TIM - Process Domains With Whois
This playbook uses several sub playbooks to process and tag indicators based on the results of the Whois tool.
- Pack
- Whois
- Tasks
- 9
Inputs
- CheckForWhoisRegistrant — Setting this input as True will run the TIM - Process Domain registrant With Whois playbook.
- CheckForWhoisDomainAgeCreation — Setting this input as True will run the TIM - Process Domain Creation Age With Whois playbook.
Outputs
- DomainsNotApproved — Domains for which the registrant isn't approved.
- ApprovedRegistrantDomains — Domains for which the registrant is approved.
- DomainsNotResolvedByWhois — Domains Not Resolved By Whois.
- NewDomains — Domains whose create value is after the tested date.
- NotNewDomains — Domains whose create value is before the tested date.
- DomainsNotProcessed — Domains that could not be processed for any reason are outputted to this context path.
Commands used
- whois