Darkmon - Enrich Domain
Sub-playbook that calls the Darkmon !domain command and returns DBotScore + Common.Domain for the input Domain indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.
- Pack
- Darkmon
- Tasks
- 5
Inputs
- Domain — The Domain indicator value to enrich. Defaults to ${Domain.Name}.
Outputs
- DBotScore.Indicator — The indicator value.
- DBotScore.Type — The indicator type.
- DBotScore.Vendor — The vendor reporting the score (Darkmon).
- DBotScore.Score — The reputation score (0=Unknown, 1=Good, 2=Suspicious, 3=Bad).
- DBotScore.Reliability — Source reliability per the Admiralty code.
- Domain.Name — The Domain value.
- Domain.Malicious.Vendor — The vendor that flagged this Domain as malicious (Darkmon).
- Domain.Malicious.Description — Reason this Domain was flagged as malicious.
- Darkmon.SearchResult — Full search result records returned by Darkmon for this indicator.
Commands used
- domain