Skip to content

Anomali: Iris App

The DomainTools Iris App for Anomali delivers a critical subset of DomainTools Iris data, including pivot enrichment, context enrichment for domains, and context enrichment for IPs, emails, and SSL certificates, directly inside the Anomali ThreatStream platform to enable rapid in-context assessments of domain name observables and discovery of connected infrastructure.

Powered by the DomainTools Iris Investigate API—included with most enterprise subscriptions.

To activate the enrichment, you need a DomainTools API username and API key. If you have API keys for the original DomainTools Anomali (v1.0) integration, you may need a new API key. Contact your DomainTools account manager if you need help obtaining access, or email enterprisesupport@domaintools.com.

Activate the DomainTools Iris App within Anomali:

  1. In the top navigation bar, select Settings > Integrations.
  2. Activate the box labeled DomainTools Iris.
  3. Enter your DomainTools API key and API username as requested.

The DomainTools App enriches the critical DomainTools dataset when you open an Observable under the Analyze > Observable tab.

The App adds a DomainTools Iris tab to the set of context enrichment options for supported entity types. Key intelligence includes:

  • Domain Risk Score with supporting evidence and component scores from machine learning classifiers and proximity-based risk algorithms.
  • Domain profile attributes from the DomainTools Iris dataset, including identity, infrastructure, web crawl, SSL details, and parsed RDAP registration data.
  • Guided Pivot counts for each attribute to identify dedicated infrastructure, novel identities, and potential research pathways.
  • An outbound link to the DomainTools Iris Investigation Platform to perform deeper analysis, with the domain name context preserved in the link to streamline the investigation process.

For a domain observable, the DomainTools Iris tab provides the following context enrichment in real time:

  • Domain Risk Score with supporting evidence.
  • Threat component scores from DomainTools machine learning classifiers and proximity-based risk algorithms.
  • Domain attributes from the DomainTools Iris dataset, including identity, infrastructure, web crawl, SSL details, and parsed RDAP registration data.
  • Guided Pivot counts for each attribute to identify dedicated infrastructure, novel identities, and potential research pathways.
  • Guided Pivots within the Enrichments tab.
  • Guided pivots within an investigation.
  • An outbound link to DomainTools Iris Research Platform for deeper analysis, with context preserved in the link to streamline the investigation process.

Sourced from the Iris Investigate API, a list of connected domains, the domain Risk Score, and the domain age distribution are displayed for the same observable value.

The DNSDB enrichment panel provides passive DNS data for domain observables directly within the Anomali ThreatStream platform. Powered by Farsight DNSDB, this panel displays historical and near-real-time DNS resolution data associated with a domain, including records observed across the global DNS infrastructure.

To view DNSDB data, open a domain observable and select the DNSDB tab in the enrichment panel. The panel displays passive DNS records linked to the domain, helping you identify infrastructure changes, historical hosting patterns, and related domains.

The DomainTools Iris App for Anomali leverages Anomali’s built-in graph utility capability to assist in researching connected infrastructure associated with an indicator.

To get started, add an entity of the supported type and right-click the node. You see a DomainTools Iris menu with options to pivot and obtain additional details or domains from the Iris Investigate API.

Observable AttributePivot TypesExpected Results (if available)
DomainPivot DomainWeb hosting ASN Name server and Mail-server IP addresses - Web host Nameserver Mail server hostnames (as a URL) Registrant name (as a tag) Registrar name (as a tag) Email addresses WHOIS, SOA, or SSL SSL certificate hash (as a hash)
IPPivot NS IP Pivot MX IP Pivot DNS IPDomain entities that share the IP address
EmailPivot EmailDomain entities that share the email address
HashPivot SSL HashDomain entities that share the SSL hash
URLPivot Name Server Host Pivot Mail Server HostDomain entities that share the hostname