DomainTools DNSDB Co-Located Hosts

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This playbook uses the Farsight DNSDB connector to automatically enrich Domain's found in the Microsoft Sentinel incidents. This use case describes the desire to easily identify Hosts that are co-located (based on Address) based on the input of a domain and a given point in time. The response would be a set of domains that also shared the same IP address as the originating domain name at the given point in time.

Attribute Value
Type Playbook
Solution DomainTools
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 4
farsightdnsdb Managed 1 4
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_DNS post /entities/dnsresolution
Entities_-_Get_Hosts post /entities/host
Add_co_located_domains_to_the_incident_comment post /Incidents/Comment
Add_comment_to_incident_(V3) post /Incidents/Comment

farsightdnsdb (Managed)

Action Method Endpoint Other
RData_Lookup_with_RRType get /lookup/rdata/@{encodeURIComponent('ip')}/@{encodeURIComponent(items('For_each_Unique_IPS'))}/ANY
RRSet_Lookup_with_RRType_AAAA_Records get /lookup/rrset/name/@{encodeURIComponent(items('For_each'))}/@{encodeURIComponent('AAAA')}
RRSet_Lookup_with_RRType_A_Records get /lookup/rrset/name/@{encodeURIComponent(items('For_each'))}/@{encodeURIComponent('A')}
RRSet_Lookup_with_RRType_CNAME get /lookup/rrset/name/@{encodeURIComponent(items('For_each'))}/@{encodeURIComponent('CNAME')}

Additional Documentation

📄 Source: DomainTools-DNSDB-Co-Located-Hosts/readme.md

DomainTools DNSDB

DomainTools DNSDB Co-Located Hosts

This playbook uses the Farsight DNSDB connector to automatically enrich Domain's found in the Microsoft Sentinel incidents. This use case describes the desire to easily identify Hosts that are co-located (based on Address) based on the input of a domain and a given point in time. The response would be a set of domains that also shared the same IP address as the originating domain name at the given point in time.

Table of Contents

  1. Overview
  2. Prerequisites
  3. Deployment
  4. Post Deployment Steps

Overview

Incident Comments

Prerequisites

Deployment Instructions

Deploy to Azure Deploy to Azure Gov

Post-Deployment Instructions

Authorize connections

Once deployment is complete please open the logic app and follow below steps

Configurations in Sentinel:


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to DomainTools