomainTools.Domains.Identity.AdditionalWhoisEmails.value String The value of the Additional Whois Emails.
DomainTools.Domains.Identity.AdditionalWhoisEmails.count Number The count of the Additional Whois Emails.
DomainTools.Domains.Registration.DomainRegistrant String The registrant of the domain.
DomainTools.Domains.Registration.RegistrarStatus String The status of the registrar.
DomainTools.Domains.Registration.DomainStatus Boolean The active status of the domain.
DomainTools.Domains.Registration.CreateDate Date The date the domain was created.
DomainTools.Domains.Registration.ExpirationDate Date The date the domain expires.
DomainTools.Domains.Hosting.IPAddresses.address.value String The address values of the IP addresses.
DomainTools.Domains.Hosting.IPAddresses.address.count Number The address counts of the IP addresses.
DomainTools.Domains.Hosting.IPAddresses.asn.value String The ASN values of the IP addresses.
DomainTools.Domains.Hosting.IPAddresses.asn.count Number The ASN counts of the IP addresses.
DomainTools.Domains.Hosting.IPAddresses.country_code.value String The country code values of the IP addresses.
DomainTools.Domains.Hosting.IPAddresses.country_code.count Number The country code counts of the IP addresses.
DomainTools.Domains.Hosting.IPAddresses.isp.value String IP Addresses Info isp value.
DomainTools.Domains.Hosting.IPAddresses.isp.count Number IP Addresses Info isp count.
DomainTools.Domains.Hosting.IPCountryCode String IP Country Code.
DomainTools.Domains.Hosting.MailServers.domain.value String Mail Servers Info domain value.
DomainTools.Domains.Hosting.MailServers.domain.count Number Mail Servers Info domain count.
DomainTools.Domains.Hosting.MailServers.host.value String Mail Servers Info host value.
DomainTools.Domains.Hosting.MailServers.host.count Number Mail Servers Info host count.
DomainTools.Domains.Hosting.MailServers.ip.value String Mail Servers Info ip value.
DomainTools.Domains.Hosting.MailServers.ip.count Number Mail Servers Info ip count.
DomainTools.Domains.Hosting.SPFRecord String The SPF record.
DomainTools.Domains.Hosting.NameServers.domain.value String The domain value of the DomainTools Domains NameServers.
DomainTools.Domains.Hosting.NameServers.domain.count Number The domain count of the DomainTools Domains NameServers.
DomainTools.Domains.Hosting.NameServers.host.value String The host value of the DomainTools Domains NameServers.
DomainTools.Domains.Hosting.NameServers.host.count Number The host count of the DomainTools Domains NameServers.
DomainTools.Domains.Hosting.NameServers.ip.value String The IP value of the DomainTools Domains NameServers.
DomainTools.Domains.Hosting.NameServers.ip.count Number The IP count of the DomainTools Domains NameServers.
DomainTools.Domains.Hosting.SSLCertificate.hash.value String The hash value of the SSL certificate.
DomainTools.Domains.Hosting.SSLCertificate.hash.count Number The hash count of the SSL certificate.
DomainTools.Domains.Hosting.SSLCertificate.organization.value String The organization value of the SSL certificate.
DomainTools.Domains.Hosting.SSLCertificate.organization.count Number The organization count of the SSL certificate.
DomainTools.Domains.Hosting.SSLCertificate.subject.value String The subject value of the SSL certificate.
DomainTools.Domains.Hosting.SSLCertificate.subject.count Number The subject count of the SSL certificate.
DomainTools.Domains.Hosting.RedirectsTo.value String The Redirects To value of the domain.
DomainTools.Domains.Hosting.RedirectsTo.count Number The Redirects To count of the domain.
DomainTools.Domains.Analytics.GoogleAdsenseTrackingCode Number The tracking code of Google Adsense.
DomainTools.Analytics.GoogleAnalyticTrackingCode Number The tracking code of Google Analytics.
DomainTools.Domains.Analytics.GA4TrackingCode Number The tracking code of ga4.
DomainTools.Domains.Analytics.GTMTrackingCode Number The tracking code of gtm.
DomainTools.Domains.Analytics.FBTrackingCode Number The tracking code of fb.
DomainTools.Domains.Analytics.HotJarTrackingCode Number The tracking code of Hot Jar.
DomainTools.Domains.Analytics.BaiduTrackingCode Number The tracking code of Baidu.
DomainTools.Domains.Analytics.YandexTrackingCode Number The tracking code of Yandex.
DomainTools.Domains.Analytics.MatomoTrackingCode Number The tracking code of Matomo.
DomainTools.Domains.Analytics.StatcounterProjectTrackingCode Number The tracking code of Stat Counter Project.
DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode Number The tracking code of Stat Counter Security.
DBotScore.Indicator String The DBotScore indicator.
DBotScore.Type String The indicator type of the DBotScore.
DBotScore.Vendor String The vendor used to calculate the score.
DBotScore.Score Number The actual score.

domaintoolsiris-threat-profile


Displays DomainTools Threat Profile data in a markdown format table.

Base Command

domaintoolsiris-threat-profile

Input

Argument Name Description Required
domain The domain name. Required

Context Output

Path Type Description
Domain.Name String The name of the domain.
Domain.DNS String The DNS of the domain.
Domain.DomainStatus Boolean The status of the domain.
Domain.CreationDate Date The creation date of the domain.
Domain.ExpirationDate Date The expiration date of the domain.
Domain.NameServers String The NameServers of the domain.
Domain.Registrant.Country String The registrant country of the domain.
Domain.Registrant.Email String The Email of the registrant domain.
Domain.Registrant.Name String The registrant name of the domain.
Domain.Registrant.Phone String The phone value of the registrant domain.
Domain.Malicious.Vendor String Vendor that classified the domain as malicious.
Domain.Malicious.Description String The description as to why the domain was found to be malicious.
DomainTools.Domains.Name String The DomainTools domain name.
DomainTools.Domains.LastEnriched Date The last time DomainTools enriched the domain data.
DomainTools.Domains.Analytics.OverallRiskScore Number The DomainTools Overall Risk Score.
DomainTools.Domains.Analytics.ProximityRiskScore Number The DomainTools Proximity Risk Score.
DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScore Number The DomainTools Threat Profile Risk Score.
DomainTools.Domains.Analytics.ThreatProfileRiskScore.Threats String The DomainTools Threat Profile Threats.
DomainTools.Domains.Analytics.ThreatProfileRiskScore.Evidence String The DomainTools Threat Profile Evidence.
DomainTools.Domains.Analytics.WebsiteResponseCode Number The response code of the Website.
DomainTools.Domains.Analytics.Tags String The DomainTools Tags.
DomainTools.Domains.Identity.RegistrantName String The name of the registrant.
DomainTools.Domains.Identity.RegistrantOrg String The organization of the registrant.
DomainTools.Domains.Identity.RegistrantContact.Country.value String The country value of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Country.count Number The county count of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Email.value String The Email value of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Email.count Number The Email count of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Name.value String The name value of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Name.count Number The name count of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Phone.value String The phone value of the registrant contact.
DomainTools.Domains.Identity.RegistrantContact.Phone.count Number The phone count of the registrant contact.
DomainTools.Domains.Identity.SOAEmail String The SOA record Email.
DomainTools.Domains.Identity.SSLCertificateEmail String The SSL certificate Email.
DomainTools.Domains.Identity.AdminContact.Country.value String The country value of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Country.count Number The country count of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Email.value String The Email value of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Email.count Number The Email count of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Name.value String The name value of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Name.count Number The name count of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Phone.value String The phone value of the administrator contact.
DomainTools.Domains.Identity.AdminContact.Phone.count Number The phone count of the administrator contact.
DomainTools.Domains.Identity.TechnicalContact.Country.value String The country value of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Country.count Number The country count of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Email.value String The Email value of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Email.count Number The Email count of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Name.value String The name value of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Name.count Number The name count of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Phone.value String The phone value of the technical contact.
DomainTools.Domains.Identity.TechnicalContact.Phone.count Number The phone count of the technical contact.
DomainTools.Domains.Identity.BillingContact.Country.value String The country value of the billing contact.
DomainTools.Domains.Identity.BillingContact.Country.count Number The country count of the billing contact.
DomainTools.Domains.Identity.BillingContact.Email.value String The Email value of the billing contact.
DomainTools.Domains.Identity.BillingContact.Email.count Number The Email count of the billing contact.
DomainTools.Domains.Identity.BillingContact.Name.value String The name value of the billing contact.
DomainTools.Domains.Identity.BillingContact.Name.count Number The name count of the billing contact.
DomainTools.Domains.Identity.BillingContact.Phone.value String The phone value of the billing contact.
DomainTools.Domains.Identity.BillingContact.Phone.count Number The phone count of the billing contact.
DomainTools.Domains.Identity.EmailDomains String The Email domains.
DomainTools.Domains.Identity.AdditionalWhoisEmails.value String The value of the Additional Whois Emails.
DomainTools.Domains.Identity.AdditionalWhoisEmails.count Number The count of the Additional Whois Emails.
DomainTools.Domains.Registration.DomainRegistrant String The registrant of the domain.
DomainTools.Domains.Registration.RegistrarStatus String The status of the registrar.
DomainTools.Domains.Registration.DomainStatus Boolean The active status of the domain.
DomainTools.Domains.Registration.CreateDate Date The date the domain was created.
DomainTools.Domains.Registration.ExpirationDate Date The expiry date of the domain.
DomainTools.Domains.Hosting.IPAddresses.address.value String The address value of the IP Addresses.
DomainTools.Domains.Hosting.IPAddresses.address.count Number The address count of the IP Addresses.
DomainTools.Domains.Hosting.IPAddresses.asn.value String The ASN value of the IP Addresses.
DomainTools.Domains.Hosting.IPAddresses.asn.count Number The ASN count of the IP Addresses.
DomainTools.Domains.Hosting.IPAddresses.country_code.value String The country code of the IP Addresses.
DomainTools.Domains.Hosting.IPAddresses.country_code.count Number The country code count of the IP Addresses.
DomainTools.Domains.Hosting.IPAddresses.isp.value String ISP value of the IP Addresses.
DomainTools.Domains.Hosting.IPAddresses.isp.count Number The ISP count of the IP Addresses.
DomainTools.Domains.Hosting.IPCountryCode String The country code of the IP address.
DomainTools.Domains.Hosting.MailServers.domain.value String The domain value of the Mail Servers.
DomainTools.Domains.Hosting.MailServers.domain.count Number The domain count of the Mail Servers.
DomainTools.Domains.Hosting.MailServers.host.value String The host value of the Mail Servers.
DomainTools.Domains.Hosting.MailServers.host.count Number The host count of the Mail Servers.
DomainTools.Domains.Hosting.MailServers.ip.value String The IP value of the Mail Servers.
DomainTools.Domains.Hosting.MailServers.ip.count Number The IP count of the Mail Servers.
DomainTools.Domains.Hosting.SPFRecord String The SPF Record.
DomainTools.Domains.Hosting.NameServers.domain.value String The domain value of the DomainTools Domains NameServers.
DomainTools.Domains.Hosting.NameServers.domain.count Number The domain count of the DomainTools Domains NameServers.
DomainTools.Domains.Hosting.NameServers.host.value String The host value of the DomainTools Domains NameServers.
DomainTools.Domains.Hosting.NameServers.host.count Number The host count of the DomainTools Domains NameServers.
DomainTools.Domains.Hosting.NameServers.ip.value String The IP value of the DomainTools Domains NameServers.
DomainTools.Domains.Hosting.NameServers.ip.count Number The IP count of the DomainTools Domains NameServers.
DomainTools.Domains.Hosting.SSLCertificate.hash.value String The hash value of the SSL certificate.
DomainTools.Domains.Hosting.SSLCertificate.hash.count Number The hash count of the SSL certificate.
DomainTools.Domains.Hosting.SSLCertificate.organization.value String The organization value of the SSL certificate.
DomainTools.Domains.Hosting.SSLCertificate.organization.count Number The organization count of the SSL certificate.
DomainTools.Domains.Hosting.SSLCertificate.subject.value String The subject value of the SSL certificate.
DomainTools.Domains.Hosting.SSLCertificate.subject.count Number The subject count of the SSL certificate.
DomainTools.Domains.Hosting.RedirectsTo.value String The Redirects To value of the domain.
DomainTools.Domains.Hosting.RedirectsTo.count Number The Redirects To count of the domain.
DomainTools.Domains.Analytics.GoogleAdsenseTrackingCode Number The tracking code of Google Adsense.
DomainTools.Analytics.GoogleAnalyticTrackingCode Number The tracking code of Google Analytics.
DomainTools.Domains.Analytics.GA4TrackingCode Number The tracking code of ga4.
DomainTools.Domains.Analytics.GTMTrackingCode Number The tracking code of gtm.
DomainTools.Domains.Analytics.FBTrackingCode Number The tracking code of fb.
DomainTools.Domains.Analytics.HotJarTrackingCode Number The tracking code of Hot Jar.
DomainTools.Domains.Analytics.BaiduTrackingCode Number The tracking code of Baidu.
DomainTools.Domains.Analytics.YandexTrackingCode Number The tracking code of Yandex.
DomainTools.Domains.Analytics.MatomoTrackingCode Number The tracking code of Matomo.
DomainTools.Domains.Analytics.StatcounterProjectTrackingCode Number The tracking code of Stat Counter Project.
DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode Number The tracking code of Stat Counter Security.
DBotScore.Indicator String The DBotScore indicator.
DBotScore.Type String The indicator type of the DBotScore.
DBotScore.Vendor String The vendor used to calculate the score.
DBotScore.Score Number The actual score.

domaintoolsiris-pivot


Pivot on connected infrastructure (IP, email, SSL), or import domains from Iris Investigate using a search hash. Retrieves up to 5000 domains at a time. Optionally exclude results from context with include_context=false.

Base Command

domaintoolsiris-pivot

Input

Argument Name Description Required
ip The IP Address. Optional
email The Email Address. Optional
nameserver_ip The Name Server IP Address. Optional
ssl_hash The hash of the SSL. Optional
nameserver_host The fully-qualified host name of the name server. For example, ns1.domaintools.net. Optional
mailserver_host The fully-qualified host name of the mail server. For example, mx.domaintools.net. Optional
email_domain Only the domain portion of a Whois or DNS SOA email address. Optional
nameserver_domain Registered domain portion of the name server. Optional
registrar Exact match to the Whois registrar field. Optional
registrant Exact match to the Whois registrant field. Optional
registrant_org Exact match to the Whois registrant organization field. Optional
tagged_with_any Comma-separated list of Iris Investigate tags. Returns domains tagged with any of the tags in a list. Optional
tagged_with_all Comma-separated list of tags. Only returns domains tagged with the full list of tags. Optional
mailserver_domain Only the registered domain portion of the mail server (domaintools.net). Optional
mailserver_ip IP address of the mail server. Optional
redirect_domain Find domains observed to redirect to another domain name. Optional
ssl_org Exact match to the organization name on the SSL certificate. Optional
ssl_subject Subject field from the SSL certificate. Optional
ssl_email Email address from the SSL certificate. Optional
google_analytics Domains with a Google Analytics tracking code. Optional
adsense Domains with a Google AdSense tracking code. Optional
search_hash Encoded search from the Iris UI. Optional
include_context Include the results of the pivot in Context Data. Defaults to true. Possible values are: true, false. Default is true. Optional

Context Output

Path Type Description
DomainTools.Pivots.PivotedDomains.Name String The DomainTools Domain Name.
DomainTools.Pivots.PivotedDomains.LastEnriched Date The last time DomainTools enriched the domain data.
DomainTools.Pivots.PivotedDomains.Analytics.OverallRiskScore Number The DomainTools Overall Risk Score.
DomainTools.Pivots.PivotedDomains.Analytics.ProximityRiskScore Number The DomainTools Proximity Risk Score.
DomainTools.Pivots.PivotedDomains.Analytics.ThreatProfileRiskScore.RiskScore Number The DomainTools Threat Profile Risk Score.
DomainTools.Pivots.PivotedDomains.Analytics.ThreatProfileRiskScore.Threats String The DomainTools Threat Profile Threats.
DomainTools.Pivots.PivotedDomains.Analytics.ThreatProfileRiskScore.Evidence String The DomainTools Threat Profile Evidence.
DomainTools.Pivots.PivotedDomains.Analytics.WebsiteResponseCode Number The response code of the website.
DomainTools.Pivots.PivotedDomains.Analytics.Tags String The DomainTools tags.
DomainTools.Pivots.PivotedDomains.Identity.RegistrantName String The name of the registrant.
DomainTools.Pivots.PivotedDomains.Identity.RegistrantOrg String The organization of the registrant.
DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Country.value String The country value of the registrant contact.
DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Country.count Number The country count of the registrant contact.
DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Email.value String The Email value of the registrant contact.
DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Email.count Number The Email count of the registrant contact.
DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Name.value String The name value of the registrant contact.
DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Name.count Number The name count of the registrant contact.
DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Phone.value String The phone value of of the registrant contact.
DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Phone.count Number The phone count of the registrant contact.
DomainTools.Pivots.PivotedDomains.Identity.SOAEmail String The SOA record Email.
DomainTools.Pivots.PivotedDomains.Identity.SSLCertificateEmail String The SSL certificate Email.
DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Country.value String The country value of the administrator contact.
DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Country.count Number The country count of the administrator contact.
DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Email.value String The Email value of the administrator contact.
DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Email.count Number The Email count of the administrator contact.
DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Name.value String The name value of the administrator contact.
DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Name.count Number The name count of the administrator contact.
DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Phone.value String The phone value of the administrator contact.
DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Phone.count Number The phone count of the administrator contact.
DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Country.value String The country value of the technical contact.
DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Country.count Number The country count of the technical contact.
DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Email.value String The Email value of the technical contact.
DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Email.count Number The Email count of the technical contact.
DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Name.value String The name value of the technical contact.
DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Name.count Number The name count of the technical contact.
DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Phone.value String The phone value of the technical contact.
DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Phone.count Number The phone count of the technical contact.
DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Country.value String The country value of the billing contact.
DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Country.count Number The country count of the billing contact.
DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Email.value String The Email value of the billing contact.
DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Email.count Number The Email count of the billing contact.
DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Name.value String The Name value of the billing contact.
DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Name.count Number The Name count of the billing contact.
DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Phone.value String The phone value of the billing contact.
DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Phone.count Number The phone count of the billing contact.
DomainTools.Pivots.PivotedDomains.Identity.EmailDomains String The Email domains.
DomainTools.Pivots.PivotedDomains.Identity.AdditionalWhoisEmails.value String The value of the Additional Whois Emails.
DomainTools.Pivots.PivotedDomains.Identity.AdditionalWhoisEmails.count Number The count of the Additional Whois Emails.
DomainTools.Pivots.PivotedDomains.Registration.DomainRegistrant String The Registrant of the domain.
DomainTools.Pivots.PivotedDomains.Registration.RegistrarStatus String The status of the registrar.
DomainTools.Pivots.PivotedDomains.Registration.DomainStatus Boolean The active status of the registrar.
DomainTools.Pivots.PivotedDomains.Registration.CreateDate Date The date the domain was created.
DomainTools.Pivots.PivotedDomains.Registration.ExpirationDate Date The Expiry date of the domain.
DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.address.value String The address value of IP addresses.
DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.address.count Number The address count of IP addresses.
DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.asn.value String The ASN value of IP addresses.
DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.asn.count Number The ASN count of IP addresses.
DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.country_code.value String The country code value of IP addresses.
DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.country_code.count Number The country code count of IP addresses.
DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.isp.value String The ISP value of IP addresses.
DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.isp.count Number The ISP count of IP addresses.
DomainTools.Pivots.PivotedDomains.Hosting.IPCountryCode String The country code of the IP address.
DomainTools.Pivots.PivotedDomains.Hosting.MailServers.domain.value String The domain value of the Mail Servers.
DomainTools.Pivots.PivotedDomains.Hosting.MailServers.domain.count Number The domain count of the Mail Servers.
DomainTools.Pivots.PivotedDomains.Hosting.MailServers.host.value String The host value of the Mail Servers.
DomainTools.Pivots.PivotedDomains.Hosting.MailServers.host.count Number The host count of the Mail Servers.
DomainTools.Pivots.PivotedDomains.Hosting.MailServers.ip.value String The IP address value of the Mail Servers.
DomainTools.Pivots.PivotedDomains.Hosting.MailServers.ip.count Number The IP address count of the Mail Servers.
DomainTools.Pivots.PivotedDomains.Hosting.SPFRecord String The SPF record Information.
DomainTools.Pivots.PivotedDomains.Hosting.NameServers.domain.value String The domain value of DomainTools Domains NameServers.
DomainTools.Pivots.PivotedDomains.Hosting.NameServers.domain.count Number The domain count of DomainTools Domains NameServers.
DomainTools.Pivots.PivotedDomains.Hosting.NameServers.host.value String The host value of DomainTools Domains NameServers.
DomainTools.Pivots.PivotedDomains.Hosting.NameServers.host.count Number The host count of DomainTools Domains NameServers.
DomainTools.Pivots.PivotedDomains.Hosting.NameServers.ip.value String The IP address value of DomainTools Domains NameServers.
DomainTools.Pivots.PivotedDomains.Hosting.NameServers.ip.count Number The IP address count of DomainTools Domains NameServers.
DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.hash.value String The hash value of the SSL certificate.
DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.hash.count Number The hash count of the SSL certificate.
DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.organization.value String The organization value of the SSL certificate.
DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.organization.count Number The organization count of the SSL certificate.
DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.subject.value String The subject value of the SSL certificate.
DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.subject.count Number The subject count of the SSL certificate.
DomainTools.Pivots.PivotedDomains.Hosting.RedirectsTo.value String The Redirects To value of the domain.
DomainTools.Pivots.PivotedDomains.Hosting.RedirectsTo.count Number The Redirects To count of the domain.
DomainTools.Pivots.PivotedDomains.Analytics.GoogleAdsenseTrackingCode Number The tracking code of Google Adsense.
DomainTools.Pivots.PivotedDomains.Analytics.GoogleAnalyticTrackingCode Number The tracking code Google Analytics.

domaintools-whois-history


The DomainTools Whois History API endpoint returns up to 100 historical Whois records associated with a domain name.

Base Command

domaintools-whois-history

Input

Argument Name Description Required
domain A domain name to query (e.g. example.com). Required
mode options: list, count, check_existence. list: (default), return whois records. count: return how many total records are available. check_existence: return if any records exist. Default: list. Possible values are: list, count, check_existence. Default is list. Optional
offset numeric, the index from which to begin retrieving results. Default: 0. Default is 0. Optional
limit numeric, default: 100, max: 100, the total number of records to return. Default: 100. Default is 100. Optional
sort options: date_desc, date_asc. date_desc: (default), order records from newest to oldest. date_asc: sort order records from oldest to newest. Default: date_desc. Possible values are: date_desc, date_asc. Default is date_desc. Optional

Context Output

Path Type Description
DomainTools.History.Value unknown Name of domain.
DomainTools.History.WhoisHistory unknown Domain Whois history data.

domaintools-hosting-history


Hosting History will list IP address, name server and registrar history.

Base Command

domaintools-hosting-history

Input

Argument Name Description Required
domain A domain name to query (e.g. example.com). Required

Context Output

Path Type Description
DomainTools.History.Value unknown Name of domain.
DomainTools.History.IPHistory unknown Domain IP history data.
DomainTools.History.NameserverHistory unknown Domain Nameserver history data.
DomainTools.History.RegistrarHistory unknown Domain Registrar history data.

domaintools-reverse-whois


The DomainTools Reverse Whois API provides a list of domain names that share the same Registrant Information. You can enter terms that describe a domain owner, like an email address or a company name, and you’ll get a list of domain names that have your search terms listed in the Whois record.

Base Command

domaintools-reverse-whois

Input

Argument Name Description Required
terms (default) List of one or more terms to search for in the Whois record, separated with the pipe character ( | ). Required
exclude Domain names with Whois records that match these terms will be excluded from the result set. Separate multiple terms with the pipe character ( | ). Optional
onlyHistoricScope Show only historic records. Possible values are: true, false. Default is false. Optional

Context Output

Path Type Description
DomainTools.ReverseWhois.Value unknown Search term to reverse whois lookup on.
DomainTools.ReverseWhois.Results unknown List of results for reverse whois lookup.

domaintools-whois


The DomainTools Parsed Whois API provides parsed information extracted from the raw Whois record. The API is optimized to quickly retrieve the Whois record, group important data together and return a well-structured format. The Parsed Whois API is ideal for anyone wishing to search for, index, or cross-reference data from one or multiple Whois records.

Base Command

domaintools-whois

Input

Argument Name Description Required
query A domain name or IP address (e.g. example.com or 192.168.1.1). Required

Context Output

Path Type Description
Domain.Name unknown Requested domain name.
Domain.Whois unknown Parsed Whois data.
Domain.WhoisRecords unknown Full Whois record.

domainRdap


Returns the most recent Domain-RDAP registration record.

Base Command

domainRdap

Input

Argument Name Description Required
domain Specify the domain (e.g., mycompany.com). Required

Context Output

There is no context output for this command.

reverseNameServer


Reverse nameserver lookup.

Base Command

reverseNameServer

Input

Argument Name Description Required
nameServer Specify the name of the primary or secondary nameserver. Required
limit Limit the size of the domain list than can appear in a response. Default is 50. Optional

Context Output

Path Type Description
Domain.Name unknown Name of the domain returned by the query.

reverseIP


Reverse loopkup of an IP address or a domain.

Base Command

reverseIP

Input

Argument Name Description Required
ip Specify the IP address to query. Optional
domain If a domain name is provided, DomainTools will respond with the list of other domains that share the same IP. Optional
limit Limits the size of the domain list than can appear in a response. The limit is applied per-IP address, not for the entire request. Default is 50. Optional

Context Output

Path Type Description
Domain.Name unknown Domain name returned by the query.
Domain.DNS.Address unknown The IP address associated with the returned domains.

Configuration parameters

  • credentials — API Username
  • username — API Username
  • apikey — API Key
  • risk_threshold — High-Risk Threshold (required)
  • young_domain_timeframe — Young Domain Timeframe (within Days) (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • domain_result_type — Domain Result Type
  • domain_enrichment_method — Domain Enrichment Method (DomainTools)
  • domain_auto_enrich — Domain Auto-Enrich on Ingestion
  • integrationReliability — Source Reliability
  • feedExpirationPolicy
  • feedExpirationInterval
  • pivot_threshold — Guided Pivot Threshold (required)
  • monitor_iris_search_hash — Enabled on Monitoring Domains by Iris Search Hash
  • domaintools_iris_search_hash — Domaintools Iris Investigate Search Hash
  • monitor_iris_tags — Enabled on Monitoring Domains by Iris Tags
  • domaintools_iris_tags — Domaintools Iris Tags
  • max_fetch — Maximum number of incidents to fetch
  • incidentType — Incident type
  • incidentFetchInterval — Incidents Fetch Interval
  • isFetch — Fetch incidents
  • first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)

Commands (13)

  • domain

    Provides data enrichment for domains.

  • domainRdap

    Returns the most recent Domain-RDAP registration record.

  • domaintools-hosting-history

    Hosting History will list IP address, name server and registrar history.

  • domaintools-reverse-whois

    The DomainTools Reverse Whois API provides a list of domain names that share the same Registrant Information. You can enter terms that describe a domain owner, like an email address or a company name, and you’ll get a list of domain names that have your search terms listed in the Whois record.

  • domaintools-whois

    The DomainTools Parsed Whois API provides parsed information extracted from the raw Whois record. The API is optimized to quickly retrieve the Whois record, group important data together and return a well-structured format. The Parsed Whois API is ideal for anyone wishing to search for, index, or cross-reference data from one or multiple Whois records.

  • domaintools-whois-history

    The DomainTools Whois History API endpoint returns up to 100 historical Whois records associated with a domain name.

  • domaintoolsiris-analytics

    Displays DomainTools Analytic data in a markdown format table.

  • domaintoolsiris-enrich

    Returns a complete profile of the domain (SLD.TLD) using Iris Enrich. If parsing of URLs or FQDNs is desired, see domainExtractAndEnrich.

  • domaintoolsiris-investigate

    Returns a complete profile of the domain (SLD.TLD) using Iris Investigate. If parsing of FQDNs is desired, see domainExtractAndInvestigate.

  • domaintoolsiris-pivot

    Pivot on connected infrastructure (IP, email, SSL), or import domains from Iris Investigate using a search hash. Retrieves up to 5000 domains at a time. Optionally exclude results from context with include_context=false.

  • domaintoolsiris-threat-profile

    Displays DomainTools Threat Profile data in a markdown format table.

  • reverseIP

    Reverse loopkup of an IP address or a domain.

  • reverseNameServer

    Reverse nameserver lookup.

category: Data Enrichment & Threat Intelligence
provider: DomainTools
commonfields:
  id: DomainTools Iris
  version: -1
configuration:
- display: API Username
  name: credentials
  type: 9
  required: false
  displaypassword: API Key
  section: Connect
- display: API Username
  name: username
  required: false
  hidden: true
  type: 0
  section: Connect
- display: API Key
  name: apikey
  required: false
  hidden: true
  type: 4
  section: Connect
- display: High-Risk Threshold
  name: risk_threshold
  required: true
  type: 0
  defaultvalue: '70'
  section: Connect
- defaultvalue: '7'
  display: Young Domain Timeframe (within Days)
  name: young_domain_timeframe
  required: true
  type: 0
  section: Connect
- display: Trust any certificate (not secure)
  name: insecure
  required: false
  type: 8
  section: Connect
- display: Use system proxy settings
  name: proxy
  type: 8
  required: false
  section: Connect
- display: Domain Result Type
  name: domain_result_type
  type: 15
  required: false
  additionalinfo: "Result type of the domain command: Iris returns full investigate results; Verdict returns only the domain risk score"
  defaultvalue: Iris
  options:
  - Iris
  - Verdict
  section: Collect
- defaultvalue: Iris Investigate
  display: 'Domain Enrichment Method (DomainTools)'
  name: domain_enrichment_method
  options:
  - Iris Investigate
  - Iris Enrich
  type: 15
  required: false
  section: Collect
  additionalinfo: "Iris API to be used for domain enrichment. Defaults to Iris Investigate."
- defaultvalue: 'Disabled'
  name: domain_auto_enrich
  display: 'Domain Auto-Enrich on Ingestion'
  type: 15
  required: false
  section: Collect
  options:
  - Enabled
  - Disabled
  additionalinfo: "Enable real-time enrichment for incoming ingested domain. Note: This may consume Iris API quotas."
- defaultvalue: 'B - Usually reliable'
  name: integrationReliability
  display: 'Source Reliability'
  type: 15
  required: false
  section: Collect
  options:
  - A+ - 3rd party enrichment
  - A - Completely reliable
  - B - Usually reliable
  - C - Fairly reliable
  - D - Not usually reliable
  - E - Unreliable
  - F - Reliability cannot be judged
  additionalinfo: Reliability of the source providing the intelligence data.
- display: ''
  name: feedExpirationPolicy
  defaultvalue: 'indicatorType'
  type: 17
  required: false
  section: Collect
  options:
  - never
  - interval
  - indicatorType
  - suddenDeath
- display: ''
  name: feedExpirationInterval
  type: 1
  required: false
  section: Collect
  defaultvalue: '20160'
- display: 'Guided Pivot Threshold'
  name: pivot_threshold
  type: 1
  required: true
  section: Connect
  additionalinfo: When a small set of domains share an attribute (e.g. registrar), that can often be pivoted on in order to find other similar domains of interest. DomainTools tracks how many domains share each attribute and can highlight it for further investigation when the number of domains is beneath the set threshold.
  defaultvalue: 500
- display: 'Enabled on Monitoring Domains by Iris Search Hash'
  name: monitor_iris_search_hash
  type: 15
  required: false
  section: Collect
  defaultvalue: Import Indicators Only
  options:
  - Import Indicators Only
  - Create Incident and Import Indicators
- display: 'Domaintools Iris Investigate Search Hash'
  name: domaintools_iris_search_hash
  required: false
  type: 12
  additionalinfo: The DomainTools Iris Investigate Search hash
  section: Collect
- display: 'Enabled on Monitoring Domains by Iris Tags'
  name: monitor_iris_tags
  type: 15
  section: Collect
  defaultvalue: 'Import Indicators Only'
  required: false
  options:
  - Import Indicators Only
  - Create Incident and Import Indicators
- display: Domaintools Iris Tags
  name: domaintools_iris_tags
  type: 12
  section: Collect
  required: false
  additionalinfo: The DomainTools Iris Tags (Values should be a comma separated value. e.g. (tag1,tag2))
- display: Maximum number of incidents to fetch
  name: max_fetch
  type: 0
  section: Collect
  defaultvalue: '2'
  required: false
  additionalinfo: This is a required field by XSOAR and should be set to 2, one for each possible feed type iris search hash and iris tags.
- display: Incident type
  name: incidentType
  type: 13
  section: Collect
- display: Incidents Fetch Interval
  name: incidentFetchInterval
  defaultvalue: '1'
  required: false
  type: 19
  section: Collect
  advanced: true
- display: Fetch incidents
  name: isFetch
  type: 8
  section: Collect
- display: First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
  defaultvalue: 7 days
  name: first_fetch
  required: false
  type: 0
  additionalinfo: How far back in time to go when performing the first fetch.
  section: Collect
description: Together, DomainTools and Cortex XSOAR automate and orchestrate the incident response process with essential domain profile, web crawl, SSL and infrastructure data. SOCs can create custom, automated workflows to trigger Indicator of Compromise (IoC) investigations, block threats based on connected infrastructure, and identify potentially malicious domains before weaponization. The DomainTools App for Cortex XSOAR is shipped with pre-built playbooks to enable automated enrichment, decision logic, ad-hoc investigations, and the ability to persist enriched intelligence.
display: DomainTools Iris
name: DomainTools Iris
script:
  commands:
  - arguments:
    - default: true
      description: The domain to enrich.
      name: domain
      required: true
      isArray: false
      secret: false
    - name: bypass_auto_enrich
      description: Bypasses the Domain Auto-Enrich on Ingestion.
      default: false
      required: false
      isArray: false
      secret: false
      auto: PREDEFINED
      predefined:
      - "true"
      - "false"
      defaultValue: "false"
    description: Provides data enrichment for domains.
    name: domain
    outputs:
    - contextPath: Domain.Name
      description: The name of the domain.
      type: String
    - contextPath: Domain.DNS
      description: The DNS of the domain.
      type: String
    - contextPath: Domain.DomainStatus
      description: The status of the domain.
      type: Boolean
    - contextPath: Domain.CreationDate
      description: The creation date.
      type: Date
    - contextPath: Domain.ExpirationDate
      description: The expiration date of the domain.
      type: Date
    - contextPath: Domain.NameServers
      description: The nameServers of the domain.
      type: String
    - contextPath: Domain.Registrant.Country
      description: The registrant country of the domain.
      type: String
    - contextPath: Domain.Registrant.Email
      description: The registrant email of the domain.
      type: String
    - contextPath: Domain.Registrant.Name
      description: The registrant name of the domain.
      type: String
    - contextPath: Domain.Registrant.Phone
      description: The registrant phone number of the domain.
      type: String
    - contextPath: Domain.Malicious.Vendor
      description: The vendor who classified the domain as malicious.
      type: String
    - contextPath: Domain.Malicious.Description
      description: The description as to why the domain was found to be malicious.
      type: String
    - contextPath: DomainTools.Name
      description: The domain name in DomainTools.
      type: String
    - contextPath: DomainTools.LastEnriched
      description: The last Time DomainTools enriched domain data.
      type: Date
    - contextPath: DomainTools.Analytics.OverallRiskScore
      description: The Overall Risk Score in DomainTools.
      type: Number
    - contextPath: DomainTools.Analytics.ProximityRiskScore
      description: The Proximity Risk Score in DomainTools.
      type: Number
    - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.RiskScore
      description: The Threat Profile Risk Score in DomainTools.
      type: Number
    - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.Threats
      description: The threats of the Threat Profile Risk Score in DomainTools.
      type: String
    - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.Evidence
      description: The Threat Profile Risk Score Evidence in DomainTools.
      type: String
    - contextPath: DomainTools.Analytics.WebsiteResponseCode
      description: The Website Response Code in DomainTools.
      type: Number
    - contextPath: DomainTools.Analytics.Tags
      description: The Tags in DomainTools.
      type: String
    - contextPath: DomainTools.Identity.RegistrantName
      description: The name of the registrant.
      type: String
    - contextPath: DomainTools.Identity.RegistrantOrg
      description: The organization of the registrant.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Country.value
      description: The country value of the registrant contact.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Country.count
      description: The count of the registrant contact country.
      type: Number
    - contextPath: DomainTools.Identity.RegistrantContact.Email.value
      description: The Email value of the registrant contact.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Email.count
      description: The Email count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Identity.RegistrantContact.Name.value
      description: The name value of the registrant contact.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Name.count
      description: The name count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Identity.RegistrantContact.Phone.value
      description: The phone value of the registrant contact.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Phone.count
      description: The phone count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Identity.SOAEmail
      description: The SOA record of the Email.
      type: String
    - contextPath: DomainTools.Identity.SSLCertificateEmail
      description: The Email of the SSL certificate.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Country.value
      description: The country value of the administrator contact.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Country.count
      description: The country count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Identity.AdminContact.Email.value
      description: The Email value of the administrator contact.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Email.count
      description: The Email count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Identity.AdminContact.Name.value
      description: The name value of the administrator contact.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Name.count
      description: The name count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Identity.AdminContact.Phone.value
      description: The phone value of the administrator contact.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Phone.count
      description: The phone count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Identity.TechnicalContact.Country.value
      description: The country value of the technical contact.
      type: String
    - contextPath: DomainTools.Identity.TechnicalContact.Country.count
      description: The country count of the technical contact.
      type: Number
    - contextPath: DomainTools.Identity.TechnicalContact.Email.value
      description: The Email value of the technical contact.
      type: String
    - contextPath: DomainTools.Identity.TechnicalContact.Email.count
      description: The Email count of the technical contact.
      type: Number
    - contextPath: DomainTools.Identity.TechnicalContact.Name.value
      description: The name value of the technical Contact.
      type: String
    - contextPath: DomainTools.Identity.TechnicalContact.Name.count
      description: The name count of the technical contact.
      type: Number
    - contextPath: DomainTools.Identity.TechnicalContact.Phone.value
      description: The phone value of the technical contact.
      type: String
    - contextPath: DomainTools.Identity.TechnicalContact.Phone.count
      description: The phone count of the technical contact.
      type: Number
    - contextPath: DomainTools.Identity.BillingContact.Country.value
      description: The country value of the billing contact.
      type: String
    - contextPath: DomainTools.Identity.BillingContact.Country.count
      description: The country count of the billing contact.
      type: Number
    - contextPath: DomainTools.Identity.BillingContact.Email.value
      description: The Email value of the billing contact.
      type: String
    - contextPath: DomainTools.Identity.BillingContact.Email.count
      description: The Email count of the billing contact.
      type: Number
    - contextPath: DomainTools.Identity.BillingContact.Name.value
      description: The name value of the billing contact.
      type: String
    - contextPath: DomainTools.Identity.BillingContact.Name.count
      description: The name count of the billing contact.
      type: Number
    - contextPath: DomainTools.Identity.BillingContact.Phone.value
      description: The phone value of the billing contact.
      type: String
    - contextPath: DomainTools.Identity.BillingContact.Phone.count
      description: The phone count of the billing contact.
      type: Number
    - contextPath: DomainTools.Identity.EmailDomains
      description: The Email Domains.
      type: String
    - contextPath: DomainTools.Identity.AdditionalWhoisEmails.value
      description: The value of the Additional Whois Emails record.
      type: String
    - contextPath: DomainTools.Identity.AdditionalWhoisEmails.count
      description: The count of the Additional Whois Emails record.
      type: Number
    - contextPath: DomainTools.Registration.DomainRegistrant
      description: The registrant of the domain.
      type: String
    - contextPath: DomainTools.Registration.RegistrarStatus
      description: The status of the registrar.
      type: String
    - contextPath: DomainTools.Registration.DomainStatus
      description: The active status of the domain.
      type: Boolean
    - contextPath: DomainTools.Registration.CreateDate
      description: The date the domain was created.
      type: Date
    - contextPath: DomainTools.Registration.ExpirationDate
      description: The expiration date of the domain.
      type: Date
    - contextPath: DomainTools.Hosting.IPAddresses.address.value
      description: The address value of IP addresses.
      type: String
    - contextPath: DomainTools.Hosting.IPAddresses.address.count
      description: The address count of IP addresses.
      type: Number
    - contextPath: DomainTools.Hosting.IPAddresses.asn.value
      description: The ASN value of IP addresses.
      type: String
    - contextPath: DomainTools.Hosting.IPAddresses.asn.count
      description: The ASN count of IP addresses.
      type: Number
    - contextPath: DomainTools.Hosting.IPAddresses.country_code.value
      description: The country code value of IP addresses.
      type: String
    - contextPath: DomainTools.Hosting.IPAddresses.country_code.count
      description: The country code count of IP addresses.
      type: Number
    - contextPath: DomainTools.Hosting.IPAddresses.isp.value
      description: The ISP value of IP addresses.
      type: String
    - contextPath: DomainTools.Hosting.IPAddresses.isp.count
      description: The ISP count of IP addresses.
      type: Number
    - contextPath: DomainTools.Hosting.IPCountryCode
      description: The country code of the IP address.
      type: String
    - contextPath: DomainTools.Hosting.MailServers.domain.value
      description: The domain value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Hosting.MailServers.domain.count
      description: The domain count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Hosting.MailServers.host.value
      description: The host value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Hosting.MailServers.host.count
      description: The host count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Hosting.MailServers.ip.value
      description: The IP value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Hosting.MailServers.ip.count
      description: The IP count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Hosting.SPFRecord
      description: The SPF Record.
      type: String
    - contextPath: DomainTools.Hosting.NameServers.domain.value
      description: The domain value of the domain NameServers.
      type: String
    - contextPath: DomainTools.Hosting.NameServers.domain.count
      description: The domain count of the domain NameServers.
      type: Number
    - contextPath: DomainTools.Hosting.NameServers.host.value
      description: The host value of the domain NameServers.
      type: String
    - contextPath: DomainTools.Hosting.NameServers.host.count
      description: The host count of the domain NameServers.
      type: Number
    - contextPath: DomainTools.Hosting.NameServers.ip.value
      description: The IP value of the domain NameServers.
      type: String
    - contextPath: DomainTools.Hosting.NameServers.ip.count
      description: The IP count of domain NameServers.
      type: Number
    - contextPath: DomainTools.Hosting.SSLCertificate.hash.value
      description: The hash value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Hosting.SSLCertificate.hash.count
      description: The hash count of the SSL certificate.
      type: Number
    - contextPath: DomainTools.Hosting.SSLCertificate.organization.value
      description: The organization value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Hosting.SSLCertificate.organization.count
      description: The organization count of the SSL certificate information.
      type: Number
    - contextPath: DomainTools.Hosting.SSLCertificate.subject.value
      description: The subject value of the SSL certificate information.
      type: String
    - contextPath: DomainTools.Hosting.SSLCertificate.subject.count
      description: The subject count of the SSL certificate information.
      type: Number
    - contextPath: DomainTools.Hosting.RedirectsTo.value
      description: The Redirects To Value of the domain.
      type: String
    - contextPath: DomainTools.Hosting.RedirectsTo.count
      description: The Redirects To Count of the domain.
      type: Number
    - contextPath: DomainTools.Analytics.GoogleAdsenseTrackingCode
      description: The tracking code of Google Adsense.
      type: Number
    - contextPath: DomainTools.Analytics.GoogleAnalyticTrackingCode
      description: The tracking code of Google Analytics.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.GA4TrackingCode
      description: The tracking code of ga4.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.GTMTrackingCode
      description: The tracking code of gtm.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.FBTrackingCode
      description: The tracking code of fb.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.HotJarTrackingCode
      description: The tracking code of Hot Jar.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.BaiduTrackingCode
      description: The tracking code of Baidu.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.YandexTrackingCode
      description: The tracking code of Yandex.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.MatomoTrackingCode
      description: The tracking code of Matomo.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.StatcounterProjectTrackingCode
      description: The tracking code of Stat Counter Project.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode
      description: The tracking code of Stat Counter Security.
      type: Number
    - contextPath: DomainTools.WebsiteTitle
      description: The website title.
      type: Number
    - contextPath: DomainTools.FirstSeen
      description: The date the domain was first seen.
      type: Number
    - contextPath: DomainTools.ServerType
      description: The server type.
      type: Number
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    deprecated: false
    execution: false
  - arguments:
    - description: Specify the domain (e.g., mycompany.com).
      name: domain
      required: true
      default: true
      isArray: false
      secret: false
    description: Returns the most recent Domain-RDAP registration record.
    name: domainRdap
    deprecated: false
    execution: false
  - arguments:
    - description: The domain name (SLD.TLD) to Investigate. Supports up to 1,000 comma-separated domains.
      name: domain
      required: true
      default: true
      isArray: false
      secret: false
    - default: false
      description: Include the investigate results in Context Data. Defaults to true.
      isArray: false
      name: include_context
      required: false
      secret: false
      type: String
      predefined:
      - "true"
      - "false"
      auto: PREDEFINED
      defaultValue: "true"
    description: Returns a complete profile of the domain (SLD.TLD) using Iris Investigate. If parsing of FQDNs is desired, see domainExtractAndInvestigate.
    name: domaintoolsiris-investigate
    outputs:
    - contextPath: Domain.Name
      description: The name of the domain.
      type: String
    - contextPath: Domain.DNS
      description: The DNS of the domain.
      type: String
    - contextPath: Domain.DomainStatus
      description: The status of the domain.
      type: Boolean
    - contextPath: Domain.CreationDate
      description: The creation date.
      type: Date
    - contextPath: Domain.ExpirationDate
      description: The expiration date of the domain.
      type: Date
    - contextPath: Domain.NameServers
      description: The nameServers of the domain.
      type: String
    - contextPath: Domain.Registrant.Country
      description: The registrant country of the domain.
      type: String
    - contextPath: Domain.Registrant.Email
      description: The registrant email of the domain.
      type: String
    - contextPath: Domain.Registrant.Name
      description: The registrant name of the domain.
      type: String
    - contextPath: Domain.Registrant.Phone
      description: The registrant phone number of the domain.
      type: String
    - contextPath: Domain.Malicious.Vendor
      description: The vendor who classified the domain as malicious.
      type: String
    - contextPath: Domain.Malicious.Description
      description: The description as to why the domain was found to be malicious.
      type: String
    - contextPath: DomainTools.Name
      description: The domain name in DomainTools.
      type: String
    - contextPath: DomainTools.LastEnriched
      description: The last Time DomainTools enriched domain data.
      type: Date
    - contextPath: DomainTools.Analytics.OverallRiskScore
      description: The Overall Risk Score in DomainTools.
      type: Number
    - contextPath: DomainTools.Analytics.ProximityRiskScore
      description: The Proximity Risk Score in DomainTools.
      type: Number
    - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.RiskScore
      description: The Threat Profile Risk Score in DomainTools.
      type: Number
    - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.Threats
      description: The threats of the Threat Profile Risk Score in DomainTools.
      type: String
    - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.Evidence
      description: The Threat Profile Risk Score Evidence in DomainTools.
      type: String
    - contextPath: DomainTools.Analytics.WebsiteResponseCode
      description: The Website Response Code in DomainTools.
      type: Number
    - contextPath: DomainTools.Analytics.Tags
      description: The Tags in DomainTools.
      type: String
    - contextPath: DomainTools.Identity.RegistrantName
      description: The name of the registrant.
      type: String
    - contextPath: DomainTools.Identity.RegistrantOrg
      description: The organization of the registrant.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Country.value
      description: The country value of the registrant contact.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Country.count
      description: The count of the registrant contact country.
      type: Number
    - contextPath: DomainTools.Identity.RegistrantContact.Email.value
      description: The Email value of the registrant contact.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Email.count
      description: The Email count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Identity.RegistrantContact.Name.value
      description: The name value of the registrant contact.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Name.count
      description: The name count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Identity.RegistrantContact.Phone.value
      description: The phone value of the registrant contact.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Phone.count
      description: The phone count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Identity.SOAEmail
      description: The SOA record of the Email.
      type: String
    - contextPath: DomainTools.Identity.SSLCertificateEmail
      description: The Email of the SSL certificate.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Country.value
      description: The country value of the administrator contact.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Country.count
      description: The country count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Identity.AdminContact.Email.value
      description: The Email value of the administrator contact.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Email.count
      description: The Email count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Identity.AdminContact.Name.value
      description: The name value of the administrator contact.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Name.count
      description: The name count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Identity.AdminContact.Phone.value
      description: The phone value of the administrator contact.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Phone.count
      description: The phone count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Identity.TechnicalContact.Country.value
      description: The country value of the technical contact.
      type: String
    - contextPath: DomainTools.Identity.TechnicalContact.Country.count
      description: The country count of the technical contact.
      type: Number
    - contextPath: DomainTools.Identity.TechnicalContact.Email.value
      description: The Email value of the technical contact.
      type: String
    - contextPath: DomainTools.Identity.TechnicalContact.Email.count
      description: The Email count of the technical contact.
      type: Number
    - contextPath: DomainTools.Identity.TechnicalContact.Name.value
      description: The name value of the technical Contact.
      type: String
    - contextPath: DomainTools.Identity.TechnicalContact.Name.count
      description: The name count of the technical contact.
      type: Number
    - contextPath: DomainTools.Identity.TechnicalContact.Phone.value
      description: The phone value of the technical contact.
      type: String
    - contextPath: DomainTools.Identity.TechnicalContact.Phone.count
      description: The phone count of the technical contact.
      type: Number
    - contextPath: DomainTools.Identity.BillingContact.Country.value
      description: The country value of the billing contact.
      type: String
    - contextPath: DomainTools.Identity.BillingContact.Country.count
      description: The country count of the billing contact.
      type: Number
    - contextPath: DomainTools.Identity.BillingContact.Email.value
      description: The Email value of the billing contact.
      type: String
    - contextPath: DomainTools.Identity.BillingContact.Email.count
      description: The Email count of the billing contact.
      type: Number
    - contextPath: DomainTools.Identity.BillingContact.Name.value
      description: The name value of the billing contact.
      type: String
    - contextPath: DomainTools.Identity.BillingContact.Name.count
      description: The name count of the billing contact.
      type: Number
    - contextPath: DomainTools.Identity.BillingContact.Phone.value
      description: The phone value of the billing contact.
      type: String
    - contextPath: DomainTools.Identity.BillingContact.Phone.count
      description: The phone count of the billing contact.
      type: Number
    - contextPath: DomainTools.Identity.EmailDomains
      description: The Email Domains.
      type: String
    - contextPath: DomainTools.Identity.AdditionalWhoisEmails.value
      description: The value of the Additional Whois Emails record.
      type: String
    - contextPath: DomainTools.Identity.AdditionalWhoisEmails.count
      description: The count of the Additional Whois Emails record.
      type: Number
    - contextPath: DomainTools.Registration.DomainRegistrant
      description: The registrant of the domain.
      type: String
    - contextPath: DomainTools.Registration.RegistrarStatus
      description: The status of the registrar.
      type: String
    - contextPath: DomainTools.Registration.DomainStatus
      description: The active status of the domain.
      type: Boolean
    - contextPath: DomainTools.Registration.CreateDate
      description: The date the domain was created.
      type: Date
    - contextPath: DomainTools.Registration.ExpirationDate
      description: The expiration date of the domain.
      type: Date
    - contextPath: DomainTools.Hosting.IPAddresses.address.value
      description: The address value of IP addresses.
      type: String
    - contextPath: DomainTools.Hosting.IPAddresses.address.count
      description: The address count of IP addresses.
      type: Number
    - contextPath: DomainTools.Hosting.IPAddresses.asn.value
      description: The ASN value of IP addresses.
      type: String
    - contextPath: DomainTools.Hosting.IPAddresses.asn.count
      description: The ASN count of IP addresses.
      type: Number
    - contextPath: DomainTools.Hosting.IPAddresses.country_code.value
      description: The country code value of IP addresses.
      type: String
    - contextPath: DomainTools.Hosting.IPAddresses.country_code.count
      description: The country code count of IP addresses.
      type: Number
    - contextPath: DomainTools.Hosting.IPAddresses.isp.value
      description: The ISP value of IP addresses.
      type: String
    - contextPath: DomainTools.Hosting.IPAddresses.isp.count
      description: The ISP count of IP addresses.
      type: Number
    - contextPath: DomainTools.Hosting.IPCountryCode
      description: The country code of the IP address.
      type: String
    - contextPath: DomainTools.Hosting.MailServers.domain.value
      description: The domain value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Hosting.MailServers.domain.count
      description: The domain count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Hosting.MailServers.host.value
      description: The host value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Hosting.MailServers.host.count
      description: The host count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Hosting.MailServers.ip.value
      description: The IP value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Hosting.MailServers.ip.count
      description: The IP count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Hosting.SPFRecord
      description: The SPF Record.
      type: String
    - contextPath: DomainTools.Hosting.NameServers.domain.value
      description: The domain value of the domain NameServers.
      type: String
    - contextPath: DomainTools.Hosting.NameServers.domain.count
      description: The domain count of the domain NameServers.
      type: Number
    - contextPath: DomainTools.Hosting.NameServers.host.value
      description: The host value of the domain NameServers.
      type: String
    - contextPath: DomainTools.Hosting.NameServers.host.count
      description: The host count of the domain NameServers.
      type: Number
    - contextPath: DomainTools.Hosting.NameServers.ip.value
      description: The IP value of the domain NameServers.
      type: String
    - contextPath: DomainTools.Hosting.NameServers.ip.count
      description: The IP count of domain NameServers.
      type: Number
    - contextPath: DomainTools.Hosting.SSLCertificate.hash.value
      description: The hash value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Hosting.SSLCertificate.hash.count
      description: The hash count of the SSL certificate.
      type: Number
    - contextPath: DomainTools.Hosting.SSLCertificate.organization.value
      description: The organization value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Hosting.SSLCertificate.organization.count
      description: The organization count of the SSL certificate information.
      type: Number
    - contextPath: DomainTools.Hosting.SSLCertificate.subject.value
      description: The subject value of the SSL certificate information.
      type: String
    - contextPath: DomainTools.Hosting.SSLCertificate.subject.count
      description: The subject count of the SSL certificate information.
      type: Number
    - contextPath: DomainTools.Hosting.RedirectsTo.value
      description: The Redirects To Value of the domain.
      type: String
    - contextPath: DomainTools.Hosting.RedirectsTo.count
      description: The Redirects To Count of the domain.
      type: Number
    - contextPath: DomainTools.Analytics.GoogleAdsenseTrackingCode
      description: The tracking code of Google Adsense.
      type: Number
    - contextPath: DomainTools.Analytics.GoogleAnalyticTrackingCode
      description: The tracking code of Google Analytics.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.GA4TrackingCode
      description: The tracking code of ga4.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.GTMTrackingCode
      description: The tracking code of gtm.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.FBTrackingCode
      description: The tracking code of fb.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.HotJarTrackingCode
      description: The tracking code of Hot Jar.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.BaiduTrackingCode
      description: The tracking code of Baidu.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.YandexTrackingCode
      description: The tracking code of Yandex.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.MatomoTrackingCode
      description: The tracking code of Matomo.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.StatcounterProjectTrackingCode
      description: The tracking code of Stat Counter Project.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode
      description: The tracking code of Stat Counter Security.
      type: Number
    - contextPath: DomainTools.WebsiteTitle
      description: The website title.
      type: Number
    - contextPath: DomainTools.FirstSeen
      description: The date the domain was first seen.
      type: Number
    - contextPath: DomainTools.ServerType
      description: The server type.
      type: Number
    - contextPath: DBotScore.Indicator
      description: The indicator of the DBotScore.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type of the DBotScore.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    deprecated: false
    execution: false
  - arguments:
    - default: true
      description: The domain name (SLD.TLD), or a comma-separated list of up to 6,000 domains.
      name: domain
      required: true
      isArray: false
      secret: false
    - description: Include the investigate results in Context Data. Defaults to true.
      name: include_context
      default: false
      isArray: false
      required: false
      secret: false
      type: String
      predefined:
      - "true"
      - "false"
      auto: PREDEFINED
      defaultValue: "true"
    description: Returns a complete profile of the domain (SLD.TLD) using Iris Enrich. If parsing of URLs or FQDNs is desired, see domainExtractAndEnrich.
    name: domaintoolsiris-enrich
    outputs:
    - contextPath: Domain.Name
      description: The name of the domain.
      type: String
    - contextPath: Domain.DNS
      description: The DNS of the domain.
      type: String
    - contextPath: Domain.DomainStatus
      description: The status of the domain.
      type: Boolean
    - contextPath: Domain.CreationDate
      description: The creation date.
      type: Date
    - contextPath: Domain.ExpirationDate
      description: The expiration date of the domain.
      type: Date
    - contextPath: Domain.NameServers
      description: The nameServers of the domain.
      type: String
    - contextPath: Domain.Registrant.Country
      description: The registrant country of the domain.
      type: String
    - contextPath: Domain.Registrant.Email
      description: The registrant email of the domain.
      type: String
    - contextPath: Domain.Registrant.Name
      description: The registrant name of the domain.
      type: String
    - contextPath: Domain.Registrant.Phone
      description: The registrant phone number of the domain.
      type: String
    - contextPath: Domain.Malicious.Vendor
      description: The vendor who classified the domain as malicious.
      type: String
    - contextPath: Domain.Malicious.Description
      description: The description as to why the domain was found to be malicious.
      type: String
    - contextPath: DomainTools.Name
      description: The domain name in DomainTools.
      type: String
    - contextPath: DomainTools.LastEnriched
      description: The last Time DomainTools enriched domain data.
      type: Date
    - contextPath: DomainTools.Analytics.OverallRiskScore
      description: The Overall Risk Score in DomainTools.
      type: Number
    - contextPath: DomainTools.Analytics.ProximityRiskScore
      description: The Proximity Risk Score in DomainTools.
      type: Number
    - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.RiskScore
      description: The Threat Profile Risk Score in DomainTools.
      type: Number
    - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.Threats
      description: The threats of the Threat Profile Risk Score in DomainTools.
      type: String
    - contextPath: DomainTools.Analytics.ThreatProfileRiskScore.Evidence
      description: The Threat Profile Risk Score Evidence in DomainTools.
      type: String
    - contextPath: DomainTools.Analytics.WebsiteResponseCode
      description: The Website Response Code in DomainTools.
      type: Number
    - contextPath: DomainTools.Analytics.Tags
      description: The Tags in DomainTools.
      type: String
    - contextPath: DomainTools.Identity.RegistrantName
      description: The name of the registrant.
      type: String
    - contextPath: DomainTools.Identity.RegistrantOrg
      description: The organization of the registrant.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Country.value
      description: The country value of the registrant contact.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Country.count
      description: The count of the registrant contact country.
      type: Number
    - contextPath: DomainTools.Identity.RegistrantContact.Email.value
      description: The Email value of the registrant contact.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Email.count
      description: The Email count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Identity.RegistrantContact.Name.value
      description: The name value of the registrant contact.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Name.count
      description: The name count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Identity.RegistrantContact.Phone.value
      description: The phone value of the registrant contact.
      type: String
    - contextPath: DomainTools.Identity.RegistrantContact.Phone.count
      description: The phone count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Identity.SOAEmail
      description: The SOA record of the Email.
      type: String
    - contextPath: DomainTools.Identity.SSLCertificateEmail
      description: The Email of the SSL certificate.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Country.value
      description: The country value of the administrator contact.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Country.count
      description: The country count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Identity.AdminContact.Email.value
      description: The Email value of the administrator contact.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Email.count
      description: The Email count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Identity.AdminContact.Name.value
      description: The name value of the administrator contact.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Name.count
      description: The name count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Identity.AdminContact.Phone.value
      description: The phone value of the administrator contact.
      type: String
    - contextPath: DomainTools.Identity.AdminContact.Phone.count
      description: The phone count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Identity.TechnicalContact.Country.value
      description: The country value of the technical contact.
      type: String
    - contextPath: DomainTools.Identity.TechnicalContact.Country.count
      description: The country count of the technical contact.
      type: Number
    - contextPath: DomainTools.Identity.TechnicalContact.Email.value
      description: The Email value of the technical contact.
      type: String
    - contextPath: DomainTools.Identity.TechnicalContact.Email.count
      description: The Email count of the technical contact.
      type: Number
    - contextPath: DomainTools.Identity.TechnicalContact.Name.value
      description: The name value of the technical Contact.
      type: String
    - contextPath: DomainTools.Identity.TechnicalContact.Name.count
      description: The name count of the technical contact.
      type: Number
    - contextPath: DomainTools.Identity.TechnicalContact.Phone.value
      description: The phone value of the technical contact.
      type: String
    - contextPath: DomainTools.Identity.TechnicalContact.Phone.count
      description: The phone count of the technical contact.
      type: Number
    - contextPath: DomainTools.Identity.BillingContact.Country.value
      description: The country value of the billing contact.
      type: String
    - contextPath: DomainTools.Identity.BillingContact.Country.count
      description: The country count of the billing contact.
      type: Number
    - contextPath: DomainTools.Identity.BillingContact.Email.value
      description: The Email value of the billing contact.
      type: String
    - contextPath: DomainTools.Identity.BillingContact.Email.count
      description: The Email count of the billing contact.
      type: Number
    - contextPath: DomainTools.Identity.BillingContact.Name.value
      description: The name value of the billing contact.
      type: String
    - contextPath: DomainTools.Identity.BillingContact.Name.count
      description: The name count of the billing contact.
      type: Number
    - contextPath: DomainTools.Identity.BillingContact.Phone.value
      description: The phone value of the billing contact.
      type: String
    - contextPath: DomainTools.Identity.BillingContact.Phone.count
      description: The phone count of the billing contact.
      type: Number
    - contextPath: DomainTools.Identity.EmailDomains
      description: The Email Domains.
      type: String
    - contextPath: DomainTools.Identity.AdditionalWhoisEmails.value
      description: The value of the Additional Whois Emails record.
      type: String
    - contextPath: DomainTools.Identity.AdditionalWhoisEmails.count
      description: The count of the Additional Whois Emails record.
      type: Number
    - contextPath: DomainTools.Registration.DomainRegistrant
      description: The registrant of the domain.
      type: String
    - contextPath: DomainTools.Registration.RegistrarStatus
      description: The status of the registrar.
      type: String
    - contextPath: DomainTools.Registration.DomainStatus
      description: The active status of the domain.
      type: Boolean
    - contextPath: DomainTools.Registration.CreateDate
      description: The date the domain was created.
      type: Date
    - contextPath: DomainTools.Registration.ExpirationDate
      description: The expiration date of the domain.
      type: Date
    - contextPath: DomainTools.Hosting.IPAddresses.address.value
      description: The address value of IP addresses.
      type: String
    - contextPath: DomainTools.Hosting.IPAddresses.address.count
      description: The address count of IP addresses.
      type: Number
    - contextPath: DomainTools.Hosting.IPAddresses.asn.value
      description: The ASN value of IP addresses.
      type: String
    - contextPath: DomainTools.Hosting.IPAddresses.asn.count
      description: The ASN count of IP addresses.
      type: Number
    - contextPath: DomainTools.Hosting.IPAddresses.country_code.value
      description: The country code value of IP addresses.
      type: String
    - contextPath: DomainTools.Hosting.IPAddresses.country_code.count
      description: The country code count of IP addresses.
      type: Number
    - contextPath: DomainTools.Hosting.IPAddresses.isp.value
      description: The ISP value of IP addresses.
      type: String
    - contextPath: DomainTools.Hosting.IPAddresses.isp.count
      description: The ISP count of IP addresses.
      type: Number
    - contextPath: DomainTools.Hosting.IPCountryCode
      description: The country code of the IP address.
      type: String
    - contextPath: DomainTools.Hosting.MailServers.domain.value
      description: The domain value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Hosting.MailServers.domain.count
      description: The domain count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Hosting.MailServers.host.value
      description: The host value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Hosting.MailServers.host.count
      description: The host count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Hosting.MailServers.ip.value
      description: The IP value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Hosting.MailServers.ip.count
      description: The IP count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Hosting.SPFRecord
      description: The SPF Record.
      type: String
    - contextPath: DomainTools.Hosting.NameServers.domain.value
      description: The domain value of the domain NameServers.
      type: String
    - contextPath: DomainTools.Hosting.NameServers.domain.count
      description: The domain count of the domain NameServers.
      type: Number
    - contextPath: DomainTools.Hosting.NameServers.host.value
      description: The host value of the domain NameServers.
      type: String
    - contextPath: DomainTools.Hosting.NameServers.host.count
      description: The host count of the domain NameServers.
      type: Number
    - contextPath: DomainTools.Hosting.NameServers.ip.value
      description: The IP value of the domain NameServers.
      type: String
    - contextPath: DomainTools.Hosting.NameServers.ip.count
      description: The IP count of domain NameServers.
      type: Number
    - contextPath: DomainTools.Hosting.SSLCertificate.hash.value
      description: The hash value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Hosting.SSLCertificate.hash.count
      description: The hash count of the SSL certificate.
      type: Number
    - contextPath: DomainTools.Hosting.SSLCertificate.organization.value
      description: The organization value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Hosting.SSLCertificate.organization.count
      description: The organization count of the SSL certificate information.
      type: Number
    - contextPath: DomainTools.Hosting.SSLCertificate.subject.value
      description: The subject value of the SSL certificate information.
      type: String
    - contextPath: DomainTools.Hosting.SSLCertificate.subject.count
      description: The subject count of the SSL certificate information.
      type: Number
    - contextPath: DomainTools.Hosting.RedirectsTo.value
      description: The Redirects To Value of the domain.
      type: String
    - contextPath: DomainTools.Hosting.RedirectsTo.count
      description: The Redirects To Count of the domain.
      type: Number
    - contextPath: DomainTools.Analytics.GoogleAdsenseTrackingCode
      description: The tracking code of Google Adsense.
      type: Number
    - contextPath: DomainTools.Analytics.GoogleAnalyticTrackingCode
      description: The tracking code of Google Analytics.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.GA4TrackingCode
      description: The tracking code of ga4.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.GTMTrackingCode
      description: The tracking code of gtm.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.FBTrackingCode
      description: The tracking code of fb.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.HotJarTrackingCode
      description: The tracking code of Hot Jar.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.BaiduTrackingCode
      description: The tracking code of Baidu.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.YandexTrackingCode
      description: The tracking code of Yandex.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.MatomoTrackingCode
      description: The tracking code of Matomo.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.StatcounterProjectTrackingCode
      description: The tracking code of Stat Counter Project.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode
      description: The tracking code of Stat Counter Security.
      type: Number
    - contextPath: DomainTools.WebsiteTitle
      description: The website title.
      type: Number
    - contextPath: DomainTools.FirstSeen
      description: The date the domain was first seen.
      type: Number
    - contextPath: DomainTools.ServerType
      description: The server type.
      type: Number
    - contextPath: DBotScore.Indicator
      description: The indicator of the DBotScore.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type of the DBotScore.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    deprecated: false
    execution: false
  - arguments:
    - default: false
      description: The domain name to display.
      name: domain
      isArray: false
      required: true
      secret: false
    - description: Include the enrich results in Context Data. Defaults to true.
      name: include_context
      default: true
      isArray: false
      required: false
      secret: false
      type: String
      predefined:
      - "true"
      - "false"
      auto: PREDEFINED
      defaultValue: "true"
    description: Displays DomainTools Analytic data in a markdown format table.
    name: domaintoolsiris-analytics
    outputs:
    - contextPath: Domain.Name
      description: The name of the domain.
      type: String
    - contextPath: Domain.DNS
      description: The DNS of the domain.
      type: String
    - contextPath: Domain.DomainStatus
      description: The status of the domain.
      type: Boolean
    - contextPath: Domain.CreationDate
      description: The creation date of the domain.
      type: Date
    - contextPath: Domain.ExpirationDate
      description: The expiration date of the domain.
      type: Date
    - contextPath: Domain.NameServers
      description: The NameServers of the domain.
      type: String
    - contextPath: Domain.Registrant.Country
      description: The registrant country of the domain.
      type: String
    - contextPath: Domain.Registrant.Email
      description: The registrant Email of the domain.
      type: String
    - contextPath: Domain.Registrant.Name
      description: The registrant name of the domain.
      type: String
    - contextPath: Domain.Registrant.Phone
      description: The registrant phone number of the domain.
      type: String
    - contextPath: Domain.Malicious.Vendor
      description: The vendor that classified the domain as malicious.
      type: String
    - contextPath: Domain.Malicious.Description
      description: The description as to why the domain was found malicious.
      type: String
    - contextPath: DomainTools.Domains.Name
      description: The domain name in DomainTools.
      type: String
    - contextPath: DomainTools.Domains.LastEnriched
      description: The last Time DomainTools enriched domain data.
      type: Date
    - contextPath: DomainTools.Domains.Analytics.OverallRiskScore
      description: The DomainTools Overall Risk Score.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.ProximityRiskScore
      description: The DomainTools Proximity Risk Score.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScore
      description: The DomainTools Threat Profile Risk Score.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.ThreatProfileRiskScore.Threats
      description: The DomainTools Threat Profile Threats.
      type: String
    - contextPath: DomainTools.Domains.Analytics.ThreatProfileRiskScore.Evidence
      description: The DomainTools Threat Profile Evidence.
      type: String
    - contextPath: DomainTools.Domains.Analytics.WebsiteResponseCode
      description: The Website Response Code.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.Tags
      description: The tags in DomainTools.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantName
      description: The name of the registrant.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantOrg
      description: The organization of the registrant.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Country.value
      description: The country value of the registrant contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Country.count
      description: The country count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Email.value
      description: The Email value of the registrant contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Email.count
      description: The Email count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Name.value
      description: The name value of the registrant contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Name.count
      description: The Name count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Phone.value
      description: The phone value of the registrant contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Phone.count
      description: The phone count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.SOAEmail
      description: The SOA record Email.
      type: String
    - contextPath: DomainTools.Domains.Identity.SSLCertificateEmail
      description: The email of the SSL certificate.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdminContact.Country.value
      description: The country value of the administrator contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdminContact.Country.count
      description: The country count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.AdminContact.Email.value
      description: The Email value of the administrator contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdminContact.Email.count
      description: The Email count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.AdminContact.Name.value
      description: The name value of the administrator contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdminContact.Name.count
      description: The name count of administrator contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.AdminContact.Phone.value
      description: The phone value of the administrator contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdminContact.Phone.count
      description: The phone count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Country.value
      description: The country value of the technical contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Country.count
      description: The country count of the technical contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Email.value
      description: The Email value of the technical contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Email.count
      description: The Email count of the technical contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Name.value
      description: The name value of the technical contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Name.count
      description: The name count of the technical contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Phone.value
      description: The phone value of the technical contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Phone.count
      description: The phone count of the technical contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.BillingContact.Country.value
      description: The country value of the billing contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.BillingContact.Country.count
      description: The country count of the billing contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.BillingContact.Email.value
      description: The email value of the billing contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.BillingContact.Email.count
      description: The email count of the billing contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.BillingContact.Name.value
      description: The name value of the billing contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.BillingContact.Name.count
      description: The name count of the billing contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.BillingContact.Phone.value
      description: The phone value of the billing contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.BillingContact.Phone.count
      description: The phone count of the billing contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.EmailDomains
      description: The domain of the Email.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdditionalWhoisEmails.value
      description: The value of the Additional Whois Emails.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdditionalWhoisEmails.count
      description: The count of the Additional Whois Emails.
      type: Number
    - contextPath: DomainTools.Domains.Registration.DomainRegistrant
      description: The registrant of the domain.
      type: String
    - contextPath: DomainTools.Domains.Registration.RegistrarStatus
      description: The status of the registrar.
      type: String
    - contextPath: DomainTools.Domains.Registration.DomainStatus
      description: The active status of the domain.
      type: Boolean
    - contextPath: DomainTools.Domains.Registration.CreateDate
      description: The date the domain was created.
      type: Date
    - contextPath: DomainTools.Domains.Registration.ExpirationDate
      description: The date the domain expires.
      type: Date
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.address.value
      description: The address values of the IP addresses.
      type: String
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.address.count
      description: The address counts of the IP addresses.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.asn.value
      description: The ASN values of the IP addresses.
      type: String
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.asn.count
      description: The ASN counts of the IP addresses.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.country_code.value
      description: The country code values of the IP addresses.
      type: String
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.country_code.count
      description: The country code counts of the IP addresses.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.isp.value
      description: IP Addresses Info isp value.
      type: String
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.isp.count
      description: IP Addresses Info isp count.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.IPCountryCode
      description: IP Country Code.
      type: String
    - contextPath: DomainTools.Domains.Hosting.MailServers.domain.value
      description: Mail Servers Info domain value.
      type: String
    - contextPath: DomainTools.Domains.Hosting.MailServers.domain.count
      description: Mail Servers Info domain count.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.MailServers.host.value
      description: Mail Servers Info host value.
      type: String
    - contextPath: DomainTools.Domains.Hosting.MailServers.host.count
      description: Mail Servers Info host count.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.MailServers.ip.value
      description: Mail Servers Info ip value.
      type: String
    - contextPath: DomainTools.Domains.Hosting.MailServers.ip.count
      description: Mail Servers Info ip count.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.SPFRecord
      description: The SPF record.
      type: String
    - contextPath: DomainTools.Domains.Hosting.NameServers.domain.value
      description: The domain value of the DomainTools Domains NameServers.
      type: String
    - contextPath: DomainTools.Domains.Hosting.NameServers.domain.count
      description: The domain count of the DomainTools Domains NameServers.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.NameServers.host.value
      description: The host value of the DomainTools Domains NameServers.
      type: String
    - contextPath: DomainTools.Domains.Hosting.NameServers.host.count
      description: The host count of the DomainTools Domains NameServers.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.NameServers.ip.value
      description: The IP value of the DomainTools Domains NameServers.
      type: String
    - contextPath: DomainTools.Domains.Hosting.NameServers.ip.count
      description: The IP count of the DomainTools Domains NameServers.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.SSLCertificate.hash.value
      description: The hash value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Domains.Hosting.SSLCertificate.hash.count
      description: The hash count of the SSL certificate.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.SSLCertificate.organization.value
      description: The organization value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Domains.Hosting.SSLCertificate.organization.count
      description: The organization count of the SSL certificate.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.SSLCertificate.subject.value
      description: The subject value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Domains.Hosting.SSLCertificate.subject.count
      description: The subject count of the SSL certificate.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.RedirectsTo.value
      description: The Redirects To value of the domain.
      type: String
    - contextPath: DomainTools.Domains.Hosting.RedirectsTo.count
      description: The Redirects To count of the domain.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.GoogleAdsenseTrackingCode
      description: The tracking code of Google Adsense.
      type: Number
    - contextPath: DomainTools.Analytics.GoogleAnalyticTrackingCode
      description: The tracking code of Google Analytics.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.GA4TrackingCode
      description: The tracking code of ga4.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.GTMTrackingCode
      description: The tracking code of gtm.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.FBTrackingCode
      description: The tracking code of fb.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.HotJarTrackingCode
      description: The tracking code of Hot Jar.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.BaiduTrackingCode
      description: The tracking code of Baidu.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.YandexTrackingCode
      description: The tracking code of Yandex.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.MatomoTrackingCode
      description: The tracking code of Matomo.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.StatcounterProjectTrackingCode
      description: The tracking code of Stat Counter Project.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode
      description: The tracking code of Stat Counter Security.
      type: Number
    - contextPath: DBotScore.Indicator
      description: The DBotScore indicator.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type of the DBotScore.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    deprecated: false
    execution: false
  - arguments:
    - default: false
      description: The domain name.
      isArray: false
      name: domain
      required: true
      secret: false
    deprecated: false
    description: Displays DomainTools Threat Profile data in a markdown format table.
    execution: false
    name: domaintoolsiris-threat-profile
    outputs:
    - contextPath: Domain.Name
      description: The name of the domain.
      type: String
    - contextPath: Domain.DNS
      description: The DNS of the domain.
      type: String
    - contextPath: Domain.DomainStatus
      description: The status of the domain.
      type: Boolean
    - contextPath: Domain.CreationDate
      description: The creation date of the domain.
      type: Date
    - contextPath: Domain.ExpirationDate
      description: The expiration date of the domain.
      type: Date
    - contextPath: Domain.NameServers
      description: The NameServers of the domain.
      type: String
    - contextPath: Domain.Registrant.Country
      description: The registrant country of the domain.
      type: String
    - contextPath: Domain.Registrant.Email
      description: The Email of the registrant domain.
      type: String
    - contextPath: Domain.Registrant.Name
      description: The registrant name of the domain.
      type: String
    - contextPath: Domain.Registrant.Phone
      description: The phone value of the registrant domain.
      type: String
    - contextPath: Domain.Malicious.Vendor
      description: Vendor that classified the domain as malicious.
      type: String
    - contextPath: Domain.Malicious.Description
      description: The  description as to why the domain was found to be malicious.
      type: String
    - contextPath: DomainTools.Domains.Name
      description: The DomainTools domain name.
      type: String
    - contextPath: DomainTools.Domains.LastEnriched
      description: The last time DomainTools enriched the domain data.
      type: Date
    - contextPath: DomainTools.Domains.Analytics.OverallRiskScore
      description: The DomainTools Overall Risk Score.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.ProximityRiskScore
      description: The DomainTools Proximity Risk Score.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScore
      description: The DomainTools Threat Profile Risk Score.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.ThreatProfileRiskScore.Threats
      description: The DomainTools Threat Profile Threats.
      type: String
    - contextPath: DomainTools.Domains.Analytics.ThreatProfileRiskScore.Evidence
      description: The DomainTools Threat Profile Evidence.
      type: String
    - contextPath: DomainTools.Domains.Analytics.WebsiteResponseCode
      description: The response code of the Website.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.Tags
      description: The DomainTools Tags.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantName
      description: The name of the registrant.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantOrg
      description: The organization of the registrant.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Country.value
      description: The country value of the registrant contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Country.count
      description: The county count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Email.value
      description: The Email value of the registrant contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Email.count
      description: The Email count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Name.value
      description: The name value of the registrant contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Name.count
      description: The name count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Phone.value
      description: The phone value of the registrant contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.RegistrantContact.Phone.count
      description: The phone count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.SOAEmail
      description: The SOA record Email.
      type: String
    - contextPath: DomainTools.Domains.Identity.SSLCertificateEmail
      description: The SSL certificate Email.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdminContact.Country.value
      description: The country value of the administrator contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdminContact.Country.count
      description: The country count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.AdminContact.Email.value
      description: The Email value of the administrator contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdminContact.Email.count
      description: The Email count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.AdminContact.Name.value
      description: The name value of the administrator contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdminContact.Name.count
      description: The name count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.AdminContact.Phone.value
      description: The phone value of the administrator contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdminContact.Phone.count
      description: The phone count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Country.value
      description: The country value of the technical contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Country.count
      description: The country count of the technical contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Email.value
      description: The Email value of the technical contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Email.count
      description: The Email count of the technical contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Name.value
      description: The name value of the technical contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Name.count
      description: The name count of the technical contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Phone.value
      description: The phone value of the technical contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.TechnicalContact.Phone.count
      description: The phone count of the technical contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.BillingContact.Country.value
      description: The country value of the billing contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.BillingContact.Country.count
      description: The country count of the billing contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.BillingContact.Email.value
      description: The Email value of the billing contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.BillingContact.Email.count
      description: The Email count of the billing contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.BillingContact.Name.value
      description: The name value of the billing contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.BillingContact.Name.count
      description: The name count of the billing contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.BillingContact.Phone.value
      description: The phone value of the billing contact.
      type: String
    - contextPath: DomainTools.Domains.Identity.BillingContact.Phone.count
      description: The phone count of the billing contact.
      type: Number
    - contextPath: DomainTools.Domains.Identity.EmailDomains
      description: The Email domains.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdditionalWhoisEmails.value
      description: The value of the Additional Whois Emails.
      type: String
    - contextPath: DomainTools.Domains.Identity.AdditionalWhoisEmails.count
      description: The count of the Additional Whois Emails.
      type: Number
    - contextPath: DomainTools.Domains.Registration.DomainRegistrant
      description: The registrant of the domain.
      type: String
    - contextPath: DomainTools.Domains.Registration.RegistrarStatus
      description: The status of the registrar.
      type: String
    - contextPath: DomainTools.Domains.Registration.DomainStatus
      description: The active status of the domain.
      type: Boolean
    - contextPath: DomainTools.Domains.Registration.CreateDate
      description: The date the domain was created.
      type: Date
    - contextPath: DomainTools.Domains.Registration.ExpirationDate
      description: The expiry date of the domain.
      type: Date
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.address.value
      description: The address value of the IP Addresses.
      type: String
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.address.count
      description: The address count of the IP Addresses.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.asn.value
      description: The ASN value of the IP Addresses.
      type: String
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.asn.count
      description: The ASN count of the IP Addresses.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.country_code.value
      description: The country code of the IP Addresses.
      type: String
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.country_code.count
      description: The country code count of the IP Addresses.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.isp.value
      description: ISP value of the IP Addresses.
      type: String
    - contextPath: DomainTools.Domains.Hosting.IPAddresses.isp.count
      description: The ISP count of the IP Addresses.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.IPCountryCode
      description: The country code of the IP address.
      type: String
    - contextPath: DomainTools.Domains.Hosting.MailServers.domain.value
      description: The domain value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Domains.Hosting.MailServers.domain.count
      description: The domain count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.MailServers.host.value
      description: The host value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Domains.Hosting.MailServers.host.count
      description: The host count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.MailServers.ip.value
      description: The IP value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Domains.Hosting.MailServers.ip.count
      description: The IP count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.SPFRecord
      description: The SPF Record.
      type: String
    - contextPath: DomainTools.Domains.Hosting.NameServers.domain.value
      description: The domain value of the DomainTools Domains NameServers.
      type: String
    - contextPath: DomainTools.Domains.Hosting.NameServers.domain.count
      description: The domain count of the DomainTools Domains NameServers.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.NameServers.host.value
      description: The host value of the DomainTools Domains NameServers.
      type: String
    - contextPath: DomainTools.Domains.Hosting.NameServers.host.count
      description: The host count of the DomainTools Domains NameServers.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.NameServers.ip.value
      description: The IP value of the DomainTools Domains NameServers.
      type: String
    - contextPath: DomainTools.Domains.Hosting.NameServers.ip.count
      description: The IP count of the DomainTools Domains NameServers.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.SSLCertificate.hash.value
      description: The hash value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Domains.Hosting.SSLCertificate.hash.count
      description: The hash count of the SSL certificate.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.SSLCertificate.organization.value
      description: The organization value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Domains.Hosting.SSLCertificate.organization.count
      description: The organization count of the SSL certificate.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.SSLCertificate.subject.value
      description: The subject value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Domains.Hosting.SSLCertificate.subject.count
      description: The subject count of the SSL certificate.
      type: Number
    - contextPath: DomainTools.Domains.Hosting.RedirectsTo.value
      description: The Redirects To value of the domain.
      type: String
    - contextPath: DomainTools.Domains.Hosting.RedirectsTo.count
      description: The Redirects To count of the domain.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.GoogleAdsenseTrackingCode
      description: The tracking code of Google Adsense.
      type: Number
    - contextPath: DomainTools.Analytics.GoogleAnalyticTrackingCode
      description: The tracking code of Google Analytics.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.GA4TrackingCode
      description: The tracking code of ga4.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.GTMTrackingCode
      description: The tracking code of gtm.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.FBTrackingCode
      description: The tracking code of fb.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.HotJarTrackingCode
      description: The tracking code of Hot Jar.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.BaiduTrackingCode
      description: The tracking code of Baidu.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.YandexTrackingCode
      description: The tracking code of Yandex.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.MatomoTrackingCode
      description: The tracking code of Matomo.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.StatcounterProjectTrackingCode
      description: The tracking code of Stat Counter Project.
      type: Number
    - contextPath: DomainTools.Domains.Analytics.StatcounterSecurityTrackingCode
      description: The tracking code of Stat Counter Security.
      type: Number
    - contextPath: DBotScore.Indicator
      description: The DBotScore indicator.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type of the DBotScore.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
  - arguments:
    - default: false
      description: The IP Address.
      isArray: false
      name: ip
      required: false
      secret: false
    - default: false
      description: "The Email Address."
      isArray: false
      name: email
      required: false
      secret: false
    - default: false
      description: "The Name Server IP Address."
      isArray: false
      name: nameserver_ip
      required: false
      secret: false
    - default: false
      description: "The hash of the SSL."
      isArray: false
      name: ssl_hash
      required: false
      secret: false
    - default: false
      description: "The fully-qualified host name of the name server. For example, ns1.domaintools.net."
      isArray: false
      name: nameserver_host
      required: false
      secret: false
    - default: false
      description: The fully-qualified host name of the mail server. For example, mx.domaintools.net.
      isArray: false
      name: mailserver_host
      required: false
      secret: false
    - default: false
      description: Only the domain portion of a Whois or DNS SOA email address.
      isArray: false
      name: email_domain
      required: false
      secret: false
    - default: false
      description: Registered domain portion of the name server.
      isArray: false
      name: nameserver_domain
      required: false
      secret: false
    - default: false
      description: Exact match to the Whois registrar field.
      isArray: false
      name: registrar
      required: false
      secret: false
    - default: false
      description: Exact match to the Whois registrant field.
      isArray: false
      name: registrant
      required: false
      secret: false
    - default: false
      description: Exact match to the Whois registrant organization field.
      isArray: false
      name: registrant_org
      required: false
      secret: false
    - default: false
      description: Comma-separated list of Iris Investigate tags. Returns domains tagged with any of the tags in a list.
      isArray: false
      name: tagged_with_any
      required: false
      secret: false
    - default: false
      description: Comma-separated list of tags. Only returns domains tagged with the full list of tags.
      isArray: false
      name: tagged_with_all
      required: false
      secret: false
    - default: false
      description: Only the registered domain portion of the mail server (domaintools.net).
      isArray: false
      name: mailserver_domain
      required: false
      secret: false
    - default: false
      description: IP address of the mail server.
      isArray: false
      name: mailserver_ip
      required: false
      secret: false
    - default: false
      description: Find domains observed to redirect to another domain name.
      isArray: false
      name: redirect_domain
      required: false
      secret: false
    - default: false
      description: Exact match to the organization name on the SSL certificate.
      isArray: false
      name: ssl_org
      required: false
      secret: false
    - default: false
      description: Subject field from the SSL certificate.
      isArray: false
      name: ssl_subject
      required: false
      secret: false
    - default: false
      description: Email address from the SSL certificate.
      isArray: false
      name: ssl_email
      required: false
      secret: false
    - default: false
      description: Domains with a Google Analytics tracking code.
      isArray: false
      name: google_analytics
      required: false
      secret: false
    - default: false
      description: Domains with a Google AdSense tracking code.
      isArray: false
      name: adsense
      required: false
      secret: false
    - default: false
      description: Encoded search from the Iris UI.
      isArray: false
      name: search_hash
      required: false
      secret: false
    - default: false
      description: Include the results of the pivot in Context Data. Defaults to true.
      isArray: false
      name: include_context
      required: false
      secret: false
      type: String
      predefined:
      - "true"
      - "false"
      auto: PREDEFINED
      defaultValue: "true"
    deprecated: false
    description: Pivot on connected infrastructure (IP, email, SSL), or import domains from Iris Investigate using a search hash. Retrieves up to 5000 domains at a time. Optionally exclude results from context with include_context=false.
    execution: false
    name: domaintoolsiris-pivot
    outputs:
    - contextPath: DomainTools.Pivots.PivotedDomains.Name
      description: The DomainTools Domain Name.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.LastEnriched
      description: The last time DomainTools enriched the domain data.
      type: Date
    - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.OverallRiskScore
      description: The DomainTools Overall Risk Score.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.ProximityRiskScore
      description: The DomainTools Proximity Risk Score.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.ThreatProfileRiskScore.RiskScore
      description: The DomainTools Threat Profile Risk Score.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.ThreatProfileRiskScore.Threats
      description: The DomainTools Threat Profile Threats.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.ThreatProfileRiskScore.Evidence
      description: The DomainTools Threat Profile Evidence.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.WebsiteResponseCode
      description: The response code of the website.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.Tags
      description: The DomainTools tags.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantName
      description: The name of the registrant.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantOrg
      description: The organization of the registrant.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Country.value
      description: The country value of the registrant contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Country.count
      description: The country count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Email.value
      description: The Email value of the registrant contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Email.count
      description: The Email count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Name.value
      description: The name value of the registrant contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Name.count
      description: The name count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Phone.value
      description: The phone value of of the registrant contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.RegistrantContact.Phone.count
      description: The phone count of the registrant contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.SOAEmail
      description: The SOA record Email.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.SSLCertificateEmail
      description: The SSL certificate Email.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Country.value
      description: The country value of the administrator contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Country.count
      description: The country count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Email.value
      description: The Email value of the administrator contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Email.count
      description: The Email count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Name.value
      description: The name value of the administrator contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Name.count
      description: The name count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Phone.value
      description: The phone value of the administrator contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdminContact.Phone.count
      description: The phone count of the administrator contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Country.value
      description: The country value of the technical contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Country.count
      description: The country count of the technical contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Email.value
      description: The Email value of the technical contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Email.count
      description: The Email count of the technical contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Name.value
      description: The name value of the technical contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Name.count
      description: The name count of the technical contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Phone.value
      description: The phone value of the technical contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.TechnicalContact.Phone.count
      description: The phone count of the technical contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Country.value
      description: The country value of the billing contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Country.count
      description: The country count of the billing contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Email.value
      description: The Email value of the billing contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Email.count
      description: The Email count of the billing contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Name.value
      description: The Name value of the billing contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Name.count
      description: The Name count of the billing contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Phone.value
      description: The phone value of the billing contact.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.BillingContact.Phone.count
      description: The phone count of the billing contact.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.EmailDomains
      description: The Email domains.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdditionalWhoisEmails.value
      description: The value of the Additional Whois Emails.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Identity.AdditionalWhoisEmails.count
      description: The count of the Additional Whois Emails.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Registration.DomainRegistrant
      description: The Registrant of the domain.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Registration.RegistrarStatus
      description: The status of the registrar.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Registration.DomainStatus
      description: The active status of the registrar.
      type: Boolean
    - contextPath: DomainTools.Pivots.PivotedDomains.Registration.CreateDate
      description: The date the domain was created.
      type: Date
    - contextPath: DomainTools.Pivots.PivotedDomains.Registration.ExpirationDate
      description: The Expiry date of the domain.
      type: Date
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.address.value
      description: The address value of IP addresses.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.address.count
      description: The address count of IP addresses.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.asn.value
      description: The ASN value of IP addresses.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.asn.count
      description: The ASN count of IP addresses.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.country_code.value
      description: The country code value of IP addresses.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.country_code.count
      description: The country code count of IP addresses.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.isp.value
      description: The ISP value of IP addresses.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPAddresses.isp.count
      description: The ISP count of IP addresses.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.IPCountryCode
      description: The country code of the IP address.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.MailServers.domain.value
      description: The domain value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.MailServers.domain.count
      description: The domain count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.MailServers.host.value
      description: The host value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.MailServers.host.count
      description: The host count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.MailServers.ip.value
      description: The IP address value of the Mail Servers.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.MailServers.ip.count
      description: The IP address count of the Mail Servers.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SPFRecord
      description: The SPF record Information.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.NameServers.domain.value
      description: The domain value of DomainTools Domains NameServers.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.NameServers.domain.count
      description: The domain count of DomainTools Domains NameServers.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.NameServers.host.value
      description: The host value of DomainTools Domains NameServers.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.NameServers.host.count
      description: The host count of DomainTools Domains NameServers.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.NameServers.ip.value
      description: The IP address value of DomainTools Domains NameServers.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.NameServers.ip.count
      description: The IP address count of DomainTools Domains NameServers.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.hash.value
      description: The hash value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.hash.count
      description: The hash count of the SSL certificate.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.organization.value
      description: The organization value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.organization.count
      description: The organization count of the SSL certificate.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.subject.value
      description: The subject value of the SSL certificate.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.SSLCertificate.subject.count
      description: The subject count of the SSL certificate.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.RedirectsTo.value
      description: The Redirects To value of the domain.
      type: String
    - contextPath: DomainTools.Pivots.PivotedDomains.Hosting.RedirectsTo.count
      description: The Redirects To count of the domain.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.GoogleAdsenseTrackingCode
      description: The tracking code of Google Adsense.
      type: Number
    - contextPath: DomainTools.Pivots.PivotedDomains.Analytics.GoogleAnalyticTrackingCode
      description: The tracking code Google Analytics.
      type: Number
  - arguments:
    - default: true
      description: A domain name to query (e.g. example.com).
      isArray: false
      name: domain
      required: true
      secret: false
    - default: false
      description: "options: list, count, check_existence. list: (default), return whois records. count: return how many total records are available. check_existence: return if any records exist. Default: list."
      isArray: false
      name: mode
      required: false
      secret: false
      type: String
      predefined:
      - "list"
      - "count"
      - "check_existence"
      auto: PREDEFINED
      defaultValue: "list"
    - default: false
      description: "numeric, the index from which to begin retrieving results. Default: 0."
      isArray: false
      name: offset
      required: false
      secret: false
      type: Number
      defaultValue: "0"
    - default: false
      description: "numeric, default: 100, max: 100, the total number of records to return. Default: 100."
      isArray: false
      name: limit
      required: false
      secret: false
      type: Number
      auto: PREDEFINED
      defaultValue: "100"
    - default: false
      description: "options: date_desc, date_asc. date_desc: (default), order records from newest to oldest. date_asc: sort order records from oldest to newest. Default: date_desc."
      isArray: false
      name: sort
      required: false
      secret: false
      auto: PREDEFINED
      defaultValue: "date_desc"
      predefined:
      - "date_desc"
      - "date_asc"
    deprecated: false
    description: The DomainTools Whois History API endpoint returns up to 100 historical Whois records associated with a domain name.
    execution: false
    name: domaintools-whois-history
    outputs:
    - contextPath: DomainTools.History.Value
      description: Name of domain.
    - contextPath: DomainTools.History.WhoisHistory
      description: Domain Whois history data.
  - arguments:
    - default: true
      description: A domain name to query (e.g. example.com).
      name: domain
      required: true
      isArray: false
      secret: false
    description: Hosting History will list IP address, name server and registrar history.
    name: domaintools-hosting-history
    outputs:
    - contextPath: DomainTools.History.Value
      description: Name of domain.
    - contextPath: DomainTools.History.IPHistory
      description: Domain IP history data.
    - contextPath: DomainTools.History.NameserverHistory
      description: Domain Nameserver history data.
    - contextPath: DomainTools.History.RegistrarHistory
      description: Domain Registrar history data.
    deprecated: false
    execution: false
  - arguments:
    - default: true
      description: (default) List of one or more terms to search for in the Whois record, separated with the pipe character ( | ).
      name: terms
      required: true
    - description: Domain names with Whois records that match these terms will be excluded from the result set. Separate multiple terms with the pipe character ( | ).
      name: exclude
    - auto: PREDEFINED
      defaultValue: "false"
      description: Show only historic records.
      name: onlyHistoricScope
      predefined:
      - "true"
      - "false"
    description: The DomainTools Reverse Whois API provides a list of domain names that share the same Registrant Information. You can enter terms that describe a domain owner, like an email address or a company name, and you’ll get a list of domain names that have your search terms listed in the Whois record.
    name: domaintools-reverse-whois
    outputs:
    - contextPath: DomainTools.ReverseWhois.Value
      description: Search term to reverse whois lookup on.
    - contextPath: DomainTools.ReverseWhois.Results
      description: List of results for reverse whois lookup.
  - name: domaintools-whois
    arguments:
    - default: true
      description: A domain name or IP address (e.g. example.com or 192.168.1.1).
      name: query
      required: true
    description: The DomainTools Parsed Whois API provides parsed information extracted from the raw Whois record. The API is optimized to quickly retrieve the Whois record, group important data together and return a well-structured format. The Parsed Whois API is ideal for anyone wishing to search for, index, or cross-reference data from one or multiple Whois records.
    outputs:
    - contextPath: Domain.Name
      description: Requested domain name.
    - contextPath: Domain.Whois
      description: Parsed Whois data.
    - contextPath: Domain.WhoisRecords
      description: Full Whois record.
  - name: reverseIP
    arguments:
    - default: true
      name: ip
      description: Specify the IP address to query.
    - name: domain
      description: If a domain name is provided, DomainTools will respond with the list of other domains that share the same IP.
    - name: limit
      description: Limits the size of the domain list than can appear in a response. The limit is applied per-IP address, not for the entire request.
      defaultValue: 50
    description: Reverse loopkup of an IP address or a domain.
    deprecated: false
    execution: false
    outputs:
    - contextPath: Domain.Name
      description: Domain name returned by the query.
    - contextPath: Domain.DNS.Address
      description: The IP address associated with the returned domains.
  - name: reverseNameServer
    arguments:
    - name: nameServer
      required: true
      description: Specify the name of the primary or secondary nameserver.
    - name: limit
      description: Limit the size of the domain list than can appear in a response.
      defaultValue: 50
    deprecated: false
    execution: false
    description: Reverse nameserver lookup.
    outputs:
    - contextPath: Domain.Name
      description: Name of the domain returned by the query.
  dockerimage: demisto/vendors-sdk:1.0.0.10120494
  runonce: false
  script: '-'
  type: python
  subtype: python3
  isfetch: true
  longRunning: false
  longRunningPort: false
tests:
- No test - test 'DomainTools Iris - Test' was moved to NonCircleFolder
fromversion: 5.0.0
sectionorder:
- Connect
- Collect