DomainExtractAndEnrich
Resolves a URL or fully qualified domain name (FQDN) and looks up a complete profile of the domain on the DomainTools Iris Enrich API.
python · DomainTools Iris Investigate
Details
| ID | DomainExtractAndEnrich |
|---|---|
| Language | python |
| From Version | 6.6.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Tags | DomainTools |
README
Resolves a URL or fully qualified domain name (FQDN) and looks up a complete profile of the domain on the DomainTools Iris Enrich API.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Tags | DomainTools |
| Cortex XSOAR Version | 6.9.0 |
Dependencies
This script uses the following commands and scripts.
- domaintoolsiris-enrich
- DomainTools Iris
- ExtractDomainFromUrlAndEmail
Inputs
| Argument Name | Description |
|---|---|
| url | Resolve and enrich domains from this URL. Also accepts a comma-separated list of up to 6,000 URLs. |
| include_context | Optionally include the investigate results into the Context Data. Defaults to false. |
Outputs
| Path | Description | Type |
|---|---|---|
| Domain.Name | The name of the domain. | String |
| Domain.DNS | The DNS of the domain. | String |
| Domain.DomainStatus | The status of the domain. | Boolean |
| Domain.CreationDate | The creation date. | Date |
| Domain.ExpirationDate | The expiration date of the domain. | Date |
| Domain.NameServers | The nameServers of the domain. | String |
| Domain.Registrant.Country | The registrant country of the domain. | String |
| Domain.Registrant.Email | The registrant email of the domain. | String |
| Domain.Registrant.Name | The registrant name of the domain. | String |
| Domain.Registrant.Phone | The registrant phone number of the domain. | String |
| Domain.Malicious.Vendor | The vendor who classified the domain as malicious. | String |
| Domain.Malicious.Description | The description as to why the domain was found to be malicious. | String |
| DomainTools.Domains.Name | The domain name in DomainTools. | String |
| DomainTools.Domains.LastEnriched | The last Time DomainTools enriched domain data. | Date |
| DomainTools.Domains.Analytics.OverallRiskScore | The Overall Risk Score in DomainTools. | Number |
| DomainTools.Domains.Analytics.ProximityRiskScore | The Proximity Risk Score in DomainTools. | Number |
| DomainTools.Domains.Analytics.ThreatProfileRiskScore.RiskScore | The Threat Profile Risk Score in DomainTools. | Number |
| DomainTools.Domains.Analytics.ThreatProfileRiskScore.Threats | The threats of the Threat Profile Risk Score in DomainTools. | String |
| DomainTools.Domains.Analytics.ThreatProfileRiskScore.Evidence | The Threat Profile Risk Score Evidence in DomainTools. | String |
| DomainTools.Domains.Analytics.WebsiteResponseCode | The Website Response Code in DomainTools. | Number |
| DomainTools.Domains.Analytics.AlexaRank | The Alexa Rank in DomainTools. | Number |
| DomainTools.Domains.Analytics.Tags | The Tags in DomainTools. | String |
| DomainTools.Domains.Identity.RegistrantName | The name of the registrant. | String |
| DomainTools.Domains.Identity.RegistrantOrg | The organization of the registrant. | String |
| DomainTools.Domains.Identity.RegistrantContact.Country.value | The country value of the registrant contact. | String |
| DomainTools.Domains.Identity.RegistrantContact.Country.count | The count of the registrant contact country. | Number |
| DomainTools.Domains.Identity.RegistrantContact.Email.value | The Email value of the registrant contact. | String |
| DomainTools.Domains.Identity.RegistrantContact.Email.count | The Email count of the registrant contact. | Number |
| DomainTools.Domains.Identity.RegistrantContact.Name.value | The name value of the registrant contact. | String |
| DomainTools.Domains.Identity.RegistrantContact.Name.count | The name count of the registrant contact. | Number |
| DomainTools.Domains.Identity.RegistrantContact.Phone.value | The phone value of the registrant contact. | String |
| DomainTools.Domains.Identity.RegistrantContact.Phone.count | The phone count of the registrant contact. | Number |
| DomainTools.Domains.Identity.SOAEmail | The SOA record of the Email. | String |
| DomainTools.Domains.Identity.SSLCertificateEmail | The Email of the SSL certificate. | String |
| DomainTools.Domains.Identity.AdminContact.Country.value | The country value of the administrator contact. | String |
| DomainTools.Domains.Identity.AdminContact.Country.count | The country count of the administrator contact. | Number |
| DomainTools.Domains.Identity.AdminContact.Email.value | The Email value of the administrator contact. | String |
| DomainTools.Domains.Identity.AdminContact.Email.count | The Email count of the administrator contact. | Number |
| DomainTools.Domains.Identity.AdminContact.Name.value | The name value of the administrator contact. | String |
| DomainTools.Domains.Identity.AdminContact.Name.count | The name count of the administrator contact. | Number |
| DomainTools.Domains.Identity.AdminContact.Phone.value | The phone value of the administrator contact. | String |
| DomainTools.Domains.Identity.AdminContact.Phone.count | The phone count of the administrator contact. | Number |
| DomainTools.Domains.Identity.TechnicalContact.Country.value | The country value of the technical contact. | String |
| DomainTools.Domains.Identity.TechnicalContact.Country.count | The country count of the technical contact. | Number |
| DomainTools.Domains.Identity.TechnicalContact.Email.value | The Email value of the technical contact. | String |
| DomainTools.Domains.Identity.TechnicalContact.Email.count | The Email count of the technical contact. | Number |
| DomainTools.Domains.Identity.TechnicalContact.Name.value | The name value of the technical Contact. | String |
| DomainTools.Domains.Identity.TechnicalContact.Name.count | The name count of the technical contact. | Number |
| DomainTools.Domains.Identity.TechnicalContact.Phone.value | The phone value of the technical contact. | String |
| DomainTools.Domains.Identity.TechnicalContact.Phone.count | The phone count of the technical contact. | Number |
| DomainTools.Domains.Identity.BillingContact.Country.value | The country value of the billing contact. | String |
| DomainTools.Domains.Identity.BillingContact.Country.count | The country count of the billing contact. | Number |
| DomainTools.Domains.Identity.BillingContact.Email.value | The Email value of the billing contact. | String |
| DomainTools.Domains.Identity.BillingContact.Email.count | The Email count of the billing contact. | Number |
| DomainTools.Domains.Identity.BillingContact.Name.value | The name value of the billing contact. | String |
| DomainTools.Domains.Identity.BillingContact.Name.count | The name count of the billing contact. | Number |
| DomainTools.Domains.Identity.BillingContact.Phone.value | The phone value of the billing contact. | String |
| DomainTools.Domains.Identity.BillingContact.Phone.count | The phone count of the billing contact. | Number |
| DomainTools.Domains.Identity.EmailDomains | The Email Domains. | String |
| DomainTools.Domains.Identity.AdditionalWhoisEmails.value | The value of the Additional Whois Emails record. | String |
| DomainTools.Domains.Identity.AdditionalWhoisEmails.count | The count of the Additional Whois Emails record. | Number |
| DomainTools.Domains.Registration.DomainRegistrant | The registrant of the domain. | String |
| DomainTools.Domains.Registration.RegistrarStatus | The status of the registrar. | String |
| DomainTools.Domains.Registration.DomainStatus | The active status of the domain. | Boolean |
| DomainTools.Domains.Registration.CreateDate | The date the domain was created. | Date |
| DomainTools.Domains.Registration.ExpirationDate | The expiration date of the domain. | Date |
| DomainTools.Domains.Hosting.IPAddresses.address.value | The address value of IP addresses. | String |
| DomainTools.Domains.Hosting.IPAddresses.address.count | The address count of IP addresses. | Number |
| DomainTools.Domains.Hosting.IPAddresses.asn.value | The ASN value of IP addresses. | String |
| DomainTools.Domains.Hosting.IPAddresses.asn.count | The ASN count of IP addresses. | Number |
| DomainTools.Domains.Hosting.IPAddresses.country_code.value | The country code value of IP addresses. | String |
| DomainTools.Domains.Hosting.IPAddresses.country_code.count | The country code count of IP addresses. | Number |
| DomainTools.Domains.Hosting.IPAddresses.isp.value | The ISP value of IP addresses. | String |
| DomainTools.Domains.Hosting.IPAddresses.isp.count | The ISP count of IP addresses. | Number |
| DomainTools.Domains.Hosting.IPCountryCode | The country code of the IP address. | String |
| DomainTools.Domains.Hosting.MailServers.domain.value | The domain value of the Mail Servers. | String |
| DomainTools.Domains.Hosting.MailServers.domain.count | The domain count of the Mail Servers. | Number |
| DomainTools.Domains.Hosting.MailServers.host.value | The host value of the Mail Servers. | String |
| DomainTools.Domains.Hosting.MailServers.host.count | The host count of the Mail Servers. | Number |
| DomainTools.Domains.Hosting.MailServers.ip.value | The IP value of the Mail Servers. | String |
| DomainTools.Domains.Hosting.MailServers.ip.count | The IP count of the Mail Servers. | Number |
| DomainTools.Domains.Hosting.SPFRecord | The SPF Record. | String |
| DomainTools.Domains.Hosting.NameServers.domain.value | The domain value of the domain NameServers. | String |
| DomainTools.Domains.Hosting.NameServers.domain.count | The domain count of the domain NameServers. | Number |
| DomainTools.Domains.Hosting.NameServers.host.value | The host value of the domain NameServers. | String |
| DomainTools.Domains.Hosting.NameServers.host.count | The host count of the domain NameServers. | Number |
| DomainTools.Domains.Hosting.NameServers.ip.value | The IP value of the domain NameServers. | String |
| DomainTools.Domains.Hosting.NameServers.ip.count | The IP count of domain NameServers. | Number |
| DomainTools.Domains.Hosting.SSLCertificate.hash.value | The hash value of the SSL certificate. | String |
| DomainTools.Domains.Hosting.SSLCertificate.hash.count | The hash count of the SSL certificate. | Number |
| DomainTools.Domains.Hosting.SSLCertificate.organization.value | The organization value of the SSL certificate. | String |
| DomainTools.Domains.Hosting.SSLCertificate.organization.count | The organization count of the SSL certificate information. | Number |
| DomainTools.Domains.Hosting.SSLCertificate.subject.value | The subject value of the SSL certificate information. | String |
| DomainTools.Domains.Hosting.SSLCertificate.subject.count | The subject count of the SSL certificate information. | Number |
| DomainTools.Domains.Hosting.RedirectsTo.value | The Redirects To Value of the domain. | String |
| DomainTools.Domains.Hosting.RedirectsTo.count | The Redirects To Count of the domain. | Number |
| DomainTools.Domains.Analytics.GoogleAdsenseTrackingCode | The tracking code of Google Adsense. | Number |
| DomainTools.Domains.Analytics.GoogleAnalyticTrackingCode | The tracking code of Google Analytics. | Number |
| DBotScore.Indicator | The indicator of the DBotScore. | String |
| DBotScore.Type | The indicator type of the DBotScore. | String |
| DBotScore.Vendor | The vendor used to calculate the score. | String |
| DBotScore.Score | The actual score. | Number |
from CommonServerPython import * from DomainExtractAndEnrich import main def test_domain_extract_and_enrich_output(mocker): domaintools_data = { "Name": "demisto.com", "LastEnriched": "2023-11-10", "Analytics": { "OverallRiskScore": 0, "ProximityRiskScore": 0, "MalwareRiskScore": 0, "PhishingRiskScore": 0, "SpamRiskScore": 0, "ThreatProfileRiskScore": {"RiskScore": 0, "Threats": "", "Evidence": ""}, "WebsiteResponseCode": 200, "GoogleAdsenseTrackingCode": {"value": "", "count": 0}, "GoogleAnalyticTrackingCode": {"value": "", "count": 0}, "Tags": [], }, "Identity": { "RegistrantName": "", "RegistrantOrg": "Palo Alto Networks, Inc.", "RegistrantContact": { "Country": {"value": "us", "count": 275572451}, "Email": [ { "value": "select request email form at https://domains.markmonitor.com/whois/demisto.com", "count": 1, } ], "Name": {"value": "", "count": 0}, "Phone": {"value": "", "count": 0}, "Street": {"value": "", "count": 0}, "City": {"value": "", "count": 0}, "State": {"value": "CA", "count": 18232716}, "Postal": {"value": "", "count": 0}, "Org": {"value": "Palo Alto Networks, Inc.", "count": 645}, }, "Registrar": {"value": "MarkMonitor, Inc.", "count": 867819}, "SOAEmail": [{"value": "it-staff-sysadmin@example.com", "count": 34}], "SSLCertificateEmail": [], "AdminContact": { "Country": {"value": "us", "count": 275572451}, "Email": [ { "value": "select request email form at https://domains.markmonitor.com/whois/demisto.com", "count": 1, } ], "Name": {"value": "", "count": 0}, "Phone": {"value": "", "count": 0}, "Street": {"value": "", "count": 0}, "City": {"value": "", "count": 0}, "State": {"value": "CA", "count": 18232716}, "Postal": {"value": "", "count": 0}, "Org": {"value": "Palo Alto Networks, Inc.", "count": 645}, }, "TechnicalContact": { "Country": {"value": "us", "count": 275572451}, "Email": [ { "value": "select request email form at https://domains.markmonitor.com/whois/demisto.com", "count": 1, } ], "Name": {"value": "", "count": 0}, "Phone": {"value": "", "count": 0}, "Street": {"value": "", "count": 0}, "City": {"value": "", "count": 0}, "State": {"value": "CA", "count": 18232716}, "Postal": {"value": "", "count": 0}, "Org": {"value": "Palo Alto Networks, Inc.", "count": 645}, }, "BillingContact": { "Country": {"value": "", "count": 0}, "Email": [], "Name": {"value": "", "count": 0}, "Phone": {"value": "", "count": 0}, "Street": {"value": "", "count": 0}, "City": {"value": "", "count": 0}, "State": {"value": "", "count": 0}, "Postal": {"value": "", "count": 0}, "Org": {"value": "", "count": 0}, }, "EmailDomains": ["markmonitor.com", "paloaltonetworks.com"], "AdditionalWhoisEmails": [ {"value": "abusecomplaints@markmonitor.com", "count": 1291667}, {"value": "whoisrequest@markmonitor.com", "count": 798372}, ], }, "Registration": { "RegistrarStatus": [ "clientdeleteprohibited", "clienttransferprohibited", "clientupdateprohibited", ], "DomainStatus": True, "CreateDate": "2015-01-16", "ExpirationDate": "2028-01-16", }, "Hosting": { "IPAddresses": [ { "address": {"value": "34.120.160.120", "count": 16}, "asn": [{"value": 396982, "count": 30156647}], "country_code": {"value": "us", "count": 197334117}, "isp": {"value": "Google", "count": 56964370}, } ], "IPCountryCode": "us", "MailServers": [ { "host": {"value": "mxa-00169c01.gslb.pphosted.com", "count": 1097}, "domain": {"value": "pphosted.com", "count": 148978}, "ip": [{"value": "67.231.156.123", "count": 854}], "priority": 10, }, { "host": {"value": "mxb-00169c01.gslb.pphosted.com", "count": 1098}, "domain": {"value": "pphosted.com", "count": 148978}, "ip": [{"value": "67.231.156.123", "count": 854}], "priority": 10, }, ], "SPFRecord": "", "NameServers": [ { "host": {"value": "pdns112.ultradns.net", "count": 369}, "domain": {"value": "ultradns.net", "count": 800581}, "ip": [{"value": "156.154.65.112", "count": 369}], }, { "host": {"value": "pdns112.ultradns.com", "count": 369}, "domain": {"value": "ultradns.com", "count": 651583}, "ip": [{"value": "156.154.64.112", "count": 369}], }, { "host": {"value": "pdns112.ultradns.biz", "count": 369}, "domain": {"value": "ultradns.biz", "count": 648560}, "ip": [{"value": "156.154.66.112", "count": 369}], }, { "host": {"value": "pdns112.ultradns.org", "count": 369}, "domain": {"value": "ultradns.org", "count": 762389}, "ip": [{"value": "156.154.67.112", "count": 369}], }, ], "SSLCertificate": [ { "hash": { "value": "9eb6468deaea5a1c9d022ebaa3694e9ce2f9dce8", "count": 1, }, "subject": {"value": "CN=demisto.com", "count": 1}, "organization": {"value": "", "count": 0}, "email": [], "alt_names": [ {"value": "blog.demisto.com", "count": 0}, {"value": "go.demisto.com", "count": 0}, {"value": "info.demisto.com", "count": 0}, {"value": "demisto.com", "count": 0}, {"value": "www.demisto.com", "count": 0}, ], "common_name": {"value": "demisto.com", "count": 1}, "issuer_common_name": { "value": "Go Daddy Secure Certificate Authority - G2", "count": 18413841, }, "not_after": {"value": 20240716, "count": 180059}, "not_before": {"value": 20230717, "count": 343154}, "duration": {"value": 365, "count": 10714248}, } ], "RedirectsTo": {"value": "www.paloaltonetworks.com", "count": 16}, "RedirectDomain": {"value": "paloaltonetworks.com", "count": 27}, }, "WebsiteTitle": "", "FirstSeen": "2015-01-16T00:00:00Z", "ServerType": "", } mocker.patch.object(demisto, "args", return_value={"url": b"demisto.com"}) mocker.patch.object(demisto, "executeCommand", return_value=[{"Contents": "demisto.com"}]) mocker.patch.object( demisto, "results", return_value=[ { "Type": entryTypes["note"], "ContentsFormat": formats["json"], "Contents": {"domain": "", "domaintools": domaintools_data}, } ], ) main() assert demisto.results.call_count == 1 results = demisto.results.return_value assert len(results) == 1 assert results[0]["Type"] == entryTypes["note"] assert results[0]["ContentsFormat"] == formats["json"] assert "domaintools" in results[0]["Contents"] assert "domain" in results[0]["Contents"]