Supported Actions Version 1.7.0
Supported Actions Version 1.6.0
Supported Actions Version 1.5.6
Supported Actions Version 1.5.5
Supported Actions Version 1.5.4
Supported Actions Version 1.5.1
Supported Actions Version 1.5.0
Supported Actions Version 1.4.1
Supported Actions Version 1.3.0
Supported Actions Version 1.2.3
Supported Actions Version 1.2.2
Supported Actions Version 1.2.1
Supported Actions Version 1.2.0
Supported Actions Version 1.1.0
Empower your Investigations with Splunk Phantom and DomainTools
The DomainTools App within Splunk Phantom enables you to block domain names based on Domain Risk Score, identify malicious connected infrastructure, and pivot within playbooks.
Enhance Your Playbooks (Playbook Repo)
Use Domain Risk Score to predict how likely a domain is to be malicious and take automated actions informed by the severity and classification of the threat
Leverage domain name and IP address Whois lookups in ad-hoc actions on events
Make automated decisions in playbooks to enrich a Splunk Phantom event with connected domains and even block them proactively
Add domain name profiles, ownership history and hosting history automatically in any Phantom playbook
Discover how many domains share an identity, a name server, or a hosting IP
Find recently registered domains that match a keyword
Automate Your Workflows
Speed incident handling by ensuring analysts have everything they need to triage an event
Avoid context switching and preserve important artifacts in an event context
Efficiently execute the best analyst workflows with no manual interventions
Take targeted action on risky domains informed by machine learning classifiers
See our blog for more info.
An Iris Investigate API key is required. Contact sales@domaintools.com for a trial.
typing_extensions
from 4.9
to 4.5
this fix issue in cloud instance.on_poll
functionality for monitoring playbooks.on_poll
.DomainTools Iris Release Notes - Published by DomainTools November 30, 2021
Version 1.2.0 - Released November 30, 2021
DomainTools Iris Release Notes - Published by DomainTools February 3, 2020
Version 1.1.0 - Released February 3, 2020
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.