Iris Investigate transforms surface the DomainTools Iris Investigate dataset directly inside Maltego. Use them for enrichment (add context to an entity already on the graph) and for pivoting (discover new related entities).
The transforms below are organized by the entity you start from. Each section lists the transform, the input it consumes, the output entities it produces, and a short description.
Populates the properties view with Alexa rank, create date, expiration date, and DomainTools Risk Score. Adds a link back to the matching Iris search.
Domain to Risk Components
Domain (enriched)
Populates the properties view with the four component scores that make up the Domain Risk Score: Proximity, Threat Profile, and Threat Profile malware/phishing/spam sub-scores.
Domain to Contact Email Addresses
Email Address
Returns aggregated contact email addresses from the WHOIS record.
Domain to Contact Aliases
Alias
Returns aggregated contact names (administrative, billing, technical) from the WHOIS record.
Domain to Registrant
Domain Registrant
Returns the registrant name from the WHOIS record.
Domain to Registrant Organization
Organization
Returns the registrant organization from the WHOIS record.
Domain to Registrar
Registrar
Returns the registrar that registered the domain.
Domain to IP Addresses
IPv4 Address
Returns the IPv4 addresses hosting the domain.
Domain to ASN
AS
Returns the Autonomous System Numbers associated with the domain’s hosting IPs.
Domain to ISPs
Company
Returns the internet service providers hosting the domain.
Domain to NS Records
NS Record
Returns the nameserver hostnames delegated by the domain.
Domain to MX Records
MX Record
Returns the mail server hostnames in the domain’s MX record.
Domain to SOA Email
Email Address
Returns the DNS/SOA email address associated with the domain.
Domain to SSL Email
Email Address
Returns email addresses extracted from SSL certificates associated with the domain.
Domain to SSL Hash
Hash
Returns the SHA hashes of SSL certificates resolving to the domain via SNI.
Domain to SSL Organization
Organization
Returns the parsed issuer organization from SSL certificates associated with the domain.
Domain to SSL Subjects
Phrase
Returns the subject-field contents from SSL certificates associated with the domain.
Domain to Email Domains
Domain
Breaks out the apex domains of every WHOIS/SOA/SSL email address associated with the domain.
Domain to Adsense Code
Phrase
Returns the Google Adsense code observed in the www. subdomain’s page source.
Domain to Analytics Code
Phrase
Returns the Google Analytics code observed in the www. subdomain’s page source.
Domain to Redirect Domain
Domain
Returns the destination domain of any HTTP 301 redirect configured for the domain when DomainTools first observed it.
Domain to Redirect Domain (recursive)
Domain
Follows a chain of redirects recursively from the domain until no further redirects are found.
Reverses an Iris Search Export (search hash phrase) to the list of domains matching that Iris query. Use this to replay Iris UI research inside Maltego.
Many transforms add a DT Count property to result entities. This represents the number of times the attribute co-occurred with the input across DomainTools’ data, and is a useful signal when ranking pivots.
Enriched Domain entities produced by Iris transforms include an IRIS Link in the display-information panel that deep-links to the matching Iris search at research.domaintools.com.
Data collection notice
We request your consent to track your visit with the services below — we use the
data to prioritize doc improvements and understand our traffic. Our servers always
log basic visitor data for operational purposes. Consult our
Privacy Policy for more
information.