Indicator Pivoting - DomainTools Iris
Pivots are used to gather data that share a common attribute with a domain. For instance, pivoting on an IP Address will give you back all domains related to that IP address.
DomainTools Iris Investigate · 17 tasks · 13 inputs · 86 outputs
Details
| ID | Indicator Pivoting - DomainTools Iris |
|---|---|
| From Version | 5.0.0 |
| Tasks | 17 |
README
Gathers data through pivots that share a common attribute with a domain. For instance, pivoting on an IP address will give you back all domains related to that IP address.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
This playbook does not use any sub-playbooks.
Integrations
- DomainTools Iris
Scripts
This playbook does not use any scripts.
Commands
- domaintoolsiris-pivot
Playbook Inputs
| Name | Description | Default Value | Source | Required |
|---|---|---|---|---|
| IPAddress | The IP address to pivot. | Address | IP | Optional |
| EmailAddress | The Email address for which to pivot. | Email.Address | Account | Optional |
| NameServerIPAddress | The name server IP address for which to pivot. | - | - | Optional |
| SSLHash | The SSL Hash for which to pivot. | - | - | Optional |
| NameServerHostName | The name server host name for which to pivot. | - | - | Optional |
| MailServerHostName | The mail server host name for which to pivot. | - | - | Optional |
| IPAddressCount | The number of matches for the IP address. | - | - | Optional |
| EmailAddressCount | The number of matches for the email address. | - | - | Optional |
| NameServerIPAddressCount | The number of matches for the name server IP address. | - | - | Optional |
| SSLHashCount | The number of matches for the SSL Hash. | - | - | Optional |
| NameServerHostNameCount | The number of matches for the name server host name. | - | - | Optional |
| MailServerHostNameCount | The number of matches for the mail server host name. | - | - | Optional |
| PivotThreshold | The threshold for matches less than to pivot on. | 500 | - | Optional |
Playbook Outputs
| Path | Description | Type |
|---|---|---|
| DomainTools.PivotedDomains.Name | The DomainTools domain name. | String |
| DomainTools.PivotedDomains.LastEnriched | The last time DomainTools enriched domain data. | Date |
| DomainTools.PivotedDomains.Analytics.OverallRiskScore | The DomainTools overall risk score. | Number |
| DomainTools.PivotedDomains.Analytics.ProximityRiskScore | The DomainTools proximity risk score. | Number |
| DomainTools.PivotedDomains.Analytics.ThreatProfileRiskScore.RiskScore | The DomainTools threat profile risk score. | Number |
| DomainTools.PivotedDomains.Analytics.ThreatProfileRiskScore.Threats | The DomainTools threat profile threats. | String |
| DomainTools.PivotedDomains.Analytics.ThreatProfileRiskScore.Evidence | The DomainTools threat profile evidence. | String |
| DomainTools.PivotedDomains.Analytics.WebsiteResponseCode | The website response code. | Number |
| DomainTools.PivotedDomains.Analytics.AlexaRank | The Alexa rank. | Number |
| DomainTools.PivotedDomains.Analytics.Tags | The DomainTools Tags. | String |
| DomainTools.PivotedDomains.Identity.RegistrantName | The name of the registrant. | String |
| DomainTools.PivotedDomains.Identity.RegistrantOrg | The organization of the registrant. | String |
| DomainTools.PivotedDomains.Identity.RegistrantContact.Country.value | The country value of the registrant contact. | String |
| DomainTools.PivotedDomains.Identity.RegistrantContact.Country.count | The country count of the registrant contact. | Number |
| DomainTools.PivotedDomains.Identity.RegistrantContact.Email.value | The email value of the registrant contact. | String |
| DomainTools.PivotedDomains.Identity.RegistrantContact.Email.count | The email count of the registrant contact. | Number |
| DomainTools.PivotedDomains.Identity.RegistrantContact.Name.value | The name value of the registrant contact. | String |
| DomainTools.PivotedDomains.Identity.RegistrantContact.Name.count | The name count of the registrant contact. | Number |
| DomainTools.PivotedDomains.Identity.RegistrantContact.Phone.value | The phone value of the registrant contact. | String |
| DomainTools.PivotedDomains.Identity.RegistrantContact.Phone.count | The phone count of the registrant contact. | Number |
| DomainTools.PivotedDomains.Identity.SOAEmail | The SOA record Email. | String |
| DomainTools.PivotedDomains.Identity.SSLCertificateEmail | The SSL certificate email. | String |
| DomainTools.PivotedDomains.Identity.AdminContact.Country.value | The country value of the administrator contact. | String |
| DomainTools.PivotedDomains.Identity.AdminContact.Country.count | The country count of the administrator contact. | Number |
| DomainTools.PivotedDomains.Identity.AdminContact.Email.value | The email value of the administrator contact. | String |
| DomainTools.PivotedDomains.Identity.AdminContact.Email.count | The email count of the administrator contact. | Number |
| DomainTools.PivotedDomains.Identity.AdminContact.Name.value | The name value of the administrator contact. | String |
| DomainTools.PivotedDomains.Identity.AdminContact.Name.count | The name count of the administrator contact. | Number |
| DomainTools.PivotedDomains.Identity.AdminContact.Phone.value | The phone value of the administrator contact. | String |
| DomainTools.PivotedDomains.Identity.AdminContact.Phone.count | The phone count of the administrator contact. | Number |
| DomainTools.PivotedDomains.Identity.TechnicalContact.Country.value | The country value of the technical contact. | String |
| DomainTools.PivotedDomains.Identity.TechnicalContact.Country.count | The country count of the technical contact. | Number |
| DomainTools.PivotedDomains.Identity.TechnicalContact.Email.value | The email value of the technical contact. | String |
| DomainTools.PivotedDomains.Identity.TechnicalContact.Email.count | The email count of the technical contact. | Number |
| DomainTools.PivotedDomains.Identity.TechnicalContact.Name.value | The name value of the technical contact. | String |
| DomainTools.PivotedDomains.Identity.TechnicalContact.Name.count | The name count of the technical contact. | Number |
| DomainTools.PivotedDomains.Identity.TechnicalContact.Phone.value | The phone value of the technical contact. | String |
| DomainTools.PivotedDomains.Identity.TechnicalContact.Phone.count | The phone count of the technical contact. | Number |
| DomainTools.PivotedDomains.Identity.BillingContact.Country.value | The country value of the billing contact. | String |
| DomainTools.PivotedDomains.Identity.BillingContact.Country.count | The country count of the billing contact. | Number |
| DomainTools.PivotedDomains.Identity.BillingContact.Email.value | The email value of the billing contact. | String |
| DomainTools.PivotedDomains.Identity.BillingContact.Email.count | The email count of the billing contact. | Number |
| DomainTools.PivotedDomains.Identity.BillingContact.Name.value | The name value of the billing contact. | String |
| DomainTools.PivotedDomains.Identity.BillingContact.Name.count | The name count of the billing contact. | Number |
| DomainTools.PivotedDomains.Identity.BillingContact.Phone.value | The phone value of the billing contact. | String |
| DomainTools.PivotedDomains.Identity.BillingContact.Phone.count | The phone count of the billing contact. | Number |
| DomainTools.PivotedDomains.Identity.EmailDomains | The email domains. | String |
| DomainTools.PivotedDomains.Identity.AdditionalWhoisEmails.value | The value of the additional Whois emails. | String |
| DomainTools.PivotedDomains.Identity.AdditionalWhoisEmails.count | The count of the additional Whois emails. | Number |
| DomainTools.PivotedDomains.Registration.DomainRegistrant | The registrant of the domain. | String |
| DomainTools.PivotedDomains.Registration.RegistrarStatus | The status of the registrar. | String |
| DomainTools.PivotedDomains.Registration.DomainStatus | The active status of the domain. | Boolean |
| DomainTools.PivotedDomains.Registration.CreateDate | The date the domain was created. | Date |
| DomainTools.PivotedDomains.Registration.ExpirationDate | The expiry date of the domain. | Date |
| DomainTools.PivotedDomains.Hosting.IPAddresses.address.value | The address value of the IP Addresses. | String |
| DomainTools.PivotedDomains.Hosting.IPAddresses.address.count | The address count of the IP Addresses. | Number |
| DomainTools.PivotedDomains.Hosting.IPAddresses.asn.value | The ASN value of the IP Addresses. | String |
| DomainTools.PivotedDomains.Hosting.IPAddresses.asn.count | The ASN count of the IP Addresses. | Number |
| DomainTools.PivotedDomains.Hosting.IPAddresses.country_code.value | The country code value of the IP Addresses. | String |
| DomainTools.PivotedDomains.Hosting.IPAddresses.country_code.count | The country code count of the IP Addresses. | Number |
| DomainTools.PivotedDomains.Hosting.IPAddresses.isp.value | The ISP value of the IP Addresses. | String |
| DomainTools.PivotedDomains.Hosting.IPAddresses.isp.count | The ISP count of the IP Addresses. | Number |
| DomainTools.PivotedDomains.Hosting.IPCountryCode | The country code of the IP address. | String |
| DomainTools.PivotedDomains.Hosting.MailServers.domain.value | The domain value of the mail servers. | String |
| DomainTools.PivotedDomains.Hosting.MailServers.domain.count | The domain count of the mail servers. | Number |
| DomainTools.PivotedDomains.Hosting.MailServers.host.value | The host value of the mail servers. | String |
| DomainTools.PivotedDomains.Hosting.MailServers.host.count | The host count of the mail servers. | Number |
| DomainTools.PivotedDomains.Hosting.MailServers.ip.value | The IP value of the mail servers. | String |
| DomainTools.PivotedDomains.Hosting.MailServers.ip.count | The IP count of the mail servers. | Number |
| DomainTools.PivotedDomains.Hosting.SPFRecord | The SPF record. | String |
| DomainTools.PivotedDomains.Hosting.NameServers.domain.value | The domain value of the DomainTools domains name servers. | String |
| DomainTools.PivotedDomains.Hosting.NameServers.domain.count | The domain count of the domainTools Domains name servers. | Number |
| DomainTools.PivotedDomains.Hosting.NameServers.host.value | The host value of the DomainTools domains name servers. | String |
| DomainTools.PivotedDomains.Hosting.NameServers.host.count | The host count of the DomainTools domains name servers. | Number |
| DomainTools.PivotedDomains.Hosting.NameServers.ip.value | The IP value of the DomainTools domains name servers. | String |
| DomainTools.PivotedDomains.Hosting.NameServers.ip.count | The IP count of the DomainTools domains name servers. | Number |
| DomainTools.PivotedDomains.Hosting.SSLCertificate.hash.value | The hash value of the SSL certificate. | String |
| DomainTools.PivotedDomains.Hosting.SSLCertificate.hash.count | The hash count of the SSL certificate. | Number |
| DomainTools.PivotedDomains.Hosting.SSLCertificate.organization.value | The organization value of the SSL certificate. | String |
| DomainTools.PivotedDomains.Hosting.SSLCertificate.organization.count | The organization count of the SSL certificate. | Number |
| DomainTools.PivotedDomains.Hosting.SSLCertificate.subject.value | The subject value of the SSL certificate. | String |
| DomainTools.PivotedDomains.Hosting.SSLCertificate.subject.count | The subject count of the SSL certificate. | Number |
| DomainTools.PivotedDomains.Hosting.RedirectsTo.value | The redirects to value of the domain. | String |
| DomainTools.PivotedDomains.Hosting.RedirectsTo.count | The redirects to count of the domain. | Number |
| DomainTools.PivotedDomains.Analytics.GoogleAdsenseTrackingCode | The tracking code of Google Adsense. | Number |
| DomainTools.PivotedDomains.Analytics.GoogleAnalyticTrackingCode | The tracking code of Google Analytics. | Number |
Playbook Image

Inputs
IPAddress— The IP address to pivot.EmailAddress— The Email address for which to pivot.NameServerIPAddress— The Name Server IP address for which to pivot.SSLHash— The SSL Hash for which to pivot.NameServerHostName— The Name Server Host Name for which to pivot.MailServerHostName— The Mail Server Host Name for which to pivot.IPAddressCount— The number of matches for the IP address.EmailAddressCount— The number of matches for the Email address.NameServerIPAddressCount— The number of matches for the Name Server IP address.SSLHashCount— The number of matches for the SSL Hash.NameServerHostNameCount— The number of matches for the Name Server Host Name.MailServerHostNameCount— The number of matches for the Mail Server Host Name.PivotThreshold— The threshold for matches less than to pivot on.
Outputs
DomainTools.PivotedDomains.Name— The DomainTools Domain Name.DomainTools.PivotedDomains.LastEnriched— The last time DomainTools enriched domain data.DomainTools.PivotedDomains.Analytics.OverallRiskScore— The DomainTools Overall Risk Score.DomainTools.PivotedDomains.Analytics.ProximityRiskScore— The DomainTools Proximity Risk Score.DomainTools.PivotedDomains.Analytics.ThreatProfileRiskScore.RiskScore— The DomainTools Threat Profile Risk Score.DomainTools.PivotedDomains.Analytics.ThreatProfileRiskScore.Threats— The DomainTools Threat Profile Threats.DomainTools.PivotedDomains.Analytics.ThreatProfileRiskScore.Evidence— The DomainTools Threat Profile Evidence.DomainTools.PivotedDomains.Analytics.WebsiteResponseCode— The Website Response Code.DomainTools.PivotedDomains.Analytics.AlexaRank— The Alexa Rank.DomainTools.PivotedDomains.Analytics.Tags— The DomainTools Tags.DomainTools.PivotedDomains.Identity.RegistrantName— The name of the registrant.DomainTools.PivotedDomains.Identity.RegistrantOrg— The organization of the registrant.DomainTools.PivotedDomains.Identity.RegistrantContact.Country.value— The country value of the registrant contact.DomainTools.PivotedDomains.Identity.RegistrantContact.Country.count— The Country count of the registrant contact.DomainTools.PivotedDomains.Identity.RegistrantContact.Email.value— The Email value of the registrant contact.DomainTools.PivotedDomains.Identity.RegistrantContact.Email.count— The Email count of the registrant contact.DomainTools.PivotedDomains.Identity.RegistrantContact.Name.value— The name value of the registrant contact.DomainTools.PivotedDomains.Identity.RegistrantContact.Name.count— The name count of the registrant contact.DomainTools.PivotedDomains.Identity.RegistrantContact.Phone.value— The phone value of the registrant contact.DomainTools.PivotedDomains.Identity.RegistrantContact.Phone.count— The phone count of the registrant contact.DomainTools.PivotedDomains.Identity.SOAEmail— The SOA record Email.DomainTools.PivotedDomains.Identity.SSLCertificateEmail— The SSL certificate Email.DomainTools.PivotedDomains.Identity.AdminContact.Country.value— The country value of the administrator contact.DomainTools.PivotedDomains.Identity.AdminContact.Country.count— The country count of the administrator contact.DomainTools.PivotedDomains.Identity.AdminContact.Email.value— The Email value of the administrator contact.DomainTools.PivotedDomains.Identity.AdminContact.Email.count— The Email count of the administrator contact.DomainTools.PivotedDomains.Identity.AdminContact.Name.value— The name value of the administrator contact.DomainTools.PivotedDomains.Identity.AdminContact.Name.count— The name count of the administrator contact.DomainTools.PivotedDomains.Identity.AdminContact.Phone.value— The phone value of the administrator contact.DomainTools.PivotedDomains.Identity.AdminContact.Phone.count— The phone count of the administrator contact.DomainTools.PivotedDomains.Identity.TechnicalContact.Country.value— The country value of the technical contact.DomainTools.PivotedDomains.Identity.TechnicalContact.Country.count— The country count of the technical contact.DomainTools.PivotedDomains.Identity.TechnicalContact.Email.value— The Email value of the technical contact.DomainTools.PivotedDomains.Identity.TechnicalContact.Email.count— The Email count of the technical contact.DomainTools.PivotedDomains.Identity.TechnicalContact.Name.value— The name value of the technical contact.DomainTools.PivotedDomains.Identity.TechnicalContact.Name.count— The name count of the technical contact.DomainTools.PivotedDomains.Identity.TechnicalContact.Phone.value— The phone value of the technical contact.DomainTools.PivotedDomains.Identity.TechnicalContact.Phone.count— The phone count of the technical contact.DomainTools.PivotedDomains.Identity.BillingContact.Country.value— The country value of the billing contact.DomainTools.PivotedDomains.Identity.BillingContact.Country.count— The country count of the billing contact.DomainTools.PivotedDomains.Identity.BillingContact.Email.value— The Email value of the billing contact.DomainTools.PivotedDomains.Identity.BillingContact.Email.count— The Email count of the billing contact.DomainTools.PivotedDomains.Identity.BillingContact.Name.value— The name value of the billing contact.DomainTools.PivotedDomains.Identity.BillingContact.Name.count— The name count of the billing contact.DomainTools.PivotedDomains.Identity.BillingContact.Phone.value— The phone value of the billing contact.DomainTools.PivotedDomains.Identity.BillingContact.Phone.count— The phone count of the billing contact.DomainTools.PivotedDomains.Identity.EmailDomains— The Email domains.DomainTools.PivotedDomains.Identity.AdditionalWhoisEmails.value— The value of the Additional Whois Emails.DomainTools.PivotedDomains.Identity.AdditionalWhoisEmails.count— The count of the Additional Whois Emails.DomainTools.PivotedDomains.Registration.DomainRegistrant— The registrant of the domain.DomainTools.PivotedDomains.Registration.RegistrarStatus— The status of the registrar.DomainTools.PivotedDomains.Registration.DomainStatus— The active status of the domain.DomainTools.PivotedDomains.Registration.CreateDate— The date the domain was created.DomainTools.PivotedDomains.Registration.ExpirationDate— The expiry date of the domain.DomainTools.PivotedDomains.Hosting.IPAddresses.address.value— The address value of the IP Addresses.DomainTools.PivotedDomains.Hosting.IPAddresses.address.count— The address count of the IP Addresses.DomainTools.PivotedDomains.Hosting.IPAddresses.asn.value— The ASN value of the IP Addresses.DomainTools.PivotedDomains.Hosting.IPAddresses.asn.count— The ASN count of the IP Addresses.DomainTools.PivotedDomains.Hosting.IPAddresses.country_code.value— The country code value of the IP Addresses.DomainTools.PivotedDomains.Hosting.IPAddresses.country_code.count— The country code count of the IP Addresses.DomainTools.PivotedDomains.Hosting.IPAddresses.isp.value— The ISP value of the IP Addresses.DomainTools.PivotedDomains.Hosting.IPAddresses.isp.count— The ISP count of the IP Addresses.DomainTools.PivotedDomains.Hosting.IPCountryCode— The country code of the IP address.DomainTools.PivotedDomains.Hosting.MailServers.domain.value— The domain value of the Mail Servers.DomainTools.PivotedDomains.Hosting.MailServers.domain.count— The domain count of the Mail Servers.DomainTools.PivotedDomains.Hosting.MailServers.host.value— The host value of the Mail Servers.DomainTools.PivotedDomains.Hosting.MailServers.host.count— The host count of the Mail Servers.DomainTools.PivotedDomains.Hosting.MailServers.ip.value— The IP value of the Mail Servers.DomainTools.PivotedDomains.Hosting.MailServers.ip.count— The IP count of the Mail Servers.DomainTools.PivotedDomains.Hosting.SPFRecord— The SPF record.DomainTools.PivotedDomains.Hosting.NameServers.domain.value— The domain value of the DomainTools Domains NameServers.DomainTools.PivotedDomains.Hosting.NameServers.domain.count— The domain count of the DomainTools Domains NameServers.DomainTools.PivotedDomains.Hosting.NameServers.host.value— The host value of the DomainTools Domains NameServers.DomainTools.PivotedDomains.Hosting.NameServers.host.count— The host count of the DomainTools Domains NameServers.DomainTools.PivotedDomains.Hosting.NameServers.ip.value— The IP value of the DomainTools Domains NameServers.DomainTools.PivotedDomains.Hosting.NameServers.ip.count— The IP count of the DomainTools Domains NameServers.DomainTools.PivotedDomains.Hosting.SSLCertificate.hash.value— The Hash value of the SSL certificate.DomainTools.PivotedDomains.Hosting.SSLCertificate.hash.count— The Hash count of the SSL certificate.DomainTools.PivotedDomains.Hosting.SSLCertificate.organization.value— The organization value of the SSL certificate.DomainTools.PivotedDomains.Hosting.SSLCertificate.organization.count— The organization count of the SSL certificate.DomainTools.PivotedDomains.Hosting.SSLCertificate.subject.value— The subject value of the SSL certificate.DomainTools.PivotedDomains.Hosting.SSLCertificate.subject.count— The subject count of the SSL certificate.DomainTools.PivotedDomains.Hosting.RedirectsTo.value— The Redirects To value of the domain.DomainTools.PivotedDomains.Hosting.RedirectsTo.count— The Redirects To count of the domain.DomainTools.PivotedDomains.Analytics.GoogleAdsenseTrackingCode— The tracking code of Google Adsense.DomainTools.PivotedDomains.Analytics.GoogleAnalyticTrackingCode— The tracking code of Google Analytics.
Commands used
domaintoolsiris-pivot
Flowchart
id: Indicator Pivoting - DomainTools Iris version: -1 name: Indicator Pivoting - DomainTools Iris description: Pivots are used to gather data that share a common attribute with a domain. For instance, pivoting on an IP Address will give you back all domains related to that IP address. starttaskid: '0' tasks: '0': id: '0' taskid: a8ce28a7-1083-45bb-8c3c-311bf5a43932 type: start task: id: a8ce28a7-1083-45bb-8c3c-311bf5a43932 version: -1 name: '' description: Start of playbook. iscommand: false brand: '' nexttasks: '#none#': - '16' separatecontext: false view: "{\n \"position\": {\n \"x\": 750,\n \"y\": -300\n }\n}" note: false timertriggers: [] ignoreworker: false '3': id: '3' taskid: 776aa67e-951c-42db-8258-9ae384c13030 type: title task: id: 776aa67e-951c-42db-8258-9ae384c13030 version: -1 name: Done description: End of playbook. type: title iscommand: false brand: '' separatecontext: false view: "{\n \"position\": {\n \"x\": 740,\n \"y\": 660\n }\n}" note: false timertriggers: [] ignoreworker: false '4': id: '4' taskid: 4101f161-91b9-4d5d-8be7-8412255ce7f8 type: condition task: id: 4101f161-91b9-4d5d-8be7-8412255ce7f8 version: -1 name: Pivot on E-mail address? description: Determines whether to pivot on an Email address. type: condition iscommand: false brand: '' nexttasks: '#default#': - '3' email_address: - '5' separatecontext: false conditions: - label: email_address condition: - - operator: isExists left: value: complex: root: inputs.EmailAddress transformers: - operator: uniq iscontext: true - - operator: isExists left: value: simple: inputs.EmailAddressCount iscontext: true - - operator: lessThanOrEqual left: value: simple: inputs.EmailAddressCount iscontext: true right: value: simple: inputs.PivotThreshold iscontext: true view: "{\n \"position\": {\n \"x\": -740,\n \"y\": 180\n }\n}" note: false timertriggers: [] ignoreworker: false '5': id: '5' taskid: d183d95c-7d02-45b1-832d-bf95ad0fdbd1 type: regular task: id: d183d95c-7d02-45b1-832d-bf95ad0fdbd1 version: -1 name: E-mail Pivot description: Pivots on an Email. script: DomainTools Iris|||domaintoolsiris-pivot type: regular iscommand: true brand: DomainTools Iris nexttasks: '#none#': - '3' scriptarguments: email: complex: root: inputs.EmailAddress transformers: - operator: uniq ip: {} mailserver_host: {} nameserver_host: {} nameserver_ip: {} ssl_hash: {} separatecontext: false view: "{\n \"position\": {\n \"x\": -940,\n \"y\": 350\n }\n}" note: false timertriggers: [] ignoreworker: false '6': id: '6' taskid: 33062c78-7259-4717-8cf4-3b56d33bd085 type: regular task: id: 33062c78-7259-4717-8cf4-3b56d33bd085 version: -1 name: IP Pivot description: Pivots on an IP address. script: DomainTools Iris|||domaintoolsiris-pivot type: regular iscommand: true brand: DomainTools Iris nexttasks: '#none#': - '3' scriptarguments: email: {} ip: complex: root: inputs.IPAddress transformers: - operator: uniq mailserver_host: {} nameserver_host: {} nameserver_ip: {} ssl_hash: {} separatecontext: false view: "{\n \"position\": {\n \"x\": -380,\n \"y\": 350\n }\n}" note: false timertriggers: [] ignoreworker: false '7': id: '7' taskid: c3a1c6b6-c0b2-405f-8649-9b43f3a4a19e type: regular task: id: c3a1c6b6-c0b2-405f-8649-9b43f3a4a19e version: -1 name: NameServer IP Pivot description: Pivots on a NameServer IP address. script: DomainTools Iris|||domaintoolsiris-pivot type: regular iscommand: true brand: DomainTools Iris nexttasks: '#none#': - '3' scriptarguments: email: {} ip: {} mailserver_host: {} nameserver_host: {} nameserver_ip: complex: root: inputs.NameServerIPAddress transformers: - operator: uniq ssl_hash: {} separatecontext: false view: "{\n \"position\": {\n \"x\": 210,\n \"y\": 350\n }\n}" note: false timertriggers: [] ignoreworker: false '8': id: '8' taskid: 5b1e99a2-4c8e-444b-88c0-2e22f21edb3d type: regular task: id: 5b1e99a2-4c8e-444b-88c0-2e22f21edb3d version: -1 name: SSL Hash Pivot description: Pivots on a SSL Hash. script: DomainTools Iris|||domaintoolsiris-pivot type: regular iscommand: true brand: DomainTools Iris nexttasks: '#none#': - '3' scriptarguments: email: {} ip: {} mailserver_host: {} nameserver_host: {} nameserver_ip: {} ssl_hash: complex: root: inputs.SSLHash transformers: - operator: uniq separatecontext: false view: "{\n \"position\": {\n \"x\": 1250,\n \"y\": 360\n }\n}" note: false timertriggers: [] ignoreworker: false '9': id: '9' taskid: 7d6ff0de-a24b-41c9-8d64-dd0743f1cdf1 type: regular task: id: 7d6ff0de-a24b-41c9-8d64-dd0743f1cdf1 version: -1 name: NameServer HostName Pivot description: Pivots on a NameServer HostName. script: DomainTools Iris|||domaintoolsiris-pivot type: regular iscommand: true brand: DomainTools Iris nexttasks: '#none#': - '3' scriptarguments: email: {} ip: {} mailserver_host: {} nameserver_host: complex: root: inputs.NameServerHostName transformers: - operator: uniq nameserver_ip: {} ssl_hash: {} separatecontext: false view: "{\n \"position\": {\n \"x\": 1770,\n \"y\": 360\n }\n}" note: false timertriggers: [] ignoreworker: false '10': id: '10' taskid: 1c2d4e3d-2a80-42ae-8dbc-c532148f5196 type: regular task: id: 1c2d4e3d-2a80-42ae-8dbc-c532148f5196 version: -1 name: MailServer HostName description: Pivots on a MailServer HostName. script: DomainTools Iris|||domaintoolsiris-pivot type: regular iscommand: true brand: DomainTools Iris nexttasks: '#none#': - '3' scriptarguments: email: {} ip: {} mailserver_host: complex: root: inputs.MailServerHostName transformers: - operator: uniq nameserver_host: {} nameserver_ip: {} ssl_hash: {} separatecontext: false view: "{\n \"position\": {\n \"x\": 2340,\n \"y\": 380\n }\n}" note: false timertriggers: [] ignoreworker: false '11': id: '11' taskid: 116e7c75-54e2-4947-8332-171ea2fcc051 type: condition task: id: 116e7c75-54e2-4947-8332-171ea2fcc051 version: -1 name: Pivot on an IP address? description: Determines whether to pivot on an IP Address. type: condition iscommand: false brand: '' nexttasks: '#default#': - '3' ip: - '6' separatecontext: false conditions: - label: ip condition: - - operator: isExists left: value: complex: root: inputs.IPAddress transformers: - operator: uniq iscontext: true - - operator: isExists left: value: simple: inputs.IPAddressCount iscontext: true - - operator: lessThanOrEqual left: value: simple: inputs.IPAddressCount iscontext: true right: value: simple: inputs.PivotThreshold iscontext: true view: "{\n \"position\": {\n \"x\": -180,\n \"y\": 180\n }\n}" note: false timertriggers: [] ignoreworker: false '12': id: '12' taskid: 3f0eb85b-f974-4845-805a-297bc7166dec type: condition task: id: 3f0eb85b-f974-4845-805a-297bc7166dec version: -1 name: Pivot on a NameServer IP? description: Determines whether to pivot on a NameServer IP address. type: condition iscommand: false brand: '' nexttasks: '#default#': - '3' nameserver_ip: - '7' separatecontext: false conditions: - label: nameserver_ip condition: - - operator: isExists left: value: complex: root: inputs.NameServerIPAddress transformers: - operator: uniq iscontext: true - - operator: isExists left: value: complex: root: inputs.NameServerIPAddressCount iscontext: true - - operator: lessThan left: value: complex: root: inputs.IPAddressCount iscontext: true right: value: simple: inputs.PivotThreshold iscontext: true view: "{\n \"position\": {\n \"x\": 390,\n \"y\": 180\n }\n}" note: false timertriggers: [] ignoreworker: false '13': id: '13' taskid: 92e7c263-9249-44d6-852c-c02eb4f4de75 type: condition task: id: 92e7c263-9249-44d6-852c-c02eb4f4de75 version: -1 name: Pivot on a SSL Hash? description: Determines whether to pivot on a SSL Hash. type: condition iscommand: false brand: '' nexttasks: '#default#': - '3' ssl_hash: - '8' separatecontext: false conditions: - label: ssl_hash condition: - - operator: isExists left: value: complex: root: inputs.SSLHash transformers: - operator: uniq iscontext: true - - operator: isExists left: value: complex: root: inputs.SSLHashCount iscontext: true - - operator: lessThanOrEqual left: value: complex: root: inputs.IPAddressCount iscontext: true right: value: simple: inputs.PivotThreshold iscontext: true view: "{\n \"position\": {\n \"x\": 1080,\n \"y\": 180\n }\n}" note: false timertriggers: [] ignoreworker: false '14': id: '14' taskid: 2e14b0b4-1fa7-4ac5-87a9-5f561da83afa type: condition task: id: 2e14b0b4-1fa7-4ac5-87a9-5f561da83afa version: -1 name: Pivot on NameServer HostName? description: Determines whether to pivot on a NameServer HostName. type: condition iscommand: false brand: '' nexttasks: '#default#': - '3' nameserver_host: - '9' separatecontext: false conditions: - label: nameserver_host condition: - - operator: isExists left: value: complex: root: inputs.NameServerHostName transformers: - operator: uniq iscontext: true - - operator: isExists left: value: complex: root: inputs.NameServerHostNameCount iscontext: true - - operator: lessThanOrEqual left: value: complex: root: inputs.NameServerHostNameCount iscontext: true right: value: simple: inputs.PivotThreshold iscontext: true view: "{\n \"position\": {\n \"x\": 1610,\n \"y\": 180\n }\n}" note: false timertriggers: [] ignoreworker: false '15': id: '15' taskid: 08927281-b7fa-4735-8fef-fd4cafddf63e type: condition task: id: 08927281-b7fa-4735-8fef-fd4cafddf63e version: -1 name: Pivot on a MailServer HostName? description: Determines whether to pivot on a MailServer HostName. type: condition iscommand: false brand: '' nexttasks: '#default#': - '3' mailserver_host: - '10' separatecontext: false conditions: - label: mailserver_host condition: - - operator: isExists left: value: complex: root: inputs.MailServerHostName transformers: - operator: uniq iscontext: true - - operator: isExists left: value: complex: root: inputs.MailServerHostNameCount iscontext: true - - operator: lessThan left: value: complex: root: inputs.MailServerHostNameCount iscontext: true right: value: simple: inputs.PivotThreshold iscontext: true view: "{\n \"position\": {\n \"x\": 2140,\n \"y\": 180\n }\n}" note: false timertriggers: [] ignoreworker: false '16': id: '16' taskid: 48dc1f6f-6c12-4a80-8939-17dd36c149ea type: condition task: id: 48dc1f6f-6c12-4a80-8939-17dd36c149ea version: -1 name: Is DomainTools Iris enabled? description: Checks whether the DomainTools Iris integration is enabled. type: condition iscommand: false brand: '' nexttasks: '#default#': - '18' 'yes': - '17' separatecontext: false conditions: - label: 'yes' condition: - - operator: isExists left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: brand iscontext: true right: value: simple: DomainTools Iris - - operator: isEqualString left: value: simple: state iscontext: true right: value: simple: active iscontext: true view: "{\n \"position\": {\n \"x\": 750,\n \"y\": -130\n }\n}" note: false timertriggers: [] ignoreworker: false '17': id: '17' taskid: 0197bd89-9066-4970-86e9-6be1a85fdc1c type: title task: id: 0197bd89-9066-4970-86e9-6be1a85fdc1c version: -1 name: Indicator Pivoting type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '4' - '11' - '12' - '13' - '14' - '15' separatecontext: false view: "{\n \"position\": {\n \"x\": 750,\n \"y\": 40\n }\n}" note: false timertriggers: [] ignoreworker: false '18': id: '18' taskid: 0ef54c67-04b3-45e3-830c-1cfbddb5f2ab type: title task: id: 0ef54c67-04b3-45e3-830c-1cfbddb5f2ab version: -1 name: Integration Not Enabled type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '3' separatecontext: false view: "{\n \"position\": {\n \"x\": -1450,\n \"y\": 40\n }\n}" note: false timertriggers: [] ignoreworker: false view: "{\n \"linkLabelsPosition\": {\n \"11_3_#default#\": 0.29,\n \"12_3_#default#\": 0.59,\n \"13_3_#default#\": 0.6,\n \"14_3_#default#\": 0.29,\n \"15_3_#default#\": 0.19,\n \"16_18_#default#\": 0.16,\n \"4_3_#default#\": 0.2\n },\n \"paper\": {\n \"dimensions\": {\n \"height\": 1025,\n \"width\": 4170,\n \"x\": -1450,\n \"y\": -300\n }\n }\n}" inputs: - key: IPAddress value: complex: root: IP accessor: Address transformers: - operator: uniq required: false description: The IP address to pivot. - key: EmailAddress value: complex: root: Account accessor: Email.Address transformers: - operator: uniq required: false description: The Email address for which to pivot. - key: NameServerIPAddress value: {} required: false description: The Name Server IP address for which to pivot. - key: SSLHash value: {} required: false description: The SSL Hash for which to pivot. - key: NameServerHostName value: {} required: false description: The Name Server Host Name for which to pivot. - key: MailServerHostName value: {} required: false description: The Mail Server Host Name for which to pivot. - key: IPAddressCount value: {} required: false description: The number of matches for the IP address. - key: EmailAddressCount value: {} required: false description: The number of matches for the Email address. - key: NameServerIPAddressCount value: {} required: false description: The number of matches for the Name Server IP address. - key: SSLHashCount value: {} required: false description: The number of matches for the SSL Hash. - key: NameServerHostNameCount value: {} required: false description: The number of matches for the Name Server Host Name. - key: MailServerHostNameCount value: {} required: false description: The number of matches for the Mail Server Host Name. - key: PivotThreshold value: simple: '500' required: false description: 'The threshold for matches less than to pivot on. ' outputs: - contextPath: DomainTools.PivotedDomains.Name description: The DomainTools Domain Name. type: String - contextPath: DomainTools.PivotedDomains.LastEnriched description: The last time DomainTools enriched domain data. type: Date - contextPath: DomainTools.PivotedDomains.Analytics.OverallRiskScore description: The DomainTools Overall Risk Score. type: Number - contextPath: DomainTools.PivotedDomains.Analytics.ProximityRiskScore description: The DomainTools Proximity Risk Score. type: Number - contextPath: DomainTools.PivotedDomains.Analytics.ThreatProfileRiskScore.RiskScore description: The DomainTools Threat Profile Risk Score. type: Number - contextPath: DomainTools.PivotedDomains.Analytics.ThreatProfileRiskScore.Threats description: The DomainTools Threat Profile Threats. type: String - contextPath: DomainTools.PivotedDomains.Analytics.ThreatProfileRiskScore.Evidence description: The DomainTools Threat Profile Evidence. type: String - contextPath: DomainTools.PivotedDomains.Analytics.WebsiteResponseCode description: The Website Response Code. type: Number - contextPath: DomainTools.PivotedDomains.Analytics.AlexaRank description: The Alexa Rank. type: Number - contextPath: DomainTools.PivotedDomains.Analytics.Tags description: The DomainTools Tags. type: String - contextPath: DomainTools.PivotedDomains.Identity.RegistrantName description: The name of the registrant. type: String - contextPath: DomainTools.PivotedDomains.Identity.RegistrantOrg description: The organization of the registrant. type: String - contextPath: DomainTools.PivotedDomains.Identity.RegistrantContact.Country.value description: The country value of the registrant contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.RegistrantContact.Country.count description: The Country count of the registrant contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.RegistrantContact.Email.value description: The Email value of the registrant contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.RegistrantContact.Email.count description: The Email count of the registrant contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.RegistrantContact.Name.value description: The name value of the registrant contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.RegistrantContact.Name.count description: The name count of the registrant contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.RegistrantContact.Phone.value description: The phone value of the registrant contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.RegistrantContact.Phone.count description: The phone count of the registrant contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.SOAEmail description: The SOA record Email. type: String - contextPath: DomainTools.PivotedDomains.Identity.SSLCertificateEmail description: The SSL certificate Email. type: String - contextPath: DomainTools.PivotedDomains.Identity.AdminContact.Country.value description: The country value of the administrator contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.AdminContact.Country.count description: The country count of the administrator contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.AdminContact.Email.value description: The Email value of the administrator contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.AdminContact.Email.count description: The Email count of the administrator contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.AdminContact.Name.value description: The name value of the administrator contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.AdminContact.Name.count description: The name count of the administrator contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.AdminContact.Phone.value description: The phone value of the administrator contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.AdminContact.Phone.count description: The phone count of the administrator contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.TechnicalContact.Country.value description: The country value of the technical contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.TechnicalContact.Country.count description: The country count of the technical contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.TechnicalContact.Email.value description: The Email value of the technical contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.TechnicalContact.Email.count description: The Email count of the technical contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.TechnicalContact.Name.value description: The name value of the technical contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.TechnicalContact.Name.count description: The name count of the technical contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.TechnicalContact.Phone.value description: The phone value of the technical contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.TechnicalContact.Phone.count description: The phone count of the technical contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.BillingContact.Country.value description: The country value of the billing contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.BillingContact.Country.count description: The country count of the billing contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.BillingContact.Email.value description: The Email value of the billing contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.BillingContact.Email.count description: The Email count of the billing contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.BillingContact.Name.value description: The name value of the billing contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.BillingContact.Name.count description: The name count of the billing contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.BillingContact.Phone.value description: The phone value of the billing contact. type: String - contextPath: DomainTools.PivotedDomains.Identity.BillingContact.Phone.count description: The phone count of the billing contact. type: Number - contextPath: DomainTools.PivotedDomains.Identity.EmailDomains description: The Email domains. type: String - contextPath: DomainTools.PivotedDomains.Identity.AdditionalWhoisEmails.value description: The value of the Additional Whois Emails. type: String - contextPath: DomainTools.PivotedDomains.Identity.AdditionalWhoisEmails.count description: The count of the Additional Whois Emails. type: Number - contextPath: DomainTools.PivotedDomains.Registration.DomainRegistrant description: The registrant of the domain. type: String - contextPath: DomainTools.PivotedDomains.Registration.RegistrarStatus description: The status of the registrar. type: String - contextPath: DomainTools.PivotedDomains.Registration.DomainStatus description: The active status of the domain. type: Boolean - contextPath: DomainTools.PivotedDomains.Registration.CreateDate description: The date the domain was created. type: Date - contextPath: DomainTools.PivotedDomains.Registration.ExpirationDate description: The expiry date of the domain. type: Date - contextPath: DomainTools.PivotedDomains.Hosting.IPAddresses.address.value description: The address value of the IP Addresses. type: String - contextPath: DomainTools.PivotedDomains.Hosting.IPAddresses.address.count description: The address count of the IP Addresses. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.IPAddresses.asn.value description: The ASN value of the IP Addresses. type: String - contextPath: DomainTools.PivotedDomains.Hosting.IPAddresses.asn.count description: The ASN count of the IP Addresses. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.IPAddresses.country_code.value description: The country code value of the IP Addresses. type: String - contextPath: DomainTools.PivotedDomains.Hosting.IPAddresses.country_code.count description: The country code count of the IP Addresses. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.IPAddresses.isp.value description: The ISP value of the IP Addresses. type: String - contextPath: DomainTools.PivotedDomains.Hosting.IPAddresses.isp.count description: The ISP count of the IP Addresses. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.IPCountryCode description: The country code of the IP address. type: String - contextPath: DomainTools.PivotedDomains.Hosting.MailServers.domain.value description: The domain value of the Mail Servers. type: String - contextPath: DomainTools.PivotedDomains.Hosting.MailServers.domain.count description: The domain count of the Mail Servers. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.MailServers.host.value description: The host value of the Mail Servers. type: String - contextPath: DomainTools.PivotedDomains.Hosting.MailServers.host.count description: The host count of the Mail Servers. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.MailServers.ip.value description: The IP value of the Mail Servers. type: String - contextPath: DomainTools.PivotedDomains.Hosting.MailServers.ip.count description: The IP count of the Mail Servers. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.SPFRecord description: The SPF record. type: String - contextPath: DomainTools.PivotedDomains.Hosting.NameServers.domain.value description: The domain value of the DomainTools Domains NameServers. type: String - contextPath: DomainTools.PivotedDomains.Hosting.NameServers.domain.count description: The domain count of the DomainTools Domains NameServers. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.NameServers.host.value description: The host value of the DomainTools Domains NameServers. type: String - contextPath: DomainTools.PivotedDomains.Hosting.NameServers.host.count description: The host count of the DomainTools Domains NameServers. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.NameServers.ip.value description: The IP value of the DomainTools Domains NameServers. type: String - contextPath: DomainTools.PivotedDomains.Hosting.NameServers.ip.count description: The IP count of the DomainTools Domains NameServers. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.SSLCertificate.hash.value description: The Hash value of the SSL certificate. type: String - contextPath: DomainTools.PivotedDomains.Hosting.SSLCertificate.hash.count description: The Hash count of the SSL certificate. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.SSLCertificate.organization.value description: The organization value of the SSL certificate. type: String - contextPath: DomainTools.PivotedDomains.Hosting.SSLCertificate.organization.count description: The organization count of the SSL certificate. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.SSLCertificate.subject.value description: The subject value of the SSL certificate. type: String - contextPath: DomainTools.PivotedDomains.Hosting.SSLCertificate.subject.count description: The subject count of the SSL certificate. type: Number - contextPath: DomainTools.PivotedDomains.Hosting.RedirectsTo.value description: The Redirects To value of the domain. type: String - contextPath: DomainTools.PivotedDomains.Hosting.RedirectsTo.count description: The Redirects To count of the domain. type: Number - contextPath: DomainTools.PivotedDomains.Analytics.GoogleAdsenseTrackingCode description: The tracking code of Google Adsense. type: Number - contextPath: DomainTools.PivotedDomains.Analytics.GoogleAnalyticTrackingCode description: The tracking code of Google Analytics. type: Number sourceplaybookid: Indicator Pivoting - DomainTools Iris fromversion: 5.0.0 tests: - No tests (auto formatted)