DomainTools Threat Intelligence Domain Feed

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index


Attribute Value
Connector ID DomainToolsCCFDefinition
Publisher DomainTools
Used in Solutions DomainTools CCF
Collection Method CCF
Connector Definition Files DomainToolsFeedsLogs_connectorDefinition.json
DCR Definition Files DomainToolsFeedsLogs_DCR.json
CCF Configuration DomainToolsFeedsLogs_PollerConfig.json
CCF Capabilities APIKey

The DomainTools CCF Domain Data Connector retrieves threat-intelligence domain data from multiple DomainTools APIs—including Newly Observed Domains (NOD), Newly Active Domains (NAD), Newly Observed Hostnames (NOH), and Domain Discovery—and ingests it into Microsoft Sentinel for analysis and detection

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
DomainToolsThreatIntelDomains_CL ? ✓ ?

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Custom Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

1. Configure DomainTools API

Enter your DomainTools API key.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index