TIM - Process Domain Registrant With Whois
This playbook compares the domain registrant against the Cortex XSOAR list of approved registrants provided in the inputs. A registrant is the company or entity that owns the domain.
- Pack
- Whois
- Tasks
- 18
Inputs
- ApprovedregistrantsListName — The Cortex XSOAR list name that contains the approved registrars. A registrant is the company or entity that owns the domain.
- RegistrantListDelimiter — A one-character string used to delimit fields. This must match the value that you defined in the list separator server configuration. The default value is a comma, however, as registrants might contain the "," character in their name, Cortex XSOAR recommends that you select a different delimiter.
- WhoisResults — This input receives the Whois results from the parent playbook.
Outputs
- RegistrantDomainNotInList — Domains for which the registrant wasn't in the list.
- RegistrantDomainInList — Domains for which the registrant was in the list.
- DomainsNotResolvedByWhois — Domains which Whois wasn't able to resolve.
- DomainsNotProcessed — In case no registrant list was provided all domains will be outputted to this context path.
Commands used
- appendIndicatorField