CheckPivotableDomains
Checks for guided pivots for a given domain.
python · DomainTools Iris Investigate
Details
| ID | CheckPivotableDomains |
|---|---|
| Language | python |
| From Version | 6.6.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Tags | DomainTools |
README
Checks for guided pivots for a given domain.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Tags | DomainTools |
Used In
This script is used in the following playbooks and scripts.
- DomainTools Auto Pivots
Inputs
| Argument Name | Description |
|---|---|
| domaintools_data | DomainTools context data for a domain |
| max_registrant_contact_name_count | Max threshold count that can be pivoted to a registrant contact name |
| max_registrant_org_count | Max threshold count that can be pivoted to a registrant org name |
| max_registrar_count | Max threshold count that can be pivoted to a registrar |
| max_ssl_info_organization_count | Max threshold count that can be pivoted to a ssl organization |
| max_ssl_info_hash_count | Max threshold count that can be pivoted to a ssl hash |
| max_ssl_email_count | Max threshold count that can be pivoted to a ssl email |
| max_ssl_subject_count | Max threshold count that can be pivoted to a ssl subject |
| max_name_server_host_count | Max threshold count that can be pivoted to a ssl subject |
| max_name_server_ip_count | Max threshold count that can be pivoted to a nameserver ip |
| max_name_server_domain_count | Max threshold count that can be pivoted to a nameserver domain |
| max_soa_email_count | Max threshold count that can be pivoted to a soa email |
| max_ip_address_count | Max threshold count that can be pivoted to an IP address |
| max_mx_ip_count | Max threshold count that can be pivoted to a MX IP |
| max_mx_host_count | Max threshold count that can be pivoted to a MX Host |
| max_mx_domain_count | Max threshold count that can be pivoted to a MX Domain |
| max_google_adsense_count | Max threshold count that can be pivoted to a google adsense |
| max_google_analytics_count | Max threshold count that can be pivoted to a google analytics |
Outputs
| Path | Description | Type |
|---|---|---|
| PivotableDomains.PivotableRegistrantContactName.pivotable | Is the domain’s registrant contact name a guided pivot. | Unknown |
| PivotableDomains.PivotableRegistrantContactName.items.count | Number of connected domains sharing the same registrant contact name. | Unknown |
| PivotableDomains.PivotableRegistrantContactName.items.value | Registrant contact name. | Unknown |
| PivotableDomains.PivotableRegistrantOrg.pivotable | Is the domain’s registrant org a guided pivot. | Unknown |
| PivotableDomains.PivotableRegistrantOrg.items.count | Number of connected domains sharing the same registrant org. | Unknown |
| PivotableDomains.PivotableRegistrantOrg.items.value | Registrant org. | Unknown |
| PivotableDomains.PivotableSslInfoOrganization.pivotable | Is the domain’s ssl org a guided pivot. | Unknown |
| PivotableDomains.PivotableSslInfoOrganization.items.count | Number of connected domains sharing the same ssl org. | Unknown |
| PivotableDomains.PivotableSslInfoOrganization.items.value | SSL org. | Unknown |
| PivotableDomains.PivotableSslInfoHash.pivotable | Is the domain’s ssl hash a guided pivot. | Unknown |
| PivotableDomains.PivotableSslInfoHash.items.count | Number of connected domains sharing the same ssl hash. | Unknown |
| PivotableDomains.PivotableSslInfoHash.items.value | SSL hash. | Unknown |
| PivotableDomains.PivotableNameServerHost.pivotable | Is the domain’s name server host a guided pivot. | Unknown |
| PivotableDomains.PivotableNameServerHost.items.count | Number of connected domains sharing the same name server host. | Unknown |
| PivotableDomains.PivotableNameServerHost.items.value | name server host. | Unknown |
| PivotableDomains.PivotableSoaEmail.pivotable | Is the domain’s name soa email a guided pivot. | Unknown |
| PivotableDomains.PivotableSoaEmail.items.count | Number of connected domains sharing the same name soa email. | Unknown |
| PivotableDomains.PivotableSoaEmail.items.value | soa email. | Unknown |
| PivotableDomains.PivotableIpAddress.pivotable | Is the domain’s IP address a guided pivot. | Unknown |
| PivotableDomains.PivotableIpAddress.items.count | Number of connected domains sharing the same IP address. | Unknown |
| PivotableDomains.PivotableIpAddress.items.value | IP address. | Unknown |
| PivotableDomains.PivotableNameServerIp.pivotable | Is the domain’s name server IP address a guided pivot. | Unknown |
| PivotableDomains.PivotableNameServerIp.items.count | Number of connected domains sharing the same name server IP address. | Unknown |
| PivotableDomains.PivotableNameServerIp.items.value | name server IP address. | Unknown |
| PivotableDomains.PivotableMxIp.pivotable | Is the domain’s mx IP address a guided pivot. | Unknown |
| PivotableDomains.PivotableMxIp.items.count | Number of connected domains sharing the same mx IP address. | Unknown |
| PivotableDomains.PivotableMxIp.items.value | mx IP address. | Unknown |
| PivotableDomains.PivotableRegistrar.pivotable | Is the domain’s registrar a guided pivot. | Unknown |
| PivotableDomains.PivotableRegistrar.items.count | Number of connected domains sharing the same registrar. | Unknown |
| PivotableDomains.PivotableRegistrar.items.value | Registrar. | Unknown |
| PivotableDomains.PivotableSslSubject.pivotable | Is the domain’s SSL subject a guided pivot. | Unknown |
| PivotableDomains.PivotableSslSubject.items.count | Number of connected domains sharing the SSL subject. | Unknown |
| PivotableDomains.PivotableSslSubject.items.value | SSL subject. | Unknown |
| PivotableDomains.PivotableSslEmail.pivotable | Is the domain’s SSL email a guided pivot. | Unknown |
| PivotableDomains.PivotableSslEmail.items.count | Number of connected domains sharing the SSL email. | Unknown |
| PivotableDomains.PivotableSslEmail.items.value | SSL email. | Unknown |
| PivotableDomains.PivotableNameServerDomain.pivotable | Is the domain’s name server domain a guided pivot. | Unknown |
| PivotableDomains.PivotableNameServerDomain.items.count | Number of connected domains sharing the name server domain. | Unknown |
| PivotableDomains.PivotableNameServerDomain.items.value | Name server domain. | Unknown |
| PivotableDomains.PivotableMxHost.pivotable | Is the domain’s mx host a guided pivot. | Unknown |
| PivotableDomains.PivotableMxHost.items.count | Number of connected domains sharing the mx host. | Unknown |
| PivotableDomains.PivotableMxHost.items.value | MX host. | Unknown |
| PivotableDomains.PivotableMxDomain.pivotable | Is the domain’s mx domain a guided pivot. | Unknown |
| PivotableDomains.PivotableMxDomain.items.count | Number of connected domains sharing the mx domain. | Unknown |
| PivotableDomains.PivotableMxDomain.items.value | MX domain. | Unknown |
| PivotableDomains.PivotableGoogleAnalytics.pivotable | Is the domain’s Google analytics a guided pivot. | Unknown |
| PivotableDomains.PivotableGoogleAnalytics.items.count | Number of connected domains sharing the Google analytics. | Unknown |
| PivotableDomains.PivotableGoogleAnalytics.items.value | Google analytics. | Unknown |
| PivotableDomains.PivotableAdsense.pivotable | Is the domain’s adsense a guided pivot. | Unknown |
| PivotableDomains.PivotableAdsense.items.count | Number of connected domains sharing the adsense. | Unknown |
| PivotableDomains.PivotableAdsense.items.value | Adsense. | Unknown |
comment: Checks for guided pivots for a given domain. args: - name: domaintools_data required: true description: DomainTools context data for a domain. - name: max_registrant_contact_name_count defaultValue: "200" description: Max threshold count that can be pivoted to a registrant contact name. - name: max_registrant_org_count defaultValue: "200" description: Max threshold count that can be pivoted to a registrant org name. - name: max_registrar_count defaultValue: "200" description: Max threshold count that can be pivoted to a registrar. - name: max_ssl_info_organization_count defaultValue: "200" description: Max threshold count that can be pivoted to a ssl organization. - name: max_ssl_info_hash_count defaultValue: "350" description: Max threshold count that can be pivoted to a ssl hash. - name: max_ssl_email_count defaultValue: "350" description: Max threshold count that can be pivoted to a ssl email. - name: max_ssl_subject_count defaultValue: "350" description: Max threshold count that can be pivoted to a ssl subject. - name: max_name_server_host_count defaultValue: "250" description: Max threshold count that can be pivoted to a ssl subject. - name: max_name_server_ip_count defaultValue: "250" description: Max threshold count that can be pivoted to a nameserver ip. - name: max_name_server_domain_count defaultValue: "250" description: Max threshold count that can be pivoted to a nameserver domain. - name: max_soa_email_count defaultValue: "200" description: Max threshold count that can be pivoted to a soa email. - name: max_ip_address_count defaultValue: "200" description: Max threshold count that can be pivoted to an IP address. - name: max_mx_ip_count defaultValue: "200" description: Max threshold count that can be pivoted to a MX IP. - name: max_mx_host_count defaultValue: "200" description: Max threshold count that can be pivoted to a MX Host. - name: max_mx_domain_count defaultValue: "200" description: Max threshold count that can be pivoted to a MX Domain. - name: max_google_adsense_count defaultValue: "200" description: Max threshold count that can be pivoted to a google adsense. - name: max_google_analytics_count defaultValue: "200" description: Max threshold count that can be pivoted to a google analytics. outputs: - contextPath: PivotableDomains.PivotableRegistrantContactName.pivotable description: Is the domain's registrant contact name a guided pivot. - contextPath: PivotableDomains.PivotableRegistrantContactName.items.count description: Number of connected domains sharing the same registrant contact name. - contextPath: PivotableDomains.PivotableRegistrantContactName.items.value description: Registrant contact name. - contextPath: PivotableDomains.PivotableRegistrantOrg.pivotable description: Is the domain's registrant org a guided pivot. - contextPath: PivotableDomains.PivotableRegistrantOrg.items.count description: Number of connected domains sharing the same registrant org. - contextPath: PivotableDomains.PivotableRegistrantOrg.items.value description: Registrant org. - contextPath: PivotableDomains.PivotableSslInfoOrganization.pivotable description: Is the domain's ssl org a guided pivot. - contextPath: PivotableDomains.PivotableSslInfoOrganization.items.count description: Number of connected domains sharing the same ssl org. - contextPath: PivotableDomains.PivotableSslInfoOrganization.items.value description: SSL org. - contextPath: PivotableDomains.PivotableSslInfoHash.pivotable description: Is the domain's ssl hash a guided pivot. - contextPath: PivotableDomains.PivotableSslInfoHash.items.count description: Number of connected domains sharing the same ssl hash. - contextPath: PivotableDomains.PivotableSslInfoHash.items.value description: SSL hash. - contextPath: PivotableDomains.PivotableNameServerHost.pivotable description: Is the domain's name server host a guided pivot. - contextPath: PivotableDomains.PivotableNameServerHost.items.count description: Number of connected domains sharing the same name server host. - contextPath: PivotableDomains.PivotableNameServerHost.items.value description: name server host. - contextPath: PivotableDomains.PivotableSoaEmail.pivotable description: Is the domain's name soa email a guided pivot. - contextPath: PivotableDomains.PivotableSoaEmail.items.count description: Number of connected domains sharing the same name soa email. - contextPath: PivotableDomains.PivotableSoaEmail.items.value description: soa email. - contextPath: PivotableDomains.PivotableIpAddress.pivotable description: Is the domain's IP address a guided pivot. - contextPath: PivotableDomains.PivotableIpAddress.items.count description: Number of connected domains sharing the same IP address. - contextPath: PivotableDomains.PivotableIpAddress.items.value description: IP address. - contextPath: PivotableDomains.PivotableNameServerIp.pivotable description: Is the domain's name server IP address a guided pivot. - contextPath: PivotableDomains.PivotableNameServerIp.items.count description: Number of connected domains sharing the same name server IP address. - contextPath: PivotableDomains.PivotableNameServerIp.items.value description: name server IP address. - contextPath: PivotableDomains.PivotableMxIp.pivotable description: Is the domain's mx IP address a guided pivot. - contextPath: PivotableDomains.PivotableMxIp.items.count description: Number of connected domains sharing the same mx IP address. - contextPath: PivotableDomains.PivotableMxIp.items.value description: mx IP address. - contextPath: PivotableDomains.PivotableRegistrar.pivotable description: Is the domain's registrar a guided pivot. - contextPath: PivotableDomains.PivotableRegistrar.items.count description: Number of connected domains sharing the same registrar. - contextPath: PivotableDomains.PivotableRegistrar.items.value description: Registrar. - contextPath: PivotableDomains.PivotableSslSubject.pivotable description: Is the domain's SSL subject a guided pivot. - contextPath: PivotableDomains.PivotableSslSubject.items.count description: Number of connected domains sharing the SSL subject. - contextPath: PivotableDomains.PivotableSslSubject.items.value description: SSL subject. - contextPath: PivotableDomains.PivotableSslEmail.pivotable description: Is the domain's SSL email a guided pivot. - contextPath: PivotableDomains.PivotableSslEmail.items.count description: Number of connected domains sharing the SSL email. - contextPath: PivotableDomains.PivotableSslEmail.items.value description: SSL email. - contextPath: PivotableDomains.PivotableNameServerDomain.pivotable description: Is the domain's name server domain a guided pivot. - contextPath: PivotableDomains.PivotableNameServerDomain.items.count description: Number of connected domains sharing the name server domain. - contextPath: PivotableDomains.PivotableNameServerDomain.items.value description: Name server domain. - contextPath: PivotableDomains.PivotableMxHost.pivotable description: Is the domain's mx host a guided pivot. - contextPath: PivotableDomains.PivotableMxHost.items.count description: Number of connected domains sharing the mx host. - contextPath: PivotableDomains.PivotableMxHost.items.value description: MX host. - contextPath: PivotableDomains.PivotableMxDomain.pivotable description: Is the domain's mx domain a guided pivot. - contextPath: PivotableDomains.PivotableMxDomain.items.count description: Number of connected domains sharing the mx domain. - contextPath: PivotableDomains.PivotableMxDomain.items.value description: MX domain. - contextPath: PivotableDomains.PivotableGoogleAnalytics.pivotable description: Is the domain's Google analytics a guided pivot. - contextPath: PivotableDomains.PivotableGoogleAnalytics.items.count description: Number of connected domains sharing the Google analytics. - contextPath: PivotableDomains.PivotableGoogleAnalytics.items.value description: Google analytics. - contextPath: PivotableDomains.PivotableAdsense.pivotable description: Is the domain's adsense a guided pivot. - contextPath: PivotableDomains.PivotableAdsense.items.count description: Number of connected domains sharing the adsense. - contextPath: PivotableDomains.PivotableAdsense.items.value description: Adsense. commonfields: id: CheckPivotableDomains version: -1 name: CheckPivotableDomains script: '-' type: python tags: - DomainTools enabled: true subtype: python3 fromversion: 6.6.0 dockerimage: demisto/python3:3.12.13.10116658 tests: - No tests (auto formatted)