category: Data Enrichment & Threat Intelligence provider: DomainTools commonfields: id: DomainTools Iris version: -1 configuration: - display: API Username name: credentials type: 9 required: false displaypassword: API Key section: Connect - display: API Username name: username required: false hidden: true type: 0 section: Connect - display: API Key name: apikey required: false hidden: true type: 4 section: Connect - display: High-Risk Threshold name: risk_threshold required: true type: 0 defaultvalue: '70' section: Connect - defaultvalue: '7' display: Young Domain Timeframe (within Days) name: young_domain_timeframe required: true type: 0 section: Connect - display: Trust any certificate (not secure) name: insecure required: false type: 8 section: Connect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - display: Domain Result Type name: domain_result_type type: 15 required: false additionalinfo: "Result type of the domain command: Iris returns full investigate results; Verdict returns only the domain risk score" defaultvalue: Iris options: - Iris - Verdict section: Collect - defaultvalue: Iris Investigate display: 'Domain Enrichment Method (DomainTools)' name: domain_enrichment_method options: - Iris Investigate - Iris Enrich type: 15 required: false section: Collect additionalinfo: "Iris API to be used for domain enrichment. Defaults to Iris Investigate." - defaultvalue: 'Disabled' name: domain_auto_enrich display: 'Domain Auto-Enrich on Ingestion' type: 15 required: false section: Collect options: - Enabled - Disabled additionalinfo: "Enable real-time enrichment for incoming ingested domain. Note: This may consume Iris API quotas." - defaultvalue: 'B - Usually reliable' name: integrationReliability display: 'Source Reliability' type: 15 required: false section: Collect options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged additionalinfo: Reliability of the source providing the intelligence data. - display: '' name: feedExpirationPolicy defaultvalue: 'indicatorType' type: 17 required: false section: Collect options: - never - interval - indicatorType - suddenDeath - display: '' name: feedExpirationInterval type: 1 required: false section: Collect defaultvalue: '20160' - display: 'Guided Pivot Threshold' name: pivot_threshold type: 1 required: true section: Connect additionalinfo: When a small set of domains share an attribute (e.g. registrar), that can often be pivoted on in order to find other similar domains of interest. DomainTools tracks how many domains share each attribute and can highlight it for further investigation when the number of domains is beneath the set threshold. defaultvalue: 500 - display: 'Enabled on Monitoring Domains by Iris Search Hash' name: monitor_iris_search_hash type: 15 required: false section: Collect defaultvalue: Import Indicators Only options: - Import Indicators Only - Create Incident and Import Indicators - display: 'Domaintools Iris Investigate Search Hash' name: domaintools_iris_search_hash required: false type: 12 additionalinfo: The DomainTools Iris Investigate Search hash section: Collect - display: 'Enabled on Monitoring Domains by Iris Tags' name: monitor_iris_tags type: 15 section: Collect defaultvalue: 'Import Indicators Only' required: false options: - Import Indicators Only - Create Incident and Import Indicators - display: Domaintools Iris Tags name: domaintools_iris_tags type: 12 section: Collect required: false additionalinfo: The DomainTools Iris Tags (Values should be a comma separated value. e.g. (tag1,tag2)) - display: Maximum number of incidents to fetch name: max_fetch type: 0 section: Collect defaultvalue: '2' required: false additionalinfo: This is a required field by XSOAR and should be set to 2, one for each possible feed type iris search hash and iris tags. - display: Incident type name: incidentType type: 13 section: Collect - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: '1' required: false type: 19 section: Collect advanced: true - display: Fetch incidents name: isFetch type: 8 section: Collect - display: First fetch timestamp (