Product Overview
- Iris Enrich
- Integrate DomainTools data with SIEM, SOAR, and other tools
- Enrich On-Network Indicators at Scale
- The DomainTools Iris data set helps analysts, detection engineering teams, threat hunters, and other practitioners obtain critical situational awareness on domains or IP addresses observed in the protected environment. Whois, DNS, SSL certificate, and risk scoring elements help build out the needed context for appropriate disposition of indicators.
Specifications
- Domain registration profile data
- The most comprehensive source of Whois data, including creation dates, registrant data, SOA records, and active/inactive status indication.
- DNS resolutions for hosting, MX, and name servers. SOA records often provide registrant contact even in domains with redacted Whois records.
- SSL/TLS certificate hash, subject, organization, and email data.
- Timely, comprehensive, and accurate
- DomainTools has the fastest new infrastructure discovery engine in existence, for the earliest context on newly-registered domains and emerging attack campaigns.
- The Iris database is the world’s largest, with over 390 million active domains, and over 95% coverage across all TLDs.
- Iris data comes from authoritative and well-vetted sources for reliable accuracy.
- Adaptable to many use cases
Internet infrastructure data offers many different kinds of insights into hacking threats, fraud, ransomware, phishing, brand infringement, attack surfaces, and adversary tools and methods.The Iris Enrich API gives you the flexibility to design detections and controls that match your most pressing needs.
Advertisement
Advertisement
Products You May Also Be Interested In
Products You May Also Be Interested In

