DomainTools Iris Investigate (v2.2.12)

Facilitates automation of key infrastructure characterization and hunting portions of the incident response process. Organizations will have access to essential domain profile, web crawl, SSL, and infrastructure data from within Cortex XSOAR. Requires a DomainTools Iris Investigate API key.

Author
DomainTools
Support
partner
URL
https://www.domaintools.com/support/
Categories
Data Enrichment & Threat Intelligence

Indicator fields (13)

Indicator types (1)

Integrations (1)

Layouts (2)

Playbooks (1)

Scripts (8)

README

Together, DomainTools and Cortex XSOAR automate and orchestrate the incident response processes with essential domain profile, web crawl, SSL, and infrastructure data delivered by the DomainTools Iris Investigate API. SOCs can create custom, automated workflows to trigger Indicator of Compromise (IoC) investigations, block threats based on connected infrastructure, and identify potentially malicious incidents before weaponization.

What does this pack do?

With the DomainTools Iris App for Cortex XSOAR, the Iris dataset is available not only for ad-hoc War-Room investigations on specific incidents, but also for automated actions. Organizations will be able to fetch a complete Iris profile for a domain name including:

This app requires an Iris Investigate API key. Please contact sales@domaintools.com for a trial.

For more information, visit DomainTools Iris App for Cortex XSOAR