DomainTools Iris

This article describes the Intelligence Card Extension for Iris API from DomainTools.


domaintoolsFull.png

DomainTools Iris delivers comprehensive domain profiles to threat analysts directly on the domain Intelligence Card, with insights on the domain's risk score, ownership, registration profile, hosting infrastructure, SSL certificates, web hosting characteristics, and more. The extension is driven by the DomainTools Iris Investigate API. You must have a subscription to DomainTools Iris and an API key to use this extension, but Please also see the Getting Started With Intelligence Card Extensions page if you're interested in enabling this extension.

You can enrich any Domain Intelligence Card using the following attributes obtained from DomainTools Iris:

  • Domain risk scores from proximity and threat profile algorithms
  • Whois, IP, active DNS, website & SSL data
  • Counts of connected domains on most attributes

You can pivot in Recorded Future on these elements of the DomainTools Iris response:

  • Hosting IP Address
  • ASN number
  • Nameserver domain, host and IP address
  • Mailserver IP address and Domain 
  • Email Domain
  • SSL Hashes and more

Example (for google.com):

Screen_Shot_2018-11-29_at_10.23.09_AM.pngScreen_Shot_2018-11-29_at_10.22.44_AM.png

 

Other Resources:

For more information about the DomainTools Iris platform, see https://www.domaintools.com/products/iris/ 

This content is confidential. Do not distribute or download content in a manner that violates your Recorded Future license agreement. Sharing this content outside of licensed Recorded Future users constitutes a breach of the terms and/or agreement and shall be considered a breach by your organization.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more