FeedDomainTools
Real-Time Threat Intelligence Feeds provide data on the different stages of the domain lifecycle: from first-observed in the wild, to newly re-activated after a period of quiet. Newly Active Domains surfaces apex-level domains seen for the first time or after ten or more days of inactivity. Newly Observed Domains surfaces domains that we observe for the first time.
Data Enrichment & Threat Intelligence · DomainTools Feed · Feed
Details
| ID | FeedDomainTools |
|---|---|
| Provider | DomainTools |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.5.0 |
| Docker Image | demisto/vendors-sdk:1.0.0.10470199 |
| Supported Modules | Agentix XSIAM |
README
Real-Time Threat Intelligence Feeds provide data on the different stages of the domain lifecycle: from first-observed in the wild, to newly re-activated after a period of quiet. Newly Active Domains surfaces apex-level domains seen for the first time or after ten or more days of inactivity. Newly Observed Domains surfaces domains that we observe for the first time.
Configure FeedDomainTools in Cortex
| Parameter | Description | Required |
|---|---|---|
| API Username | API Username and API Key | True |
| API Key | True | |
| Session ID | The session id to serve as unique identifier. On it’s initial use, it will retrieve data from the past 5 days. Defaults to ‘dt-cortex-feeds’. | False |
| After | The start of the query window in seconds, relative to the current time, inclusive. Defaults to -3600. | False |
| Top | Limits the number of results in the response payload. Defaults to 5000. | False |
| Feed Type | The DomainTools feed type fo fetch. Defaults to ‘ALL’. | False |
| Fetch indicators | False | |
| Indicator Reputation | Indicators from this integration instance will be marked with this reputation. | False |
| Source Reliability | Reliability of the source providing the intelligence data. | True |
| False | ||
| False | ||
| Feed Fetch Interval | False | |
| Bypass exclusion list | When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. | False |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False | |
| Tags | Supports CSV values. | |
| Traffic Light Protocol Color | The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
domaintools-get-indicators
Gets indicators from the feed.
Base Command
domaintools-get-indicators
Input
| Argument Name | Description | Required |
|---|---|---|
| feed_type | The DomainTools integration feed type to fetch. Possible values are: nod, nad, noh, domainrdap, domaindiscovery, domainrisk, domainhotlist. Default is nod. | Optional |
| session_id | The session id to serve as unique indentifier. On it’s initial use, it will retrieve data from the past 5 days. Default is dt-cortex-feeds. | Optional |
| domain | The top level domain to query (e.g. *.com). |
Optional |
| after | The start of the query window in seconds, relative to the current time, inclusive. Defaults to 3600 seconds (1h). Default is -3600. | Optional |
| before | The end of the query window in seconds, relative to the current time, inclusive. | Optional |
| top | Limits the number of results in the response payload. Default is 50. | Optional |
Context Output
There is no context output for this command.
Configuration parameters
credentials— API Username (required)session_id— Session IDafter— Aftertop— Topfeed_type— Feed Typefeed— Fetch indicatorsfeedReputation— Indicator ReputationfeedReliability— Source Reliability (required)feedExpirationPolicy—feedExpirationInterval—feedFetchInterval— Feed Fetch IntervalfeedBypassExclusionList— Bypass exclusion listinsecure— Trust any certificate (not secure)proxy— Use system proxy settingsfeedTags— Tagstlp_color— Traffic Light Protocol Color
Commands (1)
-
domaintools-get-indicatorsGets indicators from the feed.
category: Data Enrichment & Threat Intelligence commonfields: id: FeedDomainTools version: -1 configuration: - additionalinfo: API Username and API Key display: API Username displaypassword: API Key name: credentials type: 9 required: true section: Connect - display: Session ID name: session_id defaultvalue: dt-cortex-feeds required: false hidden: false type: 0 section: Collect additionalinfo: The session id to serve as unique identifier. On it's initial use, it will retrieve data from the past 5 days. Defaults to 'dt-cortex-feeds'. - display: After name: after defaultvalue: "-3600" required: false hidden: false type: 0 section: Collect additionalinfo: The start of the query window in seconds, relative to the current time, inclusive. Defaults to -3600. - display: Top name: top defaultvalue: 5000 required: false hidden: false type: 0 additionalinfo: Limits the number of results in the response payload. Defaults to 5000. section: Collect - display: Feed Type name: feed_type defaultvalue: ALL required: false hidden: false type: 15 options: - ALL - nod - nad - noh - domainrdap - domaindiscovery - domainrisk - domainhotlist additionalinfo: The DomainTools feed type fo fetch. Defaults to 'ALL'. section: Collect - display: Fetch indicators name: feed defaultvalue: "true" type: 8 required: false section: Collect - display: Indicator Reputation name: feedReputation defaultvalue: feedInstanceReputationNotSet type: 18 required: false options: - None - Good - Suspicious - Bad additionalinfo: Indicators from this integration instance will be marked with this reputation. section: Collect - display: Source Reliability name: feedReliability defaultvalue: F - Reliability cannot be judged type: 15 required: true options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged additionalinfo: Reliability of the source providing the intelligence data. section: Collect - display: "" name: feedExpirationPolicy defaultvalue: indicatorType type: 17 required: false options: - never - interval - indicatorType - suddenDeath section: Collect - display: "" name: feedExpirationInterval defaultvalue: "20160" type: 1 required: false section: Collect - display: Feed Fetch Interval name: feedFetchInterval defaultvalue: "240" type: 19 required: false section: Collect - display: Bypass exclusion list name: feedBypassExclusionList defaultvalue: "true" type: 8 required: false section: Collect additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. - display: Trust any certificate (not secure) name: insecure required: false type: 8 section: Connect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - name: feedTags display: Tags type: 0 additionalinfo: Supports CSV values. section: Collect - name: tlp_color display: Traffic Light Protocol Color options: - RED - AMBER - GREEN - WHITE type: 15 additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed required: false section: Collect display: FeedDomainTools description: "Real-Time Threat Intelligence Feeds provide data on the different stages of the domain lifecycle: from first-observed in the wild, to newly re-activated after a period of quiet. Newly Active Domains surfaces apex-level domains seen for the first time or after ten or more days of inactivity. Newly Observed Domains surfaces domains that we observe for the first time." name: FeedDomainTools provider: DomainTools script: commands: - name: domaintools-get-indicators deprecated: false description: Gets indicators from the feed. execution: false arguments: - name: feed_type type: String auto: PREDEFINED predefined: - "nod" - "nad" - "noh" - "domainrdap" - "domaindiscovery" - "domainrisk" - "domainhotlist" defaultValue: "nod" description: The DomainTools integration feed type to fetch. isArray: false default: false required: false secret: false - name: session_id description: The session id to serve as unique indentifier. On it's initial use, it will retrieve data from the past 5 days. defaultValue: dt-cortex-feeds isArray: false default: false required: false secret: false - name: domain description: The top level domain to query (e.g. `*.com`). isArray: false default: false required: false secret: false - name: after description: The start of the query window in seconds, relative to the current time, inclusive. Defaults to 3600 seconds (1h). defaultValue: "-3600" isArray: false default: false required: false secret: false - name: before description: The end of the query window in seconds, relative to the current time, inclusive. isArray: false default: false required: false secret: false - name: top description: Limits the number of results in the response payload. defaultValue: 50 isArray: false default: false required: false secret: false dockerimage: demisto/vendors-sdk:1.0.0.10470199 feed: true isfetch: false longRunning: false longRunningPort: false runonce: false script: '-' subtype: python3 type: python fromversion: 5.5.0 sectionorder: - Connect - Collect marketplaces: - xsoar - marketplacev2 - platform tests: - No tests (auto formatted)