IP Enrichment - DomainTools Parsed Whois

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This playbook uses the DomainTools Parsed Whois API. Given a ip address or set of ip addresses associated with an incident, return Whois information data for the extracted ip addresess as comments to the incident.

Attribute Value
Type Playbook
Solution DomainTools
Source View on GitHub

Additional Documentation

📄 Source: DomainTools-IP-Address-Playbook/readme.md

DomainTools

DomainTools IP Address Enrichment Playbook

Table of Contents

  1. Overview
  2. Deploy DomainTools-IP-Address-Playbook
  3. Authentication
  4. Prerequisites
  5. Deployment
  6. Post Deployment Steps

Overview

This playbook uses the DomainTools Parsed Whois API. It is able to provide whois information for a IP or set of IPs associated with an incident.

Visit https://www.domaintools.com/integrations to request a Api key.

When a new Azure Sentinel Incident is created, and this playbook is triggered, it performs these actions:

Incident Comments

Deploy to Azure Deploy to Azure

Authentication

Authentication methods this connector supports: - API Key authentication

Prerequisites

Deployment instructions

Post-Deployment instructions:

b. Configurations in Sentinel:


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Playbooks · Back to DomainTools